3.1 Updates (#145)

* E/f updates (#143)

* E/F Update,  Update Install Cert ID

* Small fixes

* Update common objects link (#142)

* Update README.md

* Update 09152023.md

* Update README.md

* Update 12182023.md

* Adding descriptions to micro-behaviors

* Fixing dead links

* V3.1 updates (#144)

* minor fixes for v3.1

* correct id

---------

Co-authored-by: Desiree Beck <dbeck@mitre.org>
This commit is contained in:
Ryan Xu
2024-02-14 09:27:20 -05:00
committed by GitHub
parent ad05fb07ba
commit 009ae77217
50 changed files with 145 additions and 121 deletions
+1 -1
View File
@@ -62,7 +62,7 @@ The canonical representation for MBC content is **OBJECTIVE::Behavior::Method**.
Objectives and behaviors can be used alone, but a method *must* be associated with a behavior.
### STIX 2.1 Representation ###
A STIX 2.1 representation for MBC v3.0 is available in the [mbc-stix2.1](https://github.com/MBCProject/mbc-stix2.1) repository. It's based on a refined STIX 2.1 [Malware Behavior Extension](https://github.com/oasis-open/cti-stix-common-objects/tree/main/extension-definition-specifications/malware-behavior) that includes new STIX domain objects for MBC objectives, behaviors, and methods.
A STIX 2.1 representation for MBC v3.0 is available in the [mbc-stix2.1](https://github.com/MBCProject/mbc-stix2.1) repository. It's based on a refined STIX 2.1 [Malware Behavior Extension](https://github.com/oasis-open/cti-stix-common-objects/tree/main/extension-definition-specifications/malware-behavior-8e9) that includes new STIX domain objects for MBC objectives, behaviors, and methods.
### Navigator View ###
This visual representation of the MBC Matrix is based on the ATT&CK Navigator. Two views are available:
@@ -17,7 +17,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -25,7 +25,7 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
@@ -153,7 +153,7 @@ Details on detecting debuggers can be found in the references.
<a name="3">[3]</a> Peter Ferrie, "The 'Ultimate' Anti-Debugging Reference," 4 May 2011. https://anti-reversing.com/Downloads/Anti-Reversing/The_Ultimate_Anti-Reversing_Reference.pdf.
<a name="4">[4]</a> https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
<a name="4">[4]</a> https://web.archive.org/web/20200815134441/https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
<a name="5">[5]</a> Ayoub Faouzi (LordNoteworthy), Al-Khaser v0.79. https://github.com/LordNoteworthy/al-khaser
+3 -3
View File
@@ -17,7 +17,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -25,7 +25,7 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
@@ -103,6 +103,6 @@ The related **Debugger Evasion ([T1622](https://attack.mitre.org/techniques/T162
<a name="2">[2]</a> https://web.archive.org/web/20210225195315/https://www.synack.com/blog/analyzing-the-anti-analysis-logic-of-an-adware-installer/
<a name="3">[3]</a> https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
<a name="3">[3]</a> https://web.archive.org/web/20200815134441/https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
<a name="4">[4]</a> https://securitynews.sonicwall.com/xmlpost/revisiting-vobfus-worm-mar-8-2013/
@@ -17,7 +17,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -25,7 +25,7 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
@@ -138,7 +138,7 @@ mov bl, 1
<a name="2">[2]</a> Splunk Threat Research Team,"From Macros to No Macros: Continuous Malware Improvements by QakBot," Splunk, blog,, 01 December 2022. [Online]. Available: https://www.splunk.com/en_us/blog/security/from-macros-to-no-macros-continuous-malware-improvements-by-qakbot.html.
<a name="3">[3]</a> https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
<a name="3">[3]</a> https://web.archive.org/web/20200815134441/https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
<a name="4">[4]</a> https://blogs.cisco.com/security/talos/rombertik
@@ -17,7 +17,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -25,7 +25,7 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
@@ -238,7 +238,7 @@ jmp short loc_401CBB
<a name="5">[5]</a> https://github.com/LordNoteworthy/al-khaser
<a name="6">[6]</a> https://web.archive.org/web/20161025013916/https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
<a name="6">[6]</a> https://web.archive.org/web/20161025013916/https://web.archive.org/web/20200815134441/https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
<a name="7">[7]</a> https://securelist.com/the-banking-trojan-emotet-detailed-analysis/69560/
+3 -3
View File
@@ -17,7 +17,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -25,7 +25,7 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
@@ -61,7 +61,7 @@ Anti-disassembly techniques take advantage of weaknesses in either flow-oriented
<a name="1">[1]</a> M. Sikorski and A. Honig, Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software, No Starch Press, 2012.
<a name="2">[2]</a> https://staff.ustc.edu.cn/~bjhua/courses/security/2014/readings/anti-disas.pdf
<a name="2">[2]</a> https://web.archive.org/web/20220814013655/http://staff.ustc.edu.cn/~bjhua/courses/security/2014/readings/anti-disas.pdf
<a name="3">[3]</a> https://www.kernelhacking.com/rodrigo/docs/blackhat2012-paper.pdf
+3 -3
View File
@@ -17,7 +17,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -25,7 +25,7 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
