Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1005 | Data from Local System | ||
Enterprise | T1567 | .002 | Exfiltration Over Web Service: Exfiltration to Cloud Storage |
Pcexter can upload stolen files to OneDrive storage accounts via HTTP |
Enterprise | T1083 | File and Directory Discovery |
Pcexter has the ability to search for files in specified directories.[1] |
|
Enterprise | T1574 | .002 | Hijack Execution Flow: DLL Side-Loading |
Pcexter has been distributed and executed as a DLL file named Vspmsg.dll via DLL side-loading.[1] |