Kategorie: Worm
Würmer verbreiten sich in Computernetzwerken über Netzwerkressourcen. Im Gegensatz zu Net-Worms muss ein Benutzer einen Wurm starten, damit er aktiviert wird.Diese Art von Wurm durchsucht entfernte Computernetzwerke und kopiert sich in Verzeichnisse, auf die Lese- / Schreibzugriff besteht (falls sie welche findet). Darüber hinaus verwenden diese Würmer entweder eingebaute Betriebssystemfunktionen, um nach zugänglichen Netzwerkverzeichnissen zu suchen und / oder sie suchen zufällig nach Computern im Internet, stellen eine Verbindung zu ihnen her und versuchen, vollen Zugriff auf die Festplatten dieser Computer zu erhalten.
Diese Kategorie umfasst auch jene Würmer, die aus dem einen oder anderen Grund nicht in eine der anderen oben definierten Kategorien passen (zB Würmer für mobile Geräte).
Mehr Informationen
Plattform: Win64
Win64 ist eine Plattform auf Windows-basierten Betriebssystemen für die Ausführung von 32- / 64-Bit-Anwendungen. Win64-Programme können nicht auf 32-Bit-Versionen von Windows gestartet werden.Familie: Worm.Win64.AutoRun
No family descriptionExamples
2DD8CCF717596AFA90E24DE17618F554Tactics and Techniques: Mitre*
TA0005
Defense Evasion
The adversary is trying to avoid being detected. Defense Evasion consists of techniques that adversaries use to avoid detection throughout their compromise. Techniques used for defense evasion include uninstalling/disabling security software or obfuscating/encrypting data and scripts. Adversaries also leverage and abuse trusted processes to hide and masquerade their malware. Other tactics' techniques are cross-listed here when those techniques include the added benefit of subverting defenses.
T1036.007
Double File Extension
Adversaries may abuse a double extension in the filename as a means of masquerading the true file type. A file name may include a secondary file type extension that may cause only the first extension to be displayed (ex:
File.txt.exe may render in some views as just File.txt). However, the second extension is the true file type that determines how the file is opened and executed. The real file extension may be hidden by the operating system in the file browser (ex: explorer.exe), as well as in any software configured using or similar to the system’s policies. T1112
Modify Registry
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
TA0009
Collection
The adversary is trying to gather data of interest to their goal. Collection consists of techniques adversaries may use to gather information and the sources information is collected from that are relevant to following through on the adversary's objectives. Frequently, the next goal after collecting data is to steal (exfiltrate) the data. Common target sources include various drive types, browsers, audio, video, and email. Common collection methods include capturing screenshots and keyboard input.
T1185
Browser Session Hijacking
Adversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and intercept information as part of various browser session hijacking techniques.
* © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.