Currently viewing ATT&CK v8.2 which was live between October 27, 2020 and April 28, 2021. Learn more about the versioning system or see the live site.

httpclient

httpclient is malware used by Putter Panda. It is a simple tool that provides a limited range of functionality, suggesting it is likely used as a second-stage or supplementary/backup tool. [1]

ID: S0068
Type: MALWARE
Platforms: Windows
Version: 1.1
Created: 31 May 2017
Last Modified: 30 March 2020

Techniques Used

Domain ID Name Use
Enterprise T1071 .001 Application Layer Protocol: Web Protocols

httpclient uses HTTP for command and control.[1]

Enterprise T1059 .003 Command and Scripting Interpreter: Windows Command Shell

httpclient opens cmd.exe on the victim.[1]

Enterprise T1573 .001 Encrypted Channel: Symmetric Cryptography

httpclient encrypts C2 content with XOR using a single byte, 0x12.[1]

Groups That Use This Software

ID Name References
G0024 Putter Panda

[1]

References