If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/software/S0532 - Lucifer, Software S0532 | MITR.

site address: attack.mitre.org/software/S0532 redirected to: attack.mitre.org/software/S0532

site title: Lucifer, Software S0532 MITRE ATT&CK®

Our opinion (on Saturday 22 August 2026 6:34:04 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

lucifer, techniques, used, references, enterprise, layer,

Text of the page (most frequently used words):
#enterprise (30), lucifer (29), can (22), and (21), the (17), att (11), all (11), windows (11), software (8), for (8), system (7), use (6), discovery (6), ics (5), mobile (5), none (5), remote (5), 001 (5), mitre (4), techniques (4), has (4), compromised (4), host (4), network (4), information (4), version (4), are (3), resources (3), cti (3), data (3), defenses (3), 2020 (3), malware (3), with (3), identify (3), connections (3), scheduled (3), task (3), qqmusic (3), brute (3), stratum (3), microsoft (3), currentversion (3), registry (3), ports (3), tcp (3), service (3), execute (3), download (3), run (3), 2026 (2), corporation (2), domains (2), reference (2), campaigns (2), groups (2), components (2), analytics (2), detection (2), strategies (2), assets (2), mitigations (2), tactics (2), matrices (2), core (2), objects (2), cryptojacking (2), ddos (2), hybrid (2), vulnerabilities (2), infect (2), devices (2), november (2), propagation (2), check (2), usernames (2), computer (2), itself (2), username (2), port (2), collect (2), address (2), name (2), default (2), spread (2), 005 (2), mine (2), hijacking (2), smb (2), services (2), 002 (2), hklm (2), process (2), that (2), used (2), files (2), open (2), including (2), 135 (2), 1433 (2), denial (2), certutil (2), tool (2), transfer (2), cve (2), 2017 (2), 0144 (2), clear (2), event (2), logs (2), tools (2), execution (2), shell (2), command (2), force (2), protocol (2), layer (2), platforms (2), s0532 (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, sub, hsu, june, new, exploiting, high, critical, retrieved, references, wmi, log, into, machines, management, instrumentation, t1047, specific, names, device, drivers, dll, virtual, associated, sandboxed, environments, enter, infinite, loop, stop, any, detected, checks, virtualization, sandbox, evasion, t1497, ability, owner, user, t1033, numbers, from, t1049, configuration, t1016, architecture, language, processor, frequency, t1082, established, persistence, creating, following, schtasks, create, minute, users, userprofile, downloads, exe, job, t1053, cryptocurrency, dropping, xmrig, monero, compute, resource, t1496, victims, forcing, admin, shares, t1021, existing, cryptomining, spreadcpuxmr, info, query, t1012, owns, t1057, upx, packed, binaries, packing, obfuscated, t1027, scan, t1046, udp, http, dos, attacks, t1498, hosts, within, intranets, lateral, t1570, replica, using, ingress, t1105, exploit, multiple, eternalblue, eternalromance, exploitation, t1210, perform, decremental, xor, encryption, initial, request, before, sending, over, wire, symmetric, cryptography, encrypted, channel, t1573, remove, disable, modify, t1685, decrypt, its, upon, deobfuscate, decode, t1140, issue, commands, additional, payloads, scripting, interpreter, 003, t1059, attempted, rpc, mssql, list, passwords, password, guessing, t1110, persist, setting, key, values, hkcu, keys, startup, folder, boot, logon, autostart, t1547, 10001, communication, between, bot, mining, server, application, t1071, domain, view, navigator, layers, live, permalink, april, 2025, last, modified, created, daniyal, naeem, security, contributors, type, crypto, miner, leverages, well, known, exploits, laterally, home, join, october, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, advisory, council, learn, more, about, get, started, detections,


