48 results found (page 2 of 4)
https://attack.mitre.org/versions/v17/techniques/T1048/003

…f its execution stored in the /tmp folder over FTP using the curl command. [17] G0037 FIN6 FIN6 has sent stolen payment card data to remote servers via HTTP POSTs. [18] G0061 FIN8 FIN8 has used FTP to exfiltrate collected data. [19] S0095 ftp ftp may be used to exfiltrate data se…

https://attack.mitre.org/versions/v10/techniques/T1547/001

…e by using the Registry option in PowerShell Empire to add a Run key. [79] [73] G0037 FIN6 FIN6 has used Registry Run keys to establish persistence for its downloader tools known as HARDTACK and SHIPBREAD. [80] G0046 FIN7 FIN7 malware has created Registry Run and RunOnce keys to …

https://attack.mitre.org/versions/v17/techniques/T1547/001

…32Node\Microsoft\Windows\CurrentVersion\Run\hosts to maintain persistence. [95] G0037 FIN6 FIN6 has used Registry Run keys to establish persistence for its downloader tools known as HARDTACK and SHIPBREAD. [96] G0046 FIN7 FIN7 malware has created Registry Run and RunOnce keys to …