Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1071 | .001 | Application Layer Protocol: Web Protocols | |
.003 | Application Layer Protocol: Mail Protocols | |||
Enterprise | T1555 | Credentials from Password Stores | ||
.003 | Credentials from Web Browsers |
OLDBAIT collects credentials from Internet Explorer, Mozilla Firefox, and Eudora.[1] |
||
Enterprise | T1036 | .005 | Masquerading: Match Legitimate Name or Location |
OLDBAIT installs itself in |
Enterprise | T1027 | Obfuscated Files or Information |
OLDBAIT obfuscates internal strings and unpacks them at startup.[1] |