Clase: Trojan-Dropper
Los programas Trojan-Dropper están diseñados para instalar en secreto programas maliciosos integrados en su código en las computadoras de las víctimas. Este tipo de programa malicioso generalmente guarda un rango de archivos en el disco de la víctima (generalmente en el directorio de Windows, el directorio del sistema de Windows, el directorio temporal, etc.) y los lanza sin ninguna notificación (o con notificación falsa de un error de archivo, versión obsoleta del sistema operativo, etc.). Tales programas son utilizados por los piratas informáticos para: instalar en secreto programas troyanos y / o virus para evitar que los programas maliciosos conocidos sean detectados por las soluciones antivirus; no todos los programas antivirus son capaces de escanear todos los componentes dentro de este tipo de troyanos.Más información
Plataforma: Win32
Win32 es una API en sistemas operativos basados en Windows NT (Windows XP, Windows 7, etc.) que admite la ejecución de aplicaciones de 32 bits. Una de las plataformas de programación más extendidas en el mundo.Familia: Trojan-Dropper.Win32.Agent
No family descriptionExamples
F1AEB34C44C9382C73B6B54C4177A5B529700A1D94BDF32BECEB74D92113EAA6
3188D1974CAAD4B15BCDD359D4A78592
0B57B838D684B253AEEE5ACD76AE2FEB
9319B3445B1BC8CBCDB64CFC510A4D04
Tactics and Techniques: Mitre*
TA0011
Command and Control
The adversary is trying to communicate with compromised systems to control them.
Command and Control consists of techniques that adversaries may use to communicate with systems under their control within a victim network. Adversaries commonly attempt to mimic normal, expected traffic to avoid detection. There are many ways an adversary can establish command and control with various levels of stealth depending on the victim’s network structure and defenses.
Command and Control consists of techniques that adversaries may use to communicate with systems under their control within a victim network. Adversaries commonly attempt to mimic normal, expected traffic to avoid detection. There are many ways an adversary can establish command and control with various levels of stealth depending on the victim’s network structure and defenses.
T1095
Non-Application Layer Protocol
Adversaries may use an OSI non-application layer protocol for communication between host and C2 server or among infected hosts within a network. The list of possible protocols is extensive.(Citation: Wikipedia OSI) Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
ICMP communication between hosts is one example.(Citation: Cisco Synful Knock Evolution) Because ICMP is part of the Internet Protocol Suite, it is required to be implemented by all IP-compatible hosts.(Citation: Microsoft ICMP) However, it is not as commonly monitored as other Internet Protocols such as TCP or UDP and may be used by adversaries to hide communications.
ICMP communication between hosts is one example.(Citation: Cisco Synful Knock Evolution) Because ICMP is part of the Internet Protocol Suite, it is required to be implemented by all IP-compatible hosts.(Citation: Microsoft ICMP) However, it is not as commonly monitored as other Internet Protocols such as TCP or UDP and may be used by adversaries to hide communications.
* © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.