ISMInjector is a Trojan used to install another OilRig backdoor, ISMAgent. [1]
| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1140 | 反混淆/解码文件或信息 |
ISMInjector uses the |
|
| Enterprise | T1027 | 混淆文件或信息 |
ISMInjector is obfuscated with the off-the-shelf SmartAssembly .NET obfuscator created by red-gate.com.[1] |
|
| Enterprise | T1055 | .012 | 进程注入: Process Hollowing |
ISMInjector hollows out a newly created process RegASM.exe and injects its payload into the hollowed process.[1] |
| Enterprise | T1053 | .005 | 预定任务/作业: Scheduled Task |
ISMInjector creates scheduled tasks to establish persistence.[1] |