@@ -123,7 +123,7 @@ This description refines the ATT&CK **Obfuscated Files or Information: Software
<a name="2">[2]</a> Jiang Ming et al, Towards Paving the Way for Large-Scale Windows Malware Analysis: Generic Binary Unpacking with Orders-of-Magnitude Performance Boost, October 2018, https://dl.acm.org/citation.cfm?id=3243771
<a name="3">[3]</a> https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
<a name="3">[3]</a> https://web.archive.org/web/20200815134441/https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
<a name="4">[4]</a> https://blog.malwarebytes.com/threat-analysis/2016/07/untangling-kovter/
+1 -1
View File
@@ -28,7 +28,7 @@
# Input Capture
Malware captures user input.
Malware may record user inputs, typically without the user's knowledge. This is often used to capture sensitive information such as usernames, passwords, credit card numbers, and other personal data. The most common form of input capture is keylogging, where the malware records every keystroke made on a device. However, it can also involve capturing mouse clicks, touch screen interactions, or even voice inputs. The captured data is then usually transmitted to the attacker for use in further malicious activities like identity theft or unauthorized access.
See ATT&CK: **Input Capture ([T1056](https://attack.mitre.org/techniques/T1056), [T1417](https://attack.mitre.org/techniques/T1417/))**.
+3 -3
View File
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,7 +21,7 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
@@ -82,7 +82,7 @@ See ATT&CK: **Input Capture: Keylogging ([T1056.001](https://attack.mitre.org/te
<a name="5">[5]</a> https://www.cyber.nj.gov/threat-center/threat-profiles/trojan-variants/poison-ivy
<a name="6">[6]</a> https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf
<a name="6">[6]</a> https://web.archive.org/web/20210307034415/https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf
<a name="7">[7]</a> capa v4.0, analyzed at MITRE on 10/12/2022
+4 -4
View File
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,14 +21,14 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
# Screen Capture
Malware takes screen captures of the desktop.
Malware takes screen captures of the desktop. This technique is often used by cyber attackers to gather sensitive information, such as login credentials, personal data, or confidential documents. The malware can use various methods to capture the screen, including using built-in functions of the operating system or third-party libraries. The captured screenshots are then typically sent back to the attacker's command and control server. This technique is commonly used by spyware, information stealers, and advanced persistent threats (APTs).
See ATT&CK: **Screen Capture ([T1113](https://attack.mitre.org/techniques/T1113/))**.
@@ -70,7 +70,7 @@ See ATT&CK: **Screen Capture ([T1113](https://attack.mitre.org/techniques/T1113/
<a name="3">[3]</a> https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/
<a name="4">[4]</a> https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf
<a name="4">[4]</a> https://web.archive.org/web/20210307034415/https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf
<a name="5">[5]</a> capa v4.0, analyzed at MITRE on 10/12/2022
+3 -3
View File
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.2</b></td>
<td><b>2.3</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,7 +21,7 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
@@ -159,7 +159,7 @@ jmp short loc_4019A2
<a name="7">[7]</a> https://securelist.com/the-banking-trojan-emotet-detailed-analysis/69560/
<a name="8">[8]</a> https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf
<a name="8">[8]</a> https://web.archive.org/web/20210307034415/https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf
<a name="9">[9]</a> https://unit42.paloaltonetworks.com/tracking-minidionis-cozycars-new-ride-is-related-to-seaduke
+1 -1
View File
@@ -28,7 +28,7 @@
# Bootkit
The boot sectors of a hard drive are modified (e.g., Master Boot Record (MBR)). ATT&CK associates bootkits with the Persistence. See ATT&CK: **Pre-OS Boot: Bootkit ([T1067](https://attack.mitre.org/techniques/T1067/))**.
The boot sectors of a hard drive are modified (e.g., Master Boot Record (MBR)). ATT&CK associates bootkits with the Persistence. See ATT&CK: **Pre-OS Boot: Bootkit ([T1542.003](https://attack.mitre.org/techniques/T1542/003/))**.
The MBC also associates the Bootkit behavior with Defense Evasion because the malware may execute before or external to the system's kernel or hypervisor (e.g., through the BIOS), making it more difficult to detect. (As of 2020, ATT&CK also associates the technique with Persistence.)
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.2</b></td>
<td><b>2.3</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,14 +21,14 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
# Hidden Files and Directories
Malware may hide files and folders to avoid detection and/or to persist on the system. See potential methods below.
Malware may hide files and folders to avoid detection and/or to persist on the system. See potential methods below. This is achieved by marking files or directories as hidden or by using special characters in file names to prevent them from being displayed in standard directory listings. By hiding files or directories, malware can evade detection from users and some security software.
