| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1071 | .001 | Application Layer Protocol: Web Protocols | |
| .003 | Application Layer Protocol: Mail Protocols | |||
| Enterprise | T1555 | Credentials from Password Stores | ||
| .003 | Credentials from Web Browsers |
OLDBAIT collects credentials from Internet Explorer, Mozilla Firefox, and Eudora.[1] |
||
| Enterprise | T1036 | .005 | Masquerading: Match Legitimate Name or Location |
OLDBAIT installs itself in |
| Enterprise | T1027 | Obfuscated Files or Information |
OLDBAIT obfuscates internal strings and unpacks them at startup.[1] |
|
| ID | Name | References |
|---|---|---|
| G0007 | APT28 |