fix links

This commit is contained in:
Desiree Beck
2019-09-17 19:11:49 -04:00
parent fe88149285
commit 15df2d1b99
17 changed files with 15 additions and 20 deletions
+1 -1
View File
@@ -14,7 +14,7 @@ Behaviors
---------
|Name|Use|
|---------------------|-------------------------------------------------------|
|[Denial of Service](https://github.com/MBCProject/mbc-markdown/blob/master/effects/dos.md) | Launches distributed denial of service attacks that can target more than one IP address per hostname. [1]](#1)|
|[Denial of Service](https://github.com/MBCProject/mbc-markdown/blob/master/impact/dos.md) | Launches distributed denial of service attacks that can target more than one IP address per hostname. [1]](#1)|
References
----------
+1 -1
View File
@@ -15,7 +15,7 @@ Behaviors
|Name|Use|
|---------------------|-------------------------------------------------------|
|[Domain Name Generation](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control/domain-name-generate.md) | Uses a domain name generator. [[1]](#1)|
|[Suicide Exit](https://github.com/MBCProject/mbc-markdown/blob/master/execution/suicide-exit.md)|Conficker A has routine that causes the process to suicide if the keyboard language layout is set to Ukrainian. [[2]](#2)|
|[Conditional Execution](https://github.com/MBCProject/mbc-markdown/blob/master/execution/conditional-execute.md)|Conficker A has routine that causes the process to suicide if the keyboard language layout is set to Ukrainian. [[2]](#2)|
References
----------
+1 -1
View File
@@ -14,7 +14,7 @@ Behaviors
---------
|Name|Use|
|---------------------|-------------------------------------------------------|
|[Remote Access Trojan](https://github.com/MBCProject/mbc-markdown/blob/master/execution/rat.md) | Allows an attacker to control the system via a GUI. [1]](#1)|
|[Remote Access](https://github.com/MBCProject/mbc-markdown/blob/master/impact/remote-access.md) | Allows an attacker to control the system via a GUI. [1]](#1)|
References
----------
+1 -1
View File
@@ -14,7 +14,7 @@ Behaviors
---------
|Name|Use|
|---------------------|-------------------------------------------------------|
|[Generate Fraudulent Advertising Revenue](https://github.com/MBCProject/mbc-markdown/blob/master/effects/generate-fraud-rev.md)| Alters DNS server settings to route to a rogue DNS server for the purpose of click hijacking. [[1]](#1)|
|[Generate Fraudulent Advertising Revenue](https://github.com/MBCProject/mbc-markdown/blob/master/impact/generate-fraud-rev.md)| Alters DNS server settings to route to a rogue DNS server for the purpose of click hijacking. [[1]](#1)|
|[Disable Security Tools](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/disable-security-tools.md) | Prevents the infected system from installing anti-virus software updates. [[1]](#1)|
References
+1 -1
View File
@@ -30,7 +30,7 @@ Behaviors
---------
|Name|Use|
|---------------------|-------------------------------------------------------|
|[Install Secondary Program](https://github.com/MBCProject/mbc-markdown/blob/master/execution/install-second-prog.md) | Geneio installs the browser extension *~/Library/Safari/Extensions/Omnibar.safariextz*. It also creates the app files listed in the description above. [[1]](#1)|
|[Install Additional Program](https://github.com/MBCProject/mbc-markdown/blob/master/execution/install-prog.md) | Geneio installs the browser extension *~/Library/Safari/Extensions/Omnibar.safariextz*. It also creates the app files listed in the description above. [[1]](#1)|
References
----------
+1 -1
View File
@@ -15,7 +15,7 @@ Behaviors
|Name|Use|
|---------------------|-------------------------------------------------------|
|[Alternative Installation Location](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion/alter-install-location.md) | tores malware files in the Registry instead of the hard drive. [[1]](#1)|
|[Generate Fraudulent Advertising Revenue](https://github.com/MBCProject/mbc-markdown/tree/master/effects/generate-fraud-rev.md) | Performs click-fraud. [[1]](#1)|