This behavior is related to Unprotect technique U1230.
@@ -73,7 +73,7 @@ See ATT&CK: **Hide Artifacts: Hidden Files and Directories ([T1564.001](https://
<a name="2">[2]</a> https://www.mcafee.com/blogs/other-blogs/mcafee-labs/shamoon-returns-to-wipe-systems-in-middle-east-europe/
<a name="3">[3]</a> https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf
<a name="3">[3]</a> https://web.archive.org/web/20210307034415/https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf
<a name="4">[4]</a> https://securitynews.sonicwall.com/xmlpost/revisiting-vobfus-worm-mar-8-2013/
+3 -1
View File
@@ -28,7 +28,9 @@
# Hide Artifacts
Malware may hide artifacts to evade detection and/or to persist on the system. See potential methods related to malware below.
Malware may conceal its presence and activities on a system. This can involve hiding files, directories, or other data that could reveal the malware's existence or behavior. Techniques can include using encryption or obfuscation, altering file timestamps, or manipulating data to blend in with normal system activity. The goal is to avoid detection by security tools and to prolong the period during which the malware can operate undetected on the victim's system.
See potential methods related to malware below.
See ATT&CK: **Hide Artifacts ([T1564](https://attack.mitre.org/techniques/T1564/), [T1628](https://attack.mitre.org/techniques/T1628/))**.
+1 -1
View File
@@ -28,7 +28,7 @@
# Indicator Blocking
Malware blocks indicators or events that would indicate malicious activity. Methods relevant to the malware domain are below.
Malware blocks indicators or events that would indicate malicious activity. This is achieved by blocking indicators or alerts that would typically notify users or security tools of a potential infection. This can be done in several ways, such as disabling security software, interfering with event logging, or altering system settings to suppress notifications. By blocking these indicators, the malware can continue its malicious activities without being detected. Methods relevant to the malware domain are below.
See ATT&CK: **Impair Defenses: Indicator Blocking ([T1562.006](https://attack.mitre.org/techniques/T1562/006/))**.
+4 -4
View File
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,14 +21,14 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
# Modify Registry
Malware may make changes to the Windows Registry to hide execution or to persist on the system (note that ATT&CK does not extend this behavior to the Persistence objective).
Malware may make changes to the Windows Registry to hide execution or to persist on the system (note that ATT&CK does not extend this behavior to the Persistence objective). The Windows registry is a database that stores low-level settings for the operating system and for applications that opt to use the registry. Malware may create, delete, or modify registry keys and values to change the behavior of the system or certain applications. For instance, malware may modify registry keys to enable remote desktop connections, disable security features, or to automatically start the malware whenever the system boots. This technique is commonly used by various types of malware, including ransomware, trojans, and worms.
See ATT&CK: **Modify Registry ([T1112](https://attack.mitre.org/techniques/T1112/))**.
@@ -131,7 +131,7 @@ See ATT&CK: **Modify Registry ([T1112](https://attack.mitre.org/techniques/T1112
<a name="6">[6]</a> https://www.mcafee.com/blogs/other-blogs/mcafee-labs/shamoon-returns-to-wipe-systems-in-middle-east-europe/
<a name="7">[7]</a> https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf
<a name="7">[7]</a> https://web.archive.org/web/20210307034415/https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf
<a name="8">[8]</a> https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/clipminer-bitcoin-mining-hijacking
+3 -3
View File
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,7 +21,7 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
@@ -52,7 +52,7 @@ Polymorphic code, a file with the same functionality but different execution, is
## References
<a name="1">[1]</a> https://www.mccormick.northwestern.edu/eecs/documents/tech-reports/2010-2014/evaluating-android-anti-malware-against-transformation-attacks.pdf
<a name="1">[1]</a> https://pages.cs.wisc.edu/~vrastogi/static/papers/rcj13b.pdf
<a name="2">[2]</a> https://web.archive.org/web/20150311013500/http://www.cyphort.com/evilbunny-malware-instrumented-lua/
+1 -1
View File
@@ -30,7 +30,7 @@
# Self Deletion
Malware may uninstall itself to avoid detection.
Malware may remove itself from an infected system, typically after it has achieved its primary objective. This is done to evade detection, remove evidence of its presence, and make forensic analysis more difficult. The malware may use built-in commands, scripts, or other methods to delete its files, processes, or registry entries.
See ATT&CK: **Indicator Removal on Host: Uninstall Malicious Application ([T1630.001](https://attack.mitre.org/techniques/T1630/001/)), Indicator Removal on Host: File Deletion ([T1070.004](https://attack.mitre.org/techniques/T1070/004/))**.
+4 -4
View File
