Clase: HackTool
Los programas de HackTool se utilizan para crear nuevos usuarios en la lista de visitantes permitidos del sistema y para eliminar información de los registros del sistema con el fin de ocultar la presencia del usuario malintencionado en el sistema. Estos programas también se utilizan para analizar y recopilar paquetes de red para llevar a cabo acciones maliciosas específicas. Los usuarios malintencionados emplean programas de HackTool al configurar ataques en computadoras locales o remotas.Más información
Plataforma: Win32
Win32 es una API en sistemas operativos basados en Windows NT (Windows XP, Windows 7, etc.) que admite la ejecución de aplicaciones de 32 bits. Una de las plataformas de programación más extendidas en el mundo.Familia: HackTool.Win32.AmsiETWPatch
No family descriptionExamples
F9BFB1A8098B7A6DC293A5729529DB75452959982E7F2E32A468905FBE155581
E58A85CC6D8E322CA71A0AB64D5BED14
06F6F820C0B391766FAB190037448964
74A2F47C087CCDDACBCC4305FD8DF1AE
Tactics and Techniques: Mitre*
TA0009
Collection
The adversary is trying to gather data of interest to their goal.
Collection consists of techniques adversaries may use to gather information and the sources information is collected from that are relevant to following through on the adversary's objectives. Frequently, the next goal after collecting data is to steal (exfiltrate) the data. Common target sources include various drive types, browsers, audio, video, and email. Common collection methods include capturing screenshots and keyboard input.
Collection consists of techniques adversaries may use to gather information and the sources information is collected from that are relevant to following through on the adversary's objectives. Frequently, the next goal after collecting data is to steal (exfiltrate) the data. Common target sources include various drive types, browsers, audio, video, and email. Common collection methods include capturing screenshots and keyboard input.
T1113
Screen Capture
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as
CopyFromScreen, xwd, or screencapture.(Citation: CopyFromScreen .NET)(Citation: Antiquated Mac Malware)* © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.