Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Software
  3. PinchDuke

PinchDuke

PinchDuke is malware that was used byAPT29 from 2008 to 2010.[1]

ID: S0048
Type: MALWARE
Platforms: Windows
Version: 1.1
Created: 31 May 2017
Last Modified: 25 April 2025
Enterprise Layer
downloadview

Techniques Used

DomainIDNameUse
EnterpriseT1071.001Application Layer Protocol:Web Protocols

PinchDuke transfers files from the compromised host via HTTP or HTTPS to a C2 server.[1]

EnterpriseT1555Credentials from Password Stores

PinchDuke steals credentials from compromised hosts.PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted byPinchDuke include ones associated with many sources such as The Bat!, Yahoo!, Mail.ru, Passport.Net, Google Talk, and Microsoft Outlook.[1]

.003Credentials from Web Browsers

PinchDuke steals credentials from compromised hosts.PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted byPinchDuke include ones associated with many sources such as Netscape Navigator, Mozilla Firefox, Mozilla Thunderbird, and Internet Explorer.[1]

EnterpriseT1005Data from Local System

PinchDuke collects user files from the compromised host based on predefined file extensions.[1]

EnterpriseT1083File and Directory Discovery

PinchDuke searches for files created within a certain timeframe and whose file extension matches a predefined list.[1]

EnterpriseT1003OS Credential Dumping

PinchDuke steals credentials from compromised hosts.PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted byPinchDuke include ones associated many sources such as WinInet Credential Cache, and Lightweight Directory Access Protocol (LDAP).[1]

EnterpriseT1082System Information Discovery

PinchDuke gathers system configuration information.[1]

Groups That Use This Software

IDNameReferences
G0016APT29

[1]

References

×

[8]ページ先頭

©2009-2026 Movatter.jp