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,14 +21,14 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
# System Information Discovery
Malware may attempt to get detailed information about the system.
Malware may attempt to get detailed information about the system. This can include details about the operating system, hardware configurations, installed software, system uptime, and other system-level details.
See ATT&CK: **System Information Discovery ([T1082](https://attack.mitre.org/techniques/T1082/))**.
@@ -113,7 +113,7 @@ See ATT&CK: **System Information Discovery ([T1082](https://attack.mitre.org/tec
<a name="5">[5]</a> https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en
<a name="6">[6]</a> https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf
<a name="6">[6]</a> https://web.archive.org/web/20210307034415/https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf
<a name="7">[7]</a> https://www.securityartwork.es/wp-content/uploads/2017/07/Trickbot-report-S2-Grupo.pdf
+3 -3
View File
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.0</b></td>
<td><b>2.1</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,7 +21,7 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>1 February 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
@@ -40,5 +40,5 @@ A malicious attachment is sent via spam SMS or MMS messages. When the user click
<a name="1">[1]</a> https://us.norton.com/internetsecurity-emerging-threats-mazar-bot-malware-invades-and-erases-android-devices.html
<a name="2">[2]</a> https://www.player.one/new-android-sms-malware-can-completely-own-your-phone-just-one-text-how-avoid-mazar-512363
<a name="2">[2]</a> https://www.player.one/stub-56857
+1 -1
View File
@@ -28,7 +28,7 @@
# System Services
Malware may abuse system services or daemons to execute.
Malware may manipulate, create, or interact with system services to achieve persistence, gain higher privileges, or execute malicious code. System services are background processes that are integral parts of an operating system's functionality. Malware can exploit these services by modifying their configurations, replacing legitimate service binaries with malicious ones, or creating new services that run malicious code.
See ATT&CK: **System Services ([T1569](https://attack.mitre.org/techniques/T1569/))**.
+3 -3
View File
@@ -17,7 +17,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>3.0</b></td>
<td><b>3.1</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -25,7 +25,7 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>12 February 2024</b></td>
</tr>
</table>
@@ -34,7 +34,7 @@
ATT&CK defines Clipboard Modification as a Mobile technique (Android platform). MBC extends it to the Windows platform.
After E1510 was defined, T1510 was replaced by T1610.001, and Clipboard Data (<a href="https://attack.mitre.org/techniques/T1115/">T1115</a>) was updated to include content modification.
After E1510 was defined, T1510 was replaced by T1641.001, and Clipboard Data (<a href="https://attack.mitre.org/techniques/T1115/">T1115</a>) was updated to include content modification.
## Use in Malware
+1 -1
View File
@@ -32,7 +32,7 @@
# Exploit Kit
An Exploit Kit is a toolkit that exploits vulnerabilities in software to deliver malicious payloads (malware).
An exploit kit is a software system designed to exploit known vulnerabilities. Exploit kits typically include pre-written exploit code for known vulnerabilities and mechanisms to deliver the payload, such as malware, ransomware, or spyware, onto the victim's system. These kits are typically used by cybercriminals and are often sold on the dark web. They automate the exploitation process, making it easier for individuals with limited technical skills to launch attacks.
See related ATT&CK Technique: **Exploit Public-Facing Application ([T1190](https://attack.mitre.org/techniques/T1190))**, which relates to Initial Access. Under the Impact objective, exploit behaviors are considered more broadly in MBC.
+1 -1
View File
@@ -32,7 +32,7 @@
# Generate Traffic from Victim
Malware may generate traffic from the victim system such as clicks of advertising links that generate fraudulent ad revenue. The ATT&CK technique, **Generate Traffic from Victim ([T1643](https://attack.mitre.org/techniques/T1643/))**, is only associated with the mobile platform, but the behavior is applicable to other platforms as well.
Malware may generate network traffic from a victim's system to achieve various malicious objectives. This could include disguising its own traffic, overwhelming a network with high traffic volume (Denial of Service attacks), exhausting the victim's system resources, or simulate clicks of advertising links that generate fraudulent ad revenue. The generated traffic can also be used to trigger network-based rules, alerts, or other types of indicators. This technique can make it difficult for defenders to identify malicious activity and can potentially lead to false positives. The ATT&CK technique, **Generate Traffic from Victim ([T1643](https://attack.mitre.org/techniques/T1643/))**, is only associated with the mobile platform, but the behavior is applicable to other platforms as well.
## Methods
+3 -3
View File
@@ -158,7 +158,7 @@
|E1510|**[Clipboard Modification](https://github.com/MBCProject/mbc-markdown/blob/main/impact/clipboard-modification.md)**|IMPACT|
