| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1543 | .003 | 创建或修改系统进程: Windows Service |
Carbon establishes persistence by creating a service and naming it based off the operating system version running on the current machine.[1] |
| Enterprise | T1573 | .002 | 加密通道: Asymmetric Cryptography | |
| Enterprise | T1140 | 反混淆/解码文件或信息 |
Carbon decrypts task and configuration files for execution.[1][3] |
|
| Enterprise | T1071 | .001 | 应用层协议: Web Protocols | |
| Enterprise | T1074 | .001 | 数据分段: Local Data Staging |
Carbon creates a base directory that contains the files and folders that are collected.[1] |
| Enterprise | T1048 | .003 | 替代协议渗出: Exfiltration Over Unencrypted Non-C2 Protocol | |
| Enterprise | T1069 | 权限组发现 | ||
| Enterprise | T1012 | 查询注册表 | ||
| Enterprise | T1027 | 混淆文件或信息 |
Carbon encrypts configuration files and tasks for the malware to complete using CAST-128 algorithm.[1][3] |
|
| Enterprise | T1124 | 系统时间发现 |
Carbon uses the command |
|
| Enterprise | T1049 | 系统网络连接发现 | ||
| Enterprise | T1016 | 系统网络配置发现 |
Carbon can collect the IP address of the victims and other computers on the network using the commands: |
|
| Enterprise | T1102 | 网络服务 | ||
| Enterprise | T1057 | 进程发现 | ||
| Enterprise | T1055 | .001 | 进程注入: Dynamic-link Library Injection | |
| Enterprise | T1018 | 远程系统发现 | ||
| Enterprise | T1095 | 非应用层协议 | ||
| Enterprise | T1053 | .005 | 预定任务/作业: Scheduled Task |
Carbon creates several tasks for later execution to continue persistence on the victim’s machine.[1] |