|[Generate Fraudulent Advertising Revenue](https://github.com/MBCProject/mbc-markdown/tree/master/impact/generate-fraud-rev.md) | Performs click-fraud. [[1]](#1)|
References
----------
+2 -2
View File
@@ -15,8 +15,8 @@ Behaviors
|Name|Use|
|---------------------|-------------------------------------------------------|
|[Poison SMS Message](https://github.com/MBCProject/mbc-markdown/blob/master/initial-access/send-poison-text-msg.md) |Delivered via a poisoned SMS message.|
|[Man in the Middle](https://github.com/MBCProject/mbc-markdown/blob/master/collection/man-in-middle.md) | Intercepts data coming into and going out of device.|
|[Install Secondary Program](https://github.com/MBCProject/mbc-markdown/blob/master/execution/install-second-prog.md) | Installs a backdoor.|
|[Manipulate Network Traffic](https://github.com/MBCProject/mbc-markdown/blob/master/impact/man-in-middle.md) | Intercepts data coming into and going out of device.|
|[Install Additional Program](https://github.com/MBCProject/mbc-markdown/blob/master/execution/install-prog.md) | Installs a backdoor.|
References
----------
+1 -1
View File
@@ -15,7 +15,7 @@ Behaviors
|Name|Use|
|---------------------|-------------------------------------------------------|
|[Bootkit](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/bootkit.md)| An MBR bootkit and a BIOS bootkit targeting Award BIOS. [[1]](#1)|
|[Install Secondary Program](https://github.com/MBCProject/mbc-markdown/blob/master/execution/install-second-prog.md) | A Trojan downloader. [[1]](#1)|
|[Install Additional Program](https://github.com/MBCProject/mbc-markdown/blob/master/execution/install-prog.md) | A Trojan downloader. [[1]](#1)|
References
----------
+1 -1
View File
@@ -14,7 +14,7 @@ Behaviors
---------
|Name|Use|
|---------------------|-------------------------------------------------------|
|[Remote Access Trojan](https://github.com/MBCProject/mbc-markdown/blob/master/impact/remote-access.md) | After the Poison-Ivy server is running on the target machine, the attacker uses a Windows GUI client to control the target computer. [[1]](#1)|
|[Remote Access](https://github.com/MBCProject/mbc-markdown/blob/master/impact/remote-access.md) | After the Poison-Ivy server is running on the target machine, the attacker uses a Windows GUI client to control the target computer. [[1]](#1)|
References
----------
+1 -1
View File
@@ -18,7 +18,7 @@ Behaviors
|[VM Detection](https://github.com/MAECProject/malware-behaviors/blob/master/anti-behavioral-analysis/detect-vm.md) | Redhip detects VMWare, Virtual PC and Virtual Box. It also detects VM environments in general by considering timing lapses. [[1]](#1)|
|[Debugger Detection](https://github.com/MAECProject/malware-behaviors/blob/master/anti-behavioral-analysis/detect-debugger.md) | Redhip uses general approaches to detecting user level debuggers (e.g., Process Environment Block 'Being Debugged' field), as well as specific checks for kernel level debuggers like SOFICE. [[1]](#1)|
|[Debugger Evasion](https://gitlab.mitre.org/mbc/mbc_stix/blob/master/malware-behaviors-master/anti-behavioral-analysis/evade-debugger.md) | Redhip uses general approaches to detecting user level debuggers (e.g., Process Environment Block 'Being Debugged' field), as well as specific checks for kernel level debuggers like SOFICE. [[1]](#1)|
|[Software Packing](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/software-packing.md) | Redhip samples are packed with different custom packers. [[1]](#1)|
|[Executable Code Compression](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/exe-code-compression.md) | Redhip samples are packed with different custom packers. [[1]](#1)|
References
----------
-1
View File
@@ -15,7 +15,6 @@ Behaviors
|Name|Use|
|---------------------|-------------------------------------------------------|
|[Encrypt Files for Impact](https://github.com/MBCProject/mbc-markdown/blob/master/impact/encrypt-impact.md) | SamSam is ransomware. [[1]](#1)|
