| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1543 | .003 | 创建或修改系统进程: Windows Service |
SUGARUSH has created a service named |
| Enterprise | T1059 | .003 | 命令与脚本解释器: Windows Command Shell | |
| Enterprise | T1016 | .001 | 系统网络配置发现: Internet Connection Discovery |
SUGARUSH has checked for internet connectivity from an infected host before attempting to establish a new TCP connection.[1] |
| Enterprise | T1095 | 非应用层协议 | ||
| Enterprise | T1571 | 非标准端口 |
SUGARUSH has used port 4585 for a TCP connection to its C2.[1] |
|