|E1059|**[Command and Scripting Interpreter](https://github.com/MBCProject/mbc-markdown/blob/main/execution/command-and-scripting-interpreter.md)**|EXECUTION|
|E1485|**[Data Destruction](https://github.com/MBCProject/mbc-markdown/blob/main/impact/data-destruction.md)**|IMPACT|
|E1486|**[Data Encrypted for Impact ](https://github.com/MBCProject/mbc-markdown/blob/main/impact/data-encrypted-for-impact-.md)**|IMPACT|
|E1486|**[Data Encrypted for Impact ](https://github.com/MBCProject/mbc-markdown/blob/main/impact/data-encrypted-for-impact.md)**|IMPACT|
|E1190|**[Exploit Kit](https://github.com/MBCProject/mbc-markdown/blob/main/impact/exploit-kit.md)**|IMPACT|
|E1203|**[Exploitation for Client Execution](https://github.com/MBCProject/mbc-markdown/blob/main/execution/exploitation-for-client-execution.md)**|EXECUTION, IMPACT|
|E1083|**[File and Directory Discovery](https://github.com/MBCProject/mbc-markdown/blob/main/discovery/file-and-directory-discovery.md)**|DISCOVERY|
@@ -166,7 +166,6 @@
|E1564|**[Hide Artifacts](https://github.com/MBCProject/mbc-markdown/blob/main/defense-evasion/hide-artifacts.md)**|DEFENSE EVASION, PERSISTENCE|
|E1105|**[Ingress Tool Transfer](https://github.com/MBCProject/mbc-markdown/blob/main/command-and-control/ingress-tool-transfer.md)**|COMMAND AND CONTROL, LATERAL MOVEMENT, PERSISTENCE|
|E1056|**[Input Capture](https://github.com/MBCProject/mbc-markdown/blob/main/collection/input-capture.md)**|COLLECTION, CREDENTIAL ACCESS|
|E1608|**[Install Certificate](https://github.com/MBCProject/mbc-markdown/blob/main/privilege-escalation/install-certificate.md)**|PRIVILEGE ESCALATION|
|E1112|**[Modify Registry](https://github.com/MBCProject/mbc-markdown/blob/main/defense-evasion/modify-registry.md)**|DEFENSE EVASION, PERSISTENCE|
|E1027|**[Obfuscated Files or Information](https://github.com/MBCProject/mbc-markdown/blob/main/defense-evasion/obfuscated-files-or-information.md)**|ANTI-STATIC ANALYSIS, DEFENSE EVASION|
|E1055|**[Process Injection](https://github.com/MBCProject/mbc-markdown/blob/main/defense-evasion/process-injection.md)**|DEFENSE EVASION, PRIVILEGE ESCALATION|
@@ -187,10 +186,11 @@
|F0005|**[Hidden Files and Directories](https://github.com/MBCProject/mbc-markdown/blob/main/defense-evasion/hidden-files-and-directories.md)**|DEFENSE EVASION, PERSISTENCE|
|F0015|**[Hijack Execution Flow](https://github.com/MBCProject/mbc-markdown/blob/main/defense-evasion/hijack-execution-flow.md)**|ANTI-BEHAVIORAL ANALYSIS, COLLECTION, CREDENTIAL ACCESS, DEFENSE EVASION, PERSISTENCE, PRIVILEGE ESCALATION|
|F0006|**[Indicator Blocking](https://github.com/MBCProject/mbc-markdown/blob/main/defense-evasion/indicator-blocking.md)**|DEFENSE EVASION|
|F0016|**[Install Certificate](https://github.com/MBCProject/mbc-markdown/blob/main/privilege-escalation/install-certificate.md)**|PRIVILEGE ESCALATION|
|F0010|**[Kernel Modules and Extensions](https://github.com/MBCProject/mbc-markdown/blob/main/persistence/kernel-modules-and-extensions.md)**|PERSISTENCE, PRIVILEGE ESCALATION|
|F0002|**[Keylogging](https://github.com/MBCProject/mbc-markdown/blob/main/collection/keylogging.md)**|COLLECTION, CREDENTIAL ACCESS|
|F0011|**[Modify Existing Service](https://github.com/MBCProject/mbc-markdown/blob/main/persistence/modify-existing-service.md)**|PERSISTENCE, PRIVILEGE ESCALATION|
|F0012|**[Registry Run Keys / Startup Folder](https://github.com/MBCProject/mbc-markdown/blob/main/persistence/registry-run-keys-/-startup-folder.md)**|PERSISTENCE|
|F0012|**[Registry Run Keys / Startup Folder](https://github.com/MBCProject/mbc-markdown/blob/main/persistence/registry-run-keys-startup-folder.md)**|PERSISTENCE|
|F0007|**[Self Deletion](https://github.com/MBCProject/mbc-markdown/blob/main/defense-evasion/self-deletion.md)**|DEFENSE EVASION|
|F0001|**[Software Packing](https://github.com/MBCProject/mbc-markdown/blob/main/anti-static-analysis/software-packing.md)**|ANTI-BEHAVIORAL ANALYSIS, ANTI-STATIC ANALYSIS, DEFENSE EVASION|
+3 -3
View File
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,7 +21,7 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
@@ -171,7 +171,7 @@ retn
<a name="4">[4]</a> https://www.mandiant.com/sites/default/files/2021-09/rpt-poison-ivy.pdf
<a name="5">[5]</a> https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf
<a name="5">[5]</a> https://web.archive.org/web/20210307034415/https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf
<a name="6">[6]</a> https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/
+4 -2
View File
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.0</b></td>
<td><b>2.1</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,13 +21,15 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
# Compression Library
Malware may utilize a compression library.
## Use in Malware
|Name|Date|Method|Description|
+4 -2
View File
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,13 +21,15 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
# Copy File
Malware copies a file.
## Use in Malware
|Name|Date|Method|Description|
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,13 +21,15 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
# Create Directory
Malware creates a directory.
## Use in Malware
|Name|Date|Method|Description|
