Skip to content

Hide Navigation Hide TOC

Linfo - S0211 (e9e9bfe2-76f4-4870-a2a1-b7af89808613)

Linfo is a rootkit trojan used by Elderwood to open a backdoor on compromised hosts. (Citation: Symantec Elderwood Sept 2012) (Citation: Symantec Linfo May 2012)

Cluster A Galaxy A Cluster B Galaxy B Level
Linfo - S0211 (e9e9bfe2-76f4-4870-a2a1-b7af89808613) Malware System Information Discovery - T1082 (354a7f88-63fb-41b5-a801-ce3b377b36f1) Attack Pattern 1
Linfo - S0211 (e9e9bfe2-76f4-4870-a2a1-b7af89808613) Malware File Deletion - T1070.004 (d63a3fb8-9452-4e9d-a60a-54be68d5998c) Attack Pattern 1
Linfo - S0211 (e9e9bfe2-76f4-4870-a2a1-b7af89808613) Malware Scheduled Transfer - T1029 (4eeaf8a9-c86b-4954-a663-9555fb406466) Attack Pattern 1
Linfo - S0211 (e9e9bfe2-76f4-4870-a2a1-b7af89808613) Malware Fallback Channels - T1008 (f24faf46-3b26-4dbb-98f2-63460498e433) Attack Pattern 1
Linfo - S0211 (e9e9bfe2-76f4-4870-a2a1-b7af89808613) Malware File and Directory Discovery - T1083 (7bc57495-ea59-4380-be31-a64af124ef18) Attack Pattern 1
Linfo - S0211 (e9e9bfe2-76f4-4870-a2a1-b7af89808613) Malware Ingress Tool Transfer - T1105 (e6919abc-99f9-4c6c-95a5-14761e7b2add) Attack Pattern 1
Linfo - S0211 (e9e9bfe2-76f4-4870-a2a1-b7af89808613) Malware Data from Local System - T1005 (3c4a2599-71ee-4405-ba1e-0e28414b4bc5) Attack Pattern 1
Linfo - S0211 (e9e9bfe2-76f4-4870-a2a1-b7af89808613) Malware Process Discovery - T1057 (8f4a33ec-8b1f-4b80-a2f6-642b2e479580) Attack Pattern 1
Linfo - S0211 (e9e9bfe2-76f4-4870-a2a1-b7af89808613) Malware Windows Command Shell - T1059.003 (d1fcf083-a721-4223-aedf-bf8960798d62) Attack Pattern 1
Indicator Removal - T1070 (799ace7f-e227-4411-baa0-8868704f2a69) Attack Pattern File Deletion - T1070.004 (d63a3fb8-9452-4e9d-a60a-54be68d5998c) Attack Pattern 2
Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) Attack Pattern Windows Command Shell - T1059.003 (d1fcf083-a721-4223-aedf-bf8960798d62) Attack Pattern 2