| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1090 | 代理 |
HARDRAIN uses the command |
|
| Enterprise | T1059 | .003 | 命令与脚本解释器: Windows Command Shell | |
| Enterprise | T1562 | .004 | 妨碍防御: Disable or Modify System Firewall |
HARDRAIN opens the Windows Firewall to modify incoming connections.[1] |
| Enterprise | T1001 | .003 | 数据混淆: Protocol or Service Impersonation | |
| Enterprise | T1571 | 非标准端口 |
HARDRAIN binds and listens on port 443 with a FakeTLS method.[1] |
|
| ID | Name | References |
|---|---|---|
| G0032 | Lazarus Group |