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.0</b></td>
<td><b>2.1</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,13 +21,15 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>13 September 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
# Delete Directory
Malware deletes a directory.
## Use in Malware
|Name|Date|Method|Description|
+4 -2
View File
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,13 +21,15 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
# Delete File
Malware deletes a file.
## Use in Malware
|Name|Date|Method|Description|
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.0</b></td>
<td><b>2.1</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,13 +21,15 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>13 September 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
# Get File Attributes
Malware gets file attributes.
## Use in Malware
|Name|Date|Method|Description|
+4 -2
View File
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,13 +21,15 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
# Move File
Malware moves a file.
## Use in Malware
|Name|Date|Method|Description|
+4 -2
View File
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,13 +21,15 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
# Read File
Malware reads a file.
## Use in Malware
|Name|Date|Method|Description|
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.0</b></td>
<td><b>2.1</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,13 +21,15 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>13 September 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
# Set File Attributes
Malware sets file attributes.
## Use in Malware
|Name|Date|Method|Description|
+4 -2
View File
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,13 +21,15 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
# Writes File
Malware writes to a file.
## Use in Malware
|Name|Date|Method|Description|
+4 -2
View File
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,13 +21,15 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
# Create Thread
Malware creates a thread.
## Use in Malware
|Name|Date|Method|Description|
+4 -2
View File
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.0</b></td>
<td><b>2.1</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,13 +21,15 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>13 September 2023</b></td>
<td><b>6 February 2024</b></td>
</tr>
</table>
# Resume Thread
Malware resumes a thread.
## Use in Malware
|Name|Date|Method|Description|
+1 -1
View File
@@ -21,4 +21,4 @@ Behaviors that enable malware to obtain higher level permissions. These behavior
* **Kernel Modules and Extensions** [F0010](../persistence/kernel-modules-and-extensions.md)
* **Modify Existing Service** [F0011](../persistence/modify-existing-service.md)
* **Process Injection** [E1055](../defense-evasion/process-injection.md)
* **Install Certificate** [E1608](../privilege-escalation/install-certificate.md)
* **Install Certificate** [F0016](../privilege-escalation/install-certificate.md)
+4 -4
View File
@@ -1,7 +1,7 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>E1608</b></td>
<td><b>F0016</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
@@ -13,7 +13,7 @@
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.0</b></td>
<td><b>2.1</b></td>
</tr>
<tr>
<td><b>Created</b></td>
@@ -21,14 +21,14 @@
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>17 August 2022</b></td>
<td><b>10 February 2024</b></td>
</tr>
</table>
# Install Certificate
Malware may install a certificate to gain access to https traffic.
Malware may install a malicious or fraudulent certificate onto a victim's system. This can be used to facilitate a variety of attacks, such as man-in-the-middle attacks, where the attacker intercepts and potentially alters communication between two parties without their knowledge. By installing a certificate, the malware can trick the system into trusting it, allowing the attacker to bypass security measures, intercept sensitive data, or deliver additional malicious payloads. This technique can also be used to impersonate websites or services, tricking the user into revealing sensitive information.
## Use in Malware
File diff suppressed because one or more lines are too long
@@ -114,7 +114,7 @@
}
},
"name": "Install Certificate",
"technique_id": "E1608",
"technique_id": "F0016",
"description": "The malware installs a certificate",
"confidence": 100,
"effect_refs": [
+1 -1
View File
@@ -59,4 +59,4 @@ SHA256 Hashes
## References
<a name="1">[1]</a> https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf
<a name="1">[1]</a> https://web.archive.org/web/20210307034415/https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf
+16 -18
View File
@@ -34,15 +34,15 @@ DNSChanger is used to change DNS settings to generate fraudulent advertising rev
|Name|Use|
|---|---|
|[Defense Evasion::File and Directory Permissions Modification (T1222)](https://attack.mitre.org/techniques/T1222)|DNSChanger sets file attributes. [[3]](#3)|
|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|DNSChanger accesses PE headers. [[3]](#3)|
|[Defense Evasion::File and Directory Permissions Modification (T1222)](https://attack.mitre.org/techniques/T1222)|DNSChanger sets file attributes. [[2]](#2)|
