Kategorie: Hoax
Eine Falschmeldung ist eine gefälschte Warnung vor einem Virus oder anderem bösartigen Code. In der Regel hat ein Hoax die Form einer E-Mail-Nachricht, die den Leser vor einem gefährlichen neuen Virus warnt und vorschlägt, dass der Leser die Nachricht weitergibt. Hoaxes verursachen an sich keinen Schaden, aber ihre Verteilung durch wohlmeinende Benutzer verursacht oft Angst und Unsicherheit.Die meisten Antivirus-Anbieter enthalten auf ihren Websites Hoax-Informationen und es ist immer ratsam, vor der Weiterleitung Warnmeldungen zu überprüfen.
Mehr Informationen
Plattform: Win32
Win32 ist eine API auf Windows NT-basierten Betriebssystemen (Windows XP, Windows 7 usw.), die die Ausführung von 32-Bit-Anwendungen unterstützt. Eine der am weitesten verbreiteten Programmierplattformen der Welt.Familie: Hoax.Win32.ArchSMS
No family descriptionExamples
A8D8636F8BB4EE316AB3301589199B025003227AAFFBF74AF6ABCA34137C3219
08154E038151E0A3CF2A4103C1ADDDB0
FEBA9D84775C4B5E75279AC416EA06B0
579CEAB10999A69C4189AEB9794CF7C3
Tactics and Techniques: Mitre*
TA0005
Defense Evasion
The adversary is trying to avoid being detected.
Defense Evasion consists of techniques that adversaries use to avoid detection throughout their compromise. Techniques used for defense evasion include uninstalling/disabling security software or obfuscating/encrypting data and scripts. Adversaries also leverage and abuse trusted processes to hide and masquerade their malware. Other tactics’ techniques are cross-listed here when those techniques include the added benefit of subverting defenses.
Defense Evasion consists of techniques that adversaries use to avoid detection throughout their compromise. Techniques used for defense evasion include uninstalling/disabling security software or obfuscating/encrypting data and scripts. Adversaries also leverage and abuse trusted processes to hide and masquerade their malware. Other tactics’ techniques are cross-listed here when those techniques include the added benefit of subverting defenses.
T1036
Masquerading
Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names.
Renaming abusable system utilities to evade security monitoring is also a form of Masquerading.(Citation: LOLBAS Main Site) Masquerading may also include the use of Proxy or VPNs to disguise IP addresses, which can allow adversaries to blend in with normal network traffic and bypass conditional access policies or anti-abuse protections.
Renaming abusable system utilities to evade security monitoring is also a form of Masquerading.(Citation: LOLBAS Main Site) Masquerading may also include the use of Proxy or VPNs to disguise IP addresses, which can allow adversaries to blend in with normal network traffic and bypass conditional access policies or anti-abuse protections.
* © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.