Skip to content

Hide Navigation Hide TOC

NICECURL - S1192 (0659f55c-3b68-4e5d-8071-12ded6684731)

NICECURL is a VBScript-based backdoor used by APT42 to download additional modules.(Citation: Mandiant APT42-untangling)

Cluster A Galaxy A Cluster B Galaxy B Level
Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) Attack Pattern NICECURL - S1192 (0659f55c-3b68-4e5d-8071-12ded6684731) Malware 1
Web Protocols - T1071.001 (df8b2a25-8bdf-4856-953c-a04372b1c161) Attack Pattern NICECURL - S1192 (0659f55c-3b68-4e5d-8071-12ded6684731) Malware 1
Ingress Tool Transfer - T1105 (e6919abc-99f9-4c6c-95a5-14761e7b2add) Attack Pattern NICECURL - S1192 (0659f55c-3b68-4e5d-8071-12ded6684731) Malware 1
NICECURL - S1192 (0659f55c-3b68-4e5d-8071-12ded6684731) Malware Asymmetric Cryptography - T1573.002 (bf176076-b789-408e-8cba-7275e81c0ada) Attack Pattern 1
NICECURL - S1192 (0659f55c-3b68-4e5d-8071-12ded6684731) Malware File Deletion - T1070.004 (d63a3fb8-9452-4e9d-a60a-54be68d5998c) Attack Pattern 1
Web Protocols - T1071.001 (df8b2a25-8bdf-4856-953c-a04372b1c161) Attack Pattern Application Layer Protocol - T1071 (355be19c-ffc9-46d5-8d50-d6a036c675b6) Attack Pattern 2
Encrypted Channel - T1573 (b8902400-e6c5-4ba2-95aa-2d35b442b118) Attack Pattern Asymmetric Cryptography - T1573.002 (bf176076-b789-408e-8cba-7275e81c0ada) Attack Pattern 2
Indicator Removal - T1070 (799ace7f-e227-4411-baa0-8868704f2a69) Attack Pattern File Deletion - T1070.004 (d63a3fb8-9452-4e9d-a60a-54be68d5998c) Attack Pattern 2