|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|DNSChanger accesses PE headers. [[2]](#2)|
## ATT&CK Techniques
|Name|Use|
|---|---|
|[Defense Evasion::File and Directory Permissions Modification (T1222)](https://attack.mitre.org/techniques/T1222)|Set file attributes (This capa rule had 1 match) [[3]](#3)|
|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Access PE header (This capa rule had 3 matches) [[3]](#3)|
|[Defense Evasion::File and Directory Permissions Modification (T1222)](https://attack.mitre.org/techniques/T1222)|Set file attributes (This capa rule had 1 match) [[2]](#2)|
|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Access PE header (This capa rule had 3 matches) [[2]](#2)|
## Enhanced ATT&CK Techniques
@@ -50,22 +50,22 @@ DNSChanger is used to change DNS settings to generate fraudulent advertising rev
|---|---|
|[Impact::Generate Traffic from Victim::Advertisement Replacement Fraud (E1643.m02)](../impact/generate-traffic-from-victim.md)|The malware alters DNS server settings to route to a rogue DNS server for the purpose of click hijacking. [[1]](#1)|
|[Defense Evasion::Disable or Evade Security Tools (F0004)](../defense-evasion/disable-or-evade-security-tools.md)|DNSChanger prevents the infected system from installing anti-virus software updates. [[1]](#1)|
|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|DNSChanger encodes data using XOR. [[3]](#3)|
|[Defense Evasion::Process Injection (E1055)](../defense-evasion/process-injection.md)|DNSChanger attaches user process memory. [[3]](#3)|
|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|DNSChanger encodes data using XOR. [[2]](#2)|
|[Defense Evasion::Process Injection (E1055)](../defense-evasion/process-injection.md)|DNSChanger attaches user process memory. [[2]](#2)|
## MBC Behaviors
|Name|Use|
|---|---|
|[Cryptography::Encrypt Data::RC4 (C0027.009)](../micro-behaviors/cryptography/encrypt-data.md)|DNSChanger encrypts data using RC4 PRGA. [[3]](#3)|
|[Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|DNSChanger encodes data using XOR. [[3]](#3)|
|[File System::Get File Attributes (C0049)](../micro-behaviors/file-system/get-file-attributes.md)|DNSChanger gets file attributes. [[3]](#3)|
|[File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|DNSChanger reads files on Windows. [[3]](#3)|
|[File System::Set File Attributes (C0050)](../micro-behaviors/file-system/set-file-attributes.md)|DNSChanger sets file attributes. [[3]](#3)|
|[File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|DNSChanger writes Fileon Windows. [[3]](#3)|
|[Memory::Allocate Memory (C0007)](../micro-behaviors/memory/allocate-memory.md)|DNSChanger allocates RWX memory. [[3]](#3)|
|[Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|DNSChanger queries or enumerates registry values. [[3]](#3)|
|[Operating System::Registry::Set Registry Key (C0036.001)](../micro-behaviors/operating-system/registry.md)|DNSChanger sets registry keys. [[3]](#3)|
|[Cryptography::Encrypt Data::RC4 (C0027.009)](../micro-behaviors/cryptography/encrypt-data.md)|DNSChanger encrypts data using RC4 PRGA. [[2]](#2)|
|[Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|DNSChanger encodes data using XOR. [[2]](#2)|
|[File System::Get File Attributes (C0049)](../micro-behaviors/file-system/get-file-attributes.md)|DNSChanger gets file attributes. [[2]](#2)|
|[File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|DNSChanger reads files on Windows. [[2]](#2)|
|[File System::Set File Attributes (C0050)](../micro-behaviors/file-system/set-file-attributes.md)|DNSChanger sets file attributes. [[2]](#2)|
|[File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|DNSChanger writes Fileon Windows. [[2]](#2)|
|[Memory::Allocate Memory (C0007)](../micro-behaviors/memory/allocate-memory.md)|DNSChanger allocates RWX memory. [[2]](#2)|
|[Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|DNSChanger queries or enumerates registry values. [[2]](#2)|
|[Operating System::Registry::Set Registry Key (C0036.001)](../micro-behaviors/operating-system/registry.md)|DNSChanger sets registry keys. [[2]](#2)|
## Indicators of Compromise
@@ -77,6 +77,4 @@ SHA256 Hashes
<a name="1">[1]</a> https://www.huffingtonpost.com/2011/11/09/click-hijack-hackers-online-ad-scam_n_1084497.html
<a name="2">[2]</a> https://www.joesandbox.com/analysis/258032/0/html
<a name="3">[3]</a> capa v4.0, analyzed at MITRE on 10/12/2022
<a name="2">[2]</a> capa v4.0, analyzed at MITRE on 10/12/2022
+1 -1
View File
@@ -58,6 +58,6 @@ SHA256 Hashes
<a name="1">[1]</a> https://us.norton.com/internetsecurity-emerging-threats-mazar-bot-malware-invades-and-erases-android-devices.html
<a name="2">[2]</a> https://www.player.one/new-android-sms-malware-can-completely-own-your-phone-just-one-text-how-avoid-mazar-512363
<a name="2">[2]</a> https://www.player.one/stub-56857
<a name="3">[3]</a> https://heimdalsecurity.com/blog/security-alert-mazar-bot-active-attacks-android-malware/
+1 -1
View File
@@ -96,7 +96,7 @@ SHA256 Hashes
## References
<a name="1">[1]</a> https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
<a name="1">[1]</a> https://web.archive.org/web/20200815134441/https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
<a name="2">[2]</a> capa v4.0, analyzed at MITRE on 10/12/2022
+1 -1
View File
