Copy File

April 3, 2025 ยท View on GitHub

ID C0045
Objective(s) File System
Related ATT&CK Techniques None
Version 2.2
Created 4 December 2020
Last Modified 6 February 2024

Copy File

Malware copies a file.

Use in Malware

NameDateMethodDescription
GoBotKR2019--GoBotKR copies files. [1]
Hupigon2013--Hupigon copies files. [1]
Kovter2016--Kovter copies files. [1]
Mebromi2011--Mebromi copies files. [1]
Redhip2011--Redhip copies files. [1]
Shamoon2012--Shamoon copies files. [1]
Snake2004--Snake copies files. [2]

Detection

Tool: capaMappingAPIs
copy fileCopy File (C0045)kernel32.CopyFile, kernel32.CopyFileEx, CopyFile2, CopyFileTransacted, LZCopy, System.IO.FileInfo::CopyTo, System.IO.File::Copy, kernel32.SHFileOperation
Tool: CAPEClassMappingAPIs
injection_needextensionInjectionExtensionCopy File (C0045)NtCreateUserProcess, CreateProcessInternalW

References

[1] capa v4.0, analyzed at MITRE on 10/12/2022

[2] https://www.cybereason.com/blog/research/threat-analysis-report-snake-infostealer-malware