Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Software
  3. WINERACK

WINERACK

WINERACK is a backdoor used byAPT37.[1]

ID: S0219
Type: MALWARE
Version: 1.0
Created: 18 April 2018
Last Modified: 17 November 2024
Enterprise Layer
downloadview

Techniques Used

DomainIDNameUse
EnterpriseT1010Application Window Discovery

WINERACK can enumerate active windows.[1]

EnterpriseT1059Command and Scripting Interpreter

WINERACK can create a reverse shell that utilizes statically-linked Wine cmd.exe code to emulate Windows command prompt commands.[1]

EnterpriseT1083File and Directory Discovery

WINERACK can enumerate files and directories.[1]

EnterpriseT1057Process Discovery

WINERACK can enumerate processes.[1]

EnterpriseT1082System Information Discovery

WINERACK can gather information about the host.[1]

EnterpriseT1033System Owner/User Discovery

WINERACK can gather information on the victim username.[1]

EnterpriseT1007System Service Discovery

WINERACK can enumerate services.[1]

Groups That Use This Software

IDNameReferences
G0067APT37

[1]

References

×

[8]ページ先頭

©2009-2026 Movatter.jp