@@ -46,7 +46,7 @@ SearchAwesome adware intercepts encrypted web traffic to inject ads.
|---|---|
|[Execution::User Execution (E1204)](../execution/user-execution.md)|The user opens a disk image file which invisibly installs its components. [[1]](#1)|
|[Defense Evasion::Self Deletion (F0007)](../defense-evasion/self-deletion.md)|The malware will monitor if a specific file gets deleted and then will delete itself. [[1]](#1)|
|[Privilege Escalation::Install Certificate (E1608)](../privilege-escalation/install-certificate.md)|The malware installs a certificate. [[1]](#1)|
|[Privilege Escalation::Install Certificate (F0016)](../privilege-escalation/install-certificate.md)|The malware installs a certificate. [[1]](#1)|
|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|The malware installs a script to inject a JavaScript script and modify web traffic. [[1]](#1)|
## MBC Behaviors
+2 -2
View File
@@ -12,7 +12,7 @@
* **MBC v3.0** - The latest MBC release includes behavior detection information, expanded descriptions, and new properties, such as version and created and modified dates.
* **STIX 2.1 Representation** - MBC content is available in an updated STIX format based on the new [STIX 2.1 Malware Behavior Extension](https://github.com/oasis-open/cti-stix-common-objects/tree/main/extension-definition-specifications/malware-behavior).
* **STIX 2.1 Representation** - MBC content is available in an updated STIX format based on the new [STIX 2.1 Malware Behavior Extension](https://github.com/oasis-open/cti-stix-common-objects/tree/main/extension-definition-specifications/malware-behavior-8e9).
* **Attack Flow Examples** - Example attack flows for [Shamoon](../xample-malware/shamoon.md) and [SearchAwesome](../xample-malware/searchawesome.md) reference MBC behaviors.
@@ -150,7 +150,7 @@ Malware behaviors and adversary behaviors can overlap because adversaries someti
MBC content is available in STIX 2.1 format. See the [mbc-stix2.1](https://github.com/MBCProject/mbc-stix2.1) repository for details. MBC content is also available in an [older STIX 2.1 representation](https://github.com/MBCProject/mbc-stix2) based on the representation used for ATT&CK.
### Why was MBC's STIX representation updated? ###
The previous STIX 2.1 representation is valid, but it doesn't take advantage of the STIX 2.1 Extension Definition Object. MBC users said they found the MBC representation (and ATT&CK) kludgy, so we defined new SDOs and extended the STIX Malware Object in a [malware behavior extension](https://github.com/oasis-open/cti-stix-common-objects/tree/main/extension-definition-specifications/malware-behavior). We think it works much better!
The previous STIX 2.1 representation is valid, but it doesn't take advantage of the STIX 2.1 Extension Definition Object. MBC users said they found the MBC representation (and ATT&CK) kludgy, so we defined new SDOs and extended the STIX Malware Object in a [malware behavior extension](https://github.com/oasis-open/cti-stix-common-objects/tree/main/extension-definition-specifications/malware-behavior-8e9). We think it works much better!
### How are malware corpus examples captured in STIX? ###
Corpus examples are captured using the Malware SDO. Three new properties are defined in the STIX 2.1 Malware Behavior extension:
+1 -1
View File
@@ -5,7 +5,7 @@ Hi all!
Recent MBC activity includes:
* Finalized the STIX 2.1 Malware Behavior Extension, which includes new STIX domain objects for MBC objectives, behaviors, and methods. Documentation and the JSON schemas are available in the OASIS [STIX Common Objects](https://github.com/oasis-open/cti-stix-common-objects/tree/main/extension-definition-specifications/malware-behavior) repository.
* Finalized the STIX 2.1 Malware Behavior Extension, which includes new STIX domain objects for MBC objectives, behaviors, and methods. Documentation and the JSON schemas are available in the OASIS [STIX Common Objects](https://github.com/oasis-open/cti-stix-common-objects/tree/main/extension-definition-specifications/malware-behavior-8e9) repository.
* Preparing MBC 3.0 (release date 29 September).
* Preparing release of the STIX 2.1 representation for MBC 3.0, which is based on the new malware behavior extension and will be available in a new [mbc-stix2.1](https://github.com/MBCProject/mbc-stix2.1) repository (release date 29 September).
* Revised the [MBC FAQ](https://github.com/MBCProject/mbc-markdown/tree/main/yfaq), adding new content and updating and reorganizing existing content.
+1 -1
View File
@@ -6,7 +6,7 @@ Hello all!
Here are recent MBC developments:
* Released [MBC 3.0](https://github.com/MBCProject/mbc-markdown/releases/tag/v3.0).
* Released the [STIX 2.1 representation](https://github.com/MBCProject/mbc-stix2.1) for MBC 3.0, which is based on the new [malware behavior extension](https://github.com/oasis-open/cti-stix-common-objects/tree/main/extension-definition-specifications/malware-behavior).
* Released the [STIX 2.1 representation](https://github.com/MBCProject/mbc-stix2.1) for MBC 3.0, which is based on the new [malware behavior extension](https://github.com/oasis-open/cti-stix-common-objects/tree/main/extension-definition-specifications/malware-behavior-8e9).
* Tagged malware corpus with malware type.
* Updated MBC for ATT&CK v14.
* Added CAPE signature information to behavior pages (detection section).