If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/software/S0170 - Helminth, Software S0170 | MIT.

site address: attack.mitre.org/software/S0170 redirected to: attack.mitre.org/software/S0170

site title: Helminth, Software S0170 MITRE ATT&CK®

Our opinion (on Sunday 16 August 2026 1:59:28 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

helminth, techniques, used, groups, that, use, this, software, references, enterprise, layer,

Text of the page (most frequently used words):
helminth (28), #enterprise (22), the (17), and (14), data (13), att (11), all (10), version (9), #groups (8), for (8), 001 (8), 2017 (7), has (7), software (6), domain (6), use (5), ics (5), mobile (5), none (5), retrieved (5), december (5), with (5), can (5), one (5), command (5), mitre (4), techniques (4), that (4), group (4), http (4), dns (4), scripting (4), cti (3), defenses (3), 2018 (3), oilrig (3), may (3), used (3), scheduled (3), task (3), persistence (3), information (3), discovery (3), local (3), encrypted (3), executable (3), its (3), server (3), over (3), sends (3), batch (3), vbscript (3), interpreter (3), windows (3), powershell (3), shortcut (3), layer (3), 2026 (2), corporation (2), are (2), cookie (2), domains (2), resources (2), reference (2), campaigns (2), components (2), analytics (2), detection (2), strategies (2), assets (2), mitigations (2), tactics (2), matrices (2), core (2), objects (2), november (2), january (2), signed (2), malware (2), unit (2), falcone (2), backdoor (2), references (2), name (2), code (2), signing (2), 002 (2), 005 (2), get (2), checked (2), exchange (2), trusted (2), subsystem (2), commands (2), net (2), permission (2), file (2), rc4 (2), files (2), module (2), log (2), download (2), transfer (2), into (2), scripts (2), via (2), encoding (2), shell (2), uses (2), script (2), clipboard (2), establishes (2), creating (2), boot (2), logon (2), autostart (2), execution (2), folder (2), application (2), protocol (2), s0170 (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, sub, meyers, meet, crowdstrike, adversary, month, helix, kitten, davis, caban, apt34, new, targeted, attack, middle, east, clearsky, cybersecurity, iranian, threat, agent, delivers, digitally, impersonates, university, oxford, playbook, viewer, lee, 2016, campaign, attacks, saudi, arabian, organizations, deliver, g0049, this, samples, have, been, legitimate, compromised, certificates, owned, company, squared, subvert, trust, controls, t1553, job, t1053, processes, tasklist, process, t1057, admin, using, admins, administrators, t1069, config, encoded, obfuscated, 013, t1027, keystrokes, keylogging, input, capture, t1056, additional, ingress, tool, t1105, encrypts, sent, symmetric, cryptography, channel, t1573, splits, chunks, bytes, queries, size, limits, t1030, creates, folders, store, output, from, prior, sending, staging, staged, t1074, encodes, base64, field, requests, converts, ascii, characters, their, hexadecimal, values, cleartext, standard, t1132, consists, visual, basic, provide, remote, 003, t1059, contents, t1115, modification, 009, start, menu, registry, run, keys, startup, t1547, receives, execute, set, prompt, automated, collection, t1119, 004, web, protocols, t1071, view, navigator, layers, live, permalink, april, 2024, last, modified, created, robert, contributors, platforms, type, least, two, variants, written, delivered, macros, excel, spreadsheets, standalone, home, open, join, october, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, more, about, started, detections,


