Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Software
  3. Sys10

Sys10

Sys10 is a backdoor that was used throughout 2013 byNaikon.[1]

ID: S0060
Type: MALWARE
Platforms: Windows
Version: 1.1
Created: 31 May 2017
Last Modified: 25 April 2025
Enterprise Layer
downloadview

Techniques Used

DomainIDNameUse
EnterpriseT1071.001Application Layer Protocol:Web Protocols

Sys10 uses HTTP for C2.[1]

EnterpriseT1573.001Encrypted Channel:Symmetric Cryptography

Sys10 uses an XOR 0x1 loop to encrypt its C2 domain.[1]

EnterpriseT1069.001Permission Groups Discovery:Local Groups

Sys10 collects the group name of the logged-in user and sends it to the C2.[1]

EnterpriseT1082System Information Discovery

Sys10 collects the computer name, OS versioning information, and OS install date and sends the information to the C2.[1]

EnterpriseT1016System Network Configuration Discovery

Sys10 collects the local IP address of the victim and sends it to the C2.[1]

EnterpriseT1033System Owner/User Discovery

Sys10 collects the account name of the logged-in user and sends it to the C2.[1]

Groups That Use This Software

IDNameReferences
G0019Naikon

[1]

References

×

[8]ページ先頭

©2009-2026 Movatter.jp