Класс: HackTool
Вносит в список разрешенных посетителей системы новых пользователей; чистит системные журналы для сокрытия следов присутствия злоумышленника в системе, анализирует и собирает сетевые пакеты для совершения злонамеренных действий и т.д. Может использоваться для организации атак на локальный или удаленный компьютер.Подробнее
Платформа: Win32
Win32 - платформа, управляемая операционной системой на базе Windows NT (Windows XP, Windows 7 и т.д.), позволяющей исполнять 32-битные приложения. В настоящее время данная платформа является одной из наиболее распространенных.Семейство: HackTool.Win32.AmsiETWPatch
Нет описания семействаПримеры
F9BFB1A8098B7A6DC293A5729529DB75452959982E7F2E32A468905FBE155581
E58A85CC6D8E322CA71A0AB64D5BED14
06F6F820C0B391766FAB190037448964
74A2F47C087CCDDACBCC4305FD8DF1AE
Тактики и Техники: Mitre*
TA0009
Collection
The adversary is trying to gather data of interest to their goal.
Collection consists of techniques adversaries may use to gather information and the sources information is collected from that are relevant to following through on the adversary's objectives. Frequently, the next goal after collecting data is to steal (exfiltrate) the data. Common target sources include various drive types, browsers, audio, video, and email. Common collection methods include capturing screenshots and keyboard input.
Collection consists of techniques adversaries may use to gather information and the sources information is collected from that are relevant to following through on the adversary's objectives. Frequently, the next goal after collecting data is to steal (exfiltrate) the data. Common target sources include various drive types, browsers, audio, video, and email. Common collection methods include capturing screenshots and keyboard input.
T1113
Screen Capture
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as
CopyFromScreen, xwd, or screencapture.(Citation: CopyFromScreen .NET)(Citation: Antiquated Mac Malware)* © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.