Classe: HackTool
Os programas HackTool são usados para criar novos usuários na lista de visitantes permitidos do sistema e para excluir informações dos registros do sistema para ocultar a presença do usuário malicioso no sistema. Esses programas também são usados para analisar e coletar pacotes de rede para realizar ações maliciosas específicas. Usuários mal-intencionados usam programas HackTool ao configurar ataques em computadores locais ou remotos.Plataforma: Win32
O Win32 é uma API em sistemas operacionais baseados no Windows NT (Windows XP, Windows 7, etc.) que oferece suporte à execução de aplicativos de 32 bits. Uma das plataformas de programação mais difundidas do mundo.Família: HackTool.Win32.AmsiETWPatch
No family descriptionExamples
F9BFB1A8098B7A6DC293A5729529DB75452959982E7F2E32A468905FBE155581
E58A85CC6D8E322CA71A0AB64D5BED14
06F6F820C0B391766FAB190037448964
74A2F47C087CCDDACBCC4305FD8DF1AE
Tactics and Techniques: Mitre*
TA0009
Collection
The adversary is trying to gather data of interest to their goal.
Collection consists of techniques adversaries may use to gather information and the sources information is collected from that are relevant to following through on the adversary's objectives. Frequently, the next goal after collecting data is to steal (exfiltrate) the data. Common target sources include various drive types, browsers, audio, video, and email. Common collection methods include capturing screenshots and keyboard input.
Collection consists of techniques adversaries may use to gather information and the sources information is collected from that are relevant to following through on the adversary's objectives. Frequently, the next goal after collecting data is to steal (exfiltrate) the data. Common target sources include various drive types, browsers, audio, video, and email. Common collection methods include capturing screenshots and keyboard input.
T1113
Screen Capture
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as
CopyFromScreen, xwd, or screencapture.(Citation: CopyFromScreen .NET)(Citation: Antiquated Mac Malware)* © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.