| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1005 | 从本地系统获取数据 | ||
| Enterprise | T1574 | .002 | 劫持执行流: DLL Side-Loading |
Pcexter has been distributed and executed as a DLL file named Vspmsg.dll via DLL side-loading.[1] |
| Enterprise | T1083 | 文件和目录发现 |
Pcexter has the ability to search for files in specified directories.[1] |
|
| Enterprise | T1567 | .002 | 通过网络服务渗出: Exfiltration to Cloud Storage |
Pcexter can upload stolen files to OneDrive storage accounts via HTTP |