General

  • Target

    https://github.com/vouy/Amidewin-Perm-Spoofer-Source/blob/main/x64/Release/Solution.exe

  • Sample

    240704-rs412sxgrr

Malware Config

Targets

MITRE ATT&CK Matrix ATT&CK v13

Execution

Windows Management Instrumentation

1
T1047

System Services

1
T1569

Service Execution

1
T1569.002

Command and Scripting Interpreter

1
T1059

Persistence

Create or Modify System Process

2
T1543

Windows Service

2
T1543.003

Event Triggered Execution

1
T1546

Netsh Helper DLL

1
T1546.007

Privilege Escalation

Create or Modify System Process

2
T1543

Windows Service

2
T1543.003

Event Triggered Execution

1
T1546

Netsh Helper DLL

1
T1546.007

Defense Evasion

Indicator Removal

2
T1070

File Deletion

2
T1070.004

Impair Defenses

2
T1562

Disable or Modify System Firewall

1
T1562.004

Direct Volume Access

1
T1006

Modify Registry

1
T1112

Discovery

Query Registry

3
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

4
T1082

Command and Control

Web Service

1
T1102

Impact

Inhibit System Recovery

2
T1490

Service Stop

1
T1489

Tasks