Skip to content

Hide Navigation Hide TOC

Pasam - S0208 (e811ff6a-4cef-4856-a6ae-a7daf9ed39ae)

Pasam is a trojan used by Elderwood to open a backdoor on compromised hosts. (Citation: Symantec Elderwood Sept 2012) (Citation: Symantec Pasam May 2012)

Cluster A Galaxy A Cluster B Galaxy B Level
System Information Discovery - T1082 (354a7f88-63fb-41b5-a801-ce3b377b36f1) Attack Pattern Pasam - S0208 (e811ff6a-4cef-4856-a6ae-a7daf9ed39ae) Malware 1
LSASS Driver - T1547.008 (f0589bc3-a6ae-425a-a3d5-5659bfee07f4) Attack Pattern Pasam - S0208 (e811ff6a-4cef-4856-a6ae-a7daf9ed39ae) Malware 1
Pasam - S0208 (e811ff6a-4cef-4856-a6ae-a7daf9ed39ae) Malware File Deletion - T1070.004 (d63a3fb8-9452-4e9d-a60a-54be68d5998c) Attack Pattern 1
Pasam - S0208 (e811ff6a-4cef-4856-a6ae-a7daf9ed39ae) Malware File and Directory Discovery - T1083 (7bc57495-ea59-4380-be31-a64af124ef18) Attack Pattern 1
Pasam - S0208 (e811ff6a-4cef-4856-a6ae-a7daf9ed39ae) Malware Ingress Tool Transfer - T1105 (e6919abc-99f9-4c6c-95a5-14761e7b2add) Attack Pattern 1
Data from Local System - T1005 (3c4a2599-71ee-4405-ba1e-0e28414b4bc5) Attack Pattern Pasam - S0208 (e811ff6a-4cef-4856-a6ae-a7daf9ed39ae) Malware 1
Process Discovery - T1057 (8f4a33ec-8b1f-4b80-a2f6-642b2e479580) Attack Pattern Pasam - S0208 (e811ff6a-4cef-4856-a6ae-a7daf9ed39ae) Malware 1
LSASS Driver - T1547.008 (f0589bc3-a6ae-425a-a3d5-5659bfee07f4) Attack Pattern Boot or Logon Autostart Execution - T1547 (1ecb2399-e8ba-4f6b-8ba7-5c27d49405cf) Attack Pattern 2
File Deletion - T1070.004 (d63a3fb8-9452-4e9d-a60a-54be68d5998c) Attack Pattern Indicator Removal - T1070 (799ace7f-e227-4411-baa0-8868704f2a69) Attack Pattern 2