CSPY Downloader
Techniques Used |
||||
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1548 | .002 | Abuse Elevation Control Mechanism: Bypass User Account Control |
CSPY Downloader can bypass UAC using the SilentCleanup task to execute the binary with elevated privileges.(Citation: Cybereason Kimsuky November 2020) |
Enterprise | T1071 | .001 | Application Layer Protocol: Web Protocols |
CSPY Downloader can use GET requests to download additional payloads from C2.(Citation: Cybereason Kimsuky November 2020) |
Enterprise | T1070 | .004 | Indicator Removal: File Deletion |
CSPY Downloader has the ability to self delete.(Citation: Cybereason Kimsuky November 2020) |
Enterprise | T1036 | .004 | Masquerading: Masquerade Task or Service |
CSPY Downloader has attempted to appear as a legitimate Windows service with a fake description claiming it is used to support packed applications.(Citation: Cybereason Kimsuky November 2020) |
Enterprise | T1027 | .002 | Obfuscated Files or Information: Software Packing |
CSPY Downloader has been packed with UPX.(Citation: Cybereason Kimsuky November 2020) |
Enterprise | T1053 | .005 | Scheduled Task/Job: Scheduled Task |
CSPY Downloader can use the schtasks utility to bypass UAC.(Citation: Cybereason Kimsuky November 2020) |
Enterprise | T1553 | .002 | Subvert Trust Controls: Code Signing |
CSPY Downloader has come signed with revoked certificates.(Citation: Cybereason Kimsuky November 2020) |
Enterprise | T1204 | .002 | User Execution: Malicious File |
CSPY Downloader has been delivered via malicious documents with embedded macros.(Citation: Cybereason Kimsuky November 2020) |
Enterprise | T1497 | .001 | Virtualization/Sandbox Evasion: System Checks |
CSPY Downloader can search loaded modules, PEB structure, file paths, Registry keys, and memory to determine if it is being debugged or running in a virtual environment.(Citation: Cybereason Kimsuky November 2020) |
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.