Text of the page (random words):
helminth software s0170 mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home software helminth helminth helminth is a backdoor that has at least two variants one written in vbscript and powershell that is delivered via a macros in excel spreadsheets and one that is a standalone windows executable 1 id s0170 ⓘ type malware ⓘ platforms windows contributors robert falcone version 1 2 created 16 january 2018 last modified 11 april 2024 version permalink live version att ck navigator layers enterprise layer download view techniques used domain id name use enterprise t1071 001 application layer protocol web protocols helminth can use http for c2 1 004 application layer protocol dns helminth can use dns for c2 1 enterprise t1119 automated collection a helminth vbscript receives a batch script to execute a set of commands in a command prompt 1 enterprise t1547 001 boot or logon autostart execution registry run keys startup folder helminth establishes persistence by creating a shortcut in the start menu folder 1 009 boot or logon autostart execution shortcut modification helminth establishes persistence by creating a shortcut 1 enterprise t1115 clipboard data the executable version of helminth has a module to log clipboard contents 1 enterprise t1059 001 command and scripting interpreter powershell one version of helminth uses a powershell script 1 003 command and scripting interpreter windows command shell helminth can provide a remote shell one version of helminth uses batch scripting 1 005 command and scripting interpreter visual basic one version of helminth consists of vbscript scripts 1 enterprise t1132 001 data encoding standard encoding for c2 over http helminth encodes data with base64 and sends it via the cookie field of http requests for c2 over dns helminth converts ascii characters into their hexadecimal values and sends the data in cleartext 1 enterprise t1074 001 data staged local data staging helminth creates folders to store output from batch scripts prior to sending the information to its c2 server 1 enterprise t1030 data transfer size limits helminth splits data into chunks up to 23 bytes and sends the data in dns queries to its c2 server 1 enterprise t1573 001 encrypted channel symmetric cryptography helminth encrypts data sent to its c2 server over http with rc4 1 enterprise t1105 ingress tool transfer helminth can download additional files 1 enterprise t1056 001 input capture keylogging the executable version of helminth has a module to log keystrokes 1 enterprise t1027 013 obfuscated files or information encrypted encoded file the helminth config file is encrypted with rc4 1 enterprise t1069 001 permission groups discovery local groups helminth has checked the local administrators group 2 002 permission groups discovery domain groups helminth has checked for the domain admin group and exchange trusted subsystem groups using the commands net group exchange trusted subsystem domain and net group domain admins domain 2 enterprise t1057 process discovery helminth has used tasklist to get information on processes 2 enterprise t1053 005 scheduled task job scheduled task helminth has used a scheduled task for persistence 3 enterprise t1553 002 subvert trust controls code signing helminth samples have been signed with legitimate compromised code signing certificates owned by software company ai squared 3 groups that use this software id name references g0049 oilrig 1 4 5 references falcone r and lee b 2016 may 26 the oilrig campaign attacks on saudi arabian organizations deliver helminth backdoor retrieved may 3 2017 unit 42 2017 december 15 unit 42 playbook viewer retrieved december 20 2017 clearsky cybersecurity 2017 january 5 iranian threat agent oilrig delivers digitally signed malware impersonates university of oxford retrieved may 3 2017 davis s and caban d 2017 december 19 apt34 new targeted attack in the middle east retrieved december 20 2017 meyers a 2018 november 27 meet crowdstrike s adversary of the month for november helix kitten retrieved december 18 2018 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 77 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-77


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


The site also has 1 references to other resources (not html/xhtml )

 attack.mitre.org/software/S0170/S0170___.json  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/software/S0170
X-GitHub-Request-Id DE8E:164B5F:4D3031C:4D9F4D7:6A81197F
x-github-edge-region fra
Accept-Ranges bytes
Age 0
Date Sun, 16 Aug 2026 01:59:27 GMT
Via 1.1 varnish
X-Served-By cache-rtm-ehrd2290025-RTM
X-Cache MISS
X-Cache-Hits 0
X-Timer S1786845568.790182,VS0,VE93
Vary Accept-Encoding
X-Fastly-Request-ID d0b07a9577b545854203f89a55133f4ccc2b863c
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/software/S0170/
access-control-allow-origin *
expires Sun, 16 Aug 2026 02:09:27 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id 0B0E:1020A0:4D03898:4D7295F:6A81197F
x-github-edge-region fra
accept-ranges bytes
age 0
date Sun, 16 Aug 2026 01:59:28 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290028-RTM
x-cache MISS
x-cache-hits 0
x-timer S1786845568.922877,VS0,VE107
vary Accept-Encoding
x-fastly-request-id 1db6256a50d187adfb174378e701c61a53fbf850
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:18 GMT
access-control-allow-origin *
etag W/ 6a75ea92-10849
expires Sun, 16 Aug 2026 02:09:28 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 81E8:7640F:4FBA827:5029B19:6A81197F
x-github-edge-region fra
accept-ranges bytes
age 0
date Sun, 16 Aug 2026 01:59:28 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290028-RTM
x-cache MISS
x-cache-hits 0
x-timer S1786845568.042561,VS0,VE111
vary Accept-Encoding
x-fastly-request-id 4a2a6cda1cdb5453abe543fc2969e3582547f4bb
content-length 9025

Meta Tags

title="Helminth, Software S0170 | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size9025
load time (s)0.856089
redirect count2
speed download10543
server IP 185.199.110.153
* all occurrences of the string "http://" have been changed to "htt???/"