Clase: P2P-Worm
Los gusanos P2P se propagan a través de redes de intercambio de archivos punto a punto (como Kazaa, Grokster, EDonkey, FastTrack, Gnutella, etc.). La mayoría de estos gusanos funcionan de forma relativamente simple: para acceder a una red P2P, todo lo que tiene que hacer el gusano es copiarse en el directorio de intercambio de archivos, que generalmente está en una máquina local. La red P2P hace el resto: cuando se realiza una búsqueda de archivos, informa a los usuarios remotos del archivo y proporciona servicios que permiten descargar el archivo de la computadora infectada. También hay Gusanos P2P más complejos que imitan el protocolo de red de un sistema de intercambio de archivos específico y responden positivamente a las consultas de búsqueda; una copia de P2P-Worm se ofrece como una coincidencia.Más información
Plataforma: Win32
Win32 es una API en sistemas operativos basados en Windows NT (Windows XP, Windows 7, etc.) que admite la ejecución de aplicaciones de 32 bits. Una de las plataformas de programación más extendidas en el mundo.Familia: P2P-Worm.Win32.Palevo
No family descriptionExamples
CCE8F29F4BAFA8A4A47487A3E2AEA1EETactics and Techniques: Mitre*
TA0005
Defense Evasion
The adversary is trying to avoid being detected. Defense Evasion consists of techniques that adversaries use to avoid detection throughout their compromise. Techniques used for defense evasion include uninstalling/disabling security software or obfuscating/encrypting data and scripts. Adversaries also leverage and abuse trusted processes to hide and masquerade their malware. Other tactics' techniques are cross-listed here when those techniques include the added benefit of subverting defenses.
T1497.003
Time Based Evasion
Adversaries may employ various time-based methods to detect and avoid virtualization and analysis environments. This may include enumerating time-based properties, such as uptime or the system clock, as well as the use of timers or other triggers to avoid a virtual machine environment (VME) or sandbox, specifically those that are automated or only operate for a limited amount of time.
TA0006
Credential Access
The adversary is trying to steal account names and passwords. Credential Access consists of techniques for stealing credentials like account names and passwords. Techniques used to get credentials include keylogging or credential dumping. Using legitimate credentials can give adversaries access to systems, make them harder to detect, and provide the opportunity to create more accounts to help achieve their goals.
T1552.008
Chat Messages
Adversaries may directly collect unsecured credentials stored or passed through user communication services. Credentials may be sent and stored in user chat communication applications such as email, chat services like Slack or Teams, collaboration tools like Jira or Trello, and any other services that support user communication. Users may share various forms of credentials (such as usernames and passwords, API keys, or authentication tokens) on private or public corporate internal communications channels.
TA0007
Discovery
The adversary is trying to figure out your environment. Discovery consists of techniques an adversary may use to gain knowledge about the system and internal network. These techniques help adversaries observe the environment and orient themselves before deciding how to act. They also allow adversaries to explore what they can control and what's around their entry point in order to discover how it could benefit their current objective. Native operating system tools are often used toward this post-compromise information-gathering objective.
T1497.003
Time Based Evasion
Adversaries may employ various time-based methods to detect and avoid virtualization and analysis environments. This may include enumerating time-based properties, such as uptime or the system clock, as well as the use of timers or other triggers to avoid a virtual machine environment (VME) or sandbox, specifically those that are automated or only operate for a limited amount of time.
* © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.