Text of the page (random words):
lucifer software s0532 mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home software lucifer lucifer lucifer is a crypto miner and ddos hybrid malware that leverages well known exploits to spread laterally on windows platforms 1 id s0532 ⓘ type malware ⓘ platforms windows contributors daniyal naeem bt security version 1 1 created 16 november 2020 last modified 25 april 2025 version permalink live version att ck navigator layers enterprise layer download view techniques used domain id name use enterprise t1071 application layer protocol lucifer can use the stratum protocol on port 10001 for communication between the cryptojacking bot and the mining server 1 enterprise t1547 001 boot or logon autostart execution registry run keys startup folder lucifer can persist by setting registry key values hklm software microsoft windows currentversion run qqmusic and hkcu software microsoft windows currentversion run qqmusic 1 enterprise t1110 001 brute force password guessing lucifer has attempted to brute force tcp ports 135 rpc and 1433 mssql with the default username or list of usernames and passwords 1 enterprise t1059 003 command and scripting interpreter windows command shell lucifer can issue shell commands to download and execute additional payloads 1 enterprise t1140 deobfuscate decode files or information lucifer can decrypt its c2 address upon execution 1 enterprise t1685 005 disable or modify tools clear windows event logs lucifer can clear and remove event logs 1 enterprise t1573 001 encrypted channel symmetric cryptography lucifer can perform a decremental xor encryption on the initial c2 request before sending it over the wire 1 enterprise t1210 exploitation of remote services lucifer can exploit multiple vulnerabilities including eternalblue cve 2017 0144 and eternalromance cve 2017 0144 1 enterprise t1105 ingress tool transfer lucifer can download and execute a replica of itself using certutil 1 enterprise t1570 lateral tool transfer lucifer can use certutil for propagation on windows hosts within intranets 1 enterprise t1498 network denial of service lucifer can execute tcp udp and http denial of service dos attacks 1 enterprise t1046 network service discovery lucifer can scan for open ports including tcp ports 135 and 1433 1 enterprise t1027 002 obfuscated files or information software packing lucifer has used upx packed binaries 1 enterprise t1057 process discovery lucifer can identify the process that owns remote connections 1 enterprise t1012 query registry lucifer can check for existing stratum cryptomining information in hklm software microsoft windows currentversion spreadcpuxmr stratum info 1 enterprise t1021 002 remote services smb windows admin shares lucifer can infect victims by brute forcing smb 1 enterprise t1496 001 resource hijacking compute hijacking lucifer can use system resources to mine cryptocurrency dropping xmrig to mine monero 1 enterprise t1053 005 scheduled task job scheduled task lucifer has established persistence by creating the following scheduled task schtasks create sc minute mo 1 tn qqmusic tr c users userprofile downloads spread exe f 1 enterprise t1082 system information discovery lucifer can collect the computer name system architecture default language and processor frequency of a compromised host 1 enterprise t1016 system network configuration discovery lucifer can collect the ip address of a compromised host 1 enterprise t1049 system network connections discovery lucifer can identify the ip and port numbers for all remote connections from the compromised host 1 enterprise t1033 system owner user discovery lucifer has the ability to identify the username on a compromised host 1 enterprise t1497 001 virtualization sandbox evasion system checks lucifer can check for specific usernames computer names device drivers dll s and virtual devices associated with sandboxed environments and can enter an infinite loop and stop itself if any are detected 1 enterprise t1047 windows management instrumentation lucifer can use wmi to log into remote machines for propagation 1 references hsu k et al 2020 june 24 lucifer new cryptojacking and ddos hybrid malware exploiting high and critical vulnerabilities to infect windows devices retrieved november 16 2020 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 78 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-78


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


The site also has 1 references to other resources (not html/xhtml )

 attack.mitre.org/software/S0532/S0532___.json  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/software/S0532
X-GitHub-Request-Id 67B4:34F8D5:2494EC:263E66:6A8942DB
x-github-edge-region uksouth
Accept-Ranges bytes
Age 0
Date Sat, 22 Aug 2026 06:34:04 GMT
Via 1.1 varnish
X-Served-By cache-lcy-egml8630067-LCY
X-Cache MISS
X-Cache-Hits 0
X-Timer S1787380444.990376,VS0,VE80
Vary Accept-Encoding
X-Fastly-Request-ID b01d2fd10be64ed3aa7f5f4186a73dd023bdaa95
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/software/S0532/
access-control-allow-origin *
expires Sat, 22 Aug 2026 06:44:04 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id B7D0:19B99D:24479F:25F13F:6A8942D7
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Sat, 22 Aug 2026 06:34:04 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630031-LCY
x-cache MISS
x-cache-hits 0
x-timer S1787380444.096542,VS0,VE82
vary Accept-Encoding
x-fastly-request-id 194019b2391f5762d7c07d37030635af063b95fa
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:21 GMT
access-control-allow-origin *
etag W/ 6a75ea95-101e1
expires Sat, 22 Aug 2026 06:44:04 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 6EA8:3C500E:24B97A:266312:6A8942DC
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Sat, 22 Aug 2026 06:34:04 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630031-LCY
x-cache MISS
x-cache-hits 0
x-timer S1787380444.186232,VS0,VE90
vary Accept-Encoding
x-fastly-request-id bf297314a35d94c34efbbe643c5d2ba85a557ad2
content-length 8657

Meta Tags

title="Lucifer, Software S0532 | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size8657
load time (s)0.567404
redirect count2
speed download15268
server IP 185.199.110.153
* all occurrences of the string "http://" have been changed to "htt???/"