MCMD
Techniques Used |
||||
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1071 | .001 | Application Layer Protocol: Web Protocols |
MCMD can use HTTPS in communication with C2 web servers.(Citation: Secureworks MCMD July 2019) |
Enterprise | T1547 | .001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
MCMD can use Registry Run Keys for persistence.(Citation: Secureworks MCMD July 2019) |
Enterprise | T1059 | .003 | Command and Scripting Interpreter: Windows Command Shell |
MCMD can launch a console process (cmd.exe) with redirected standard input and output.(Citation: Secureworks MCMD July 2019) |
Enterprise | T1564 | .003 | Hide Artifacts: Hidden Window |
MCMD can modify processes to prevent them from being visible on the desktop.(Citation: Secureworks MCMD July 2019) |
Enterprise | T1070 | .009 | Indicator Removal: Clear Persistence |
MCMD has the ability to remove set Registry Keys, including those used for persistence.(Citation: Secureworks MCMD July 2019) |
Enterprise | T1036 | .005 | Masquerading: Match Legitimate Name or Location |
MCMD has been named Readme.txt to appear legitimate.(Citation: Secureworks MCMD July 2019) |
Enterprise | T1053 | .005 | Scheduled Task/Job: Scheduled Task |
MCMD can use scheduled tasks for persistence.(Citation: Secureworks MCMD July 2019) |
Groups That Use This Software |
||
ID | Name | References |
---|---|---|
G0035 | Dragonfly |
(Citation: Secureworks MCMD July 2019) |
G0074 | Dragonfly 2.0 |
(Citation: Secureworks MCMD July 2019) |
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.