down_new is a downloader that has been used by BRONZE BUTLER since at least 2019.[1]
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1071 | .001 | Application Layer Protocol: Web Protocols |
down_new has the ability to use HTTP in C2 communications.[1] |
Enterprise | T1132 | .001 | Data Encoding: Standard Encoding |
down_new has the ability to base64 encode C2 communications.[1] |
Enterprise | T1573 | .001 | Encrypted Channel: Symmetric Cryptography |
down_new has the ability to AES encrypt C2 communications.[1] |
Enterprise | T1083 | File and Directory Discovery |
down_new has the ability to list the directories on a compromised host.[1] |
|
Enterprise | T1105 | Ingress Tool Transfer |
down_new has the ability to download files to the compromised host.[1] |
|
Enterprise | T1057 | Process Discovery |
down_new has the ability to list running processes on a compromised host.[1] |
|
Enterprise | T1518 | Software Discovery |
down_new has the ability to gather information on installed applications.[1] |
|
.001 | Security Software Discovery |
down_new has the ability to detect anti-virus products and processes on a compromised host.[1] |
||
Enterprise | T1082 | System Information Discovery |
down_new has the ability to identify the system volume information of a compromised host.[1] |
|
Enterprise | T1016 | System Network Configuration Discovery |
down_new has the ability to identify the MAC address of a compromised host.[1] |
ID | Name | References |
---|---|---|
G0060 | BRONZE BUTLER |