|[Software Vulnerability](https://github.com/MBCProject/mbc-markdown/blob/master/initial-infection/software-vuln.md)| Attackers associated with SamSam exploit vulnerabilities in remote desktop protocols (RDP), Java-based web servers, or file transfer protocol (FTP) servers. [[1]](#1)|
References
----------
+1 -1
View File
@@ -14,7 +14,7 @@ Behaviors
---------
|Name|Use|
|---------------------|-------------------------------------------------------|
|[Manipulate Network Traffic](https://github.com/MBCProject/mbc-markdown/blob/master/effects/manipulate-network-traffic.md)| Intercepts encrypted web traffic to inject adds. [[1]](#1)|
|[Manipulate Network Traffic](https://github.com/MBCProject/mbc-markdown/blob/master/impact/manipulate-network-traffic.md)| Intercepts encrypted web traffic to inject adds. [[1]](#1)|
References
----------
+1 -1
View File
@@ -14,7 +14,7 @@ Behaviors
---------
|Name|Use|
|---------------------|-------------------------------------------------------|
|[Destroy Data](https://github.com/MBCProject/mbc-markdown/blob/master/effects/destroy-data.md) | A 2018 variant includes a component that erases files and then wipes the master boot record, preventing file recovery. [[[1]](#1)|
|[Data Destruction](https://github.com/MBCProject/mbc-markdown/blob/master/impact/data-destruction.md) | A 2018 variant includes a component that erases files and then wipes the master boot record, preventing file recovery. [[[1]](#1)|
References
----------
+1 -1
View File
@@ -14,7 +14,7 @@ Behaviors
---------
|Name|Use|
|---------------------|-------------------------------------------------------|
|[Destroy Hardware](https://github.com/MBCProject/mbc-markdown/blob/master/effects/destroy-hardware.md) | Stuxnet made the centrifuges at Iran's nuclear plant spin dangerously fast for 15 minutes, before returning to normal speed. About a month later, it slowed the centrifuges down for 50 minutes. This was repeated for several months, and over time the strain destroyed the machines. [[2]](#2)|
|[Destroy Hardware](https://github.com/MBCProject/mbc-markdown/blob/master/impact/destroy-hardware.md) | Stuxnet made the centrifuges at Iran's nuclear plant spin dangerously fast for 15 minutes, before returning to normal speed. About a month later, it slowed the centrifuges down for 50 minutes. This was repeated for several months, and over time the strain destroyed the machines. [[2]](#2)|
References
----------
-1
View File
@@ -14,7 +14,6 @@ Behaviors
---------
|Name|Use|
|---------------------|-------------------------------------------------------|
|[Spearphishing Attachment](https://github.com/MBCProject/mbc-markdown/blob/master/initial-access/spearphishing-attach.md)| Attacks usually start with a weaponized Microsoft Word document. [[1]](#1)|
|[Sandbox Detection](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/detect-sandbox.md) | The Terminator rat evades a sandbox by not executing until after a reboot. Most sandboxes don't reboot during an analysis. [[1]](#1)|
| [Registry Run Keys / Startup Folder](https://github.com/MBCProject/mbc-markdown/blob/master/persistence/registry-run-startup.md)| Sets "2019" as Windows' startup folder by modifying a registry value. [[1]](#1)|
|[File Deletion](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/file-deletion.md)| The malicious executable deletes itself after it has dropped other executable files.|
-3
View File
@@ -15,9 +15,6 @@ Behaviors
|Name|Use|
|---------------------|-------------------------------------------------------|
|[Sandbox Detection](https://github.com/MAECProject/malware-behaviors/blob/master/anti-behavioral-analysis/detect-sandbox.md) | Ursnif uses malware macros to evade sandbox detection. [[1]](#1)|
|[Spearphishing Attachment](https://github.com/MBCProject/mbc-markdown/blob/master/initial-access/spearphishing-attachment.md) | Ursnif is sometimes delivered via malicious email attachment.
|[Spearphishing Link](https://github.com/MBCProject/mbc-markdown/blob/master/initial-access/spearphishing-link.md) | Ursnif is sometimes delivered via malicious link.|
|[Exploit Kit](https://github.com/MBCProject/mbc-markdown/blob/master/initial-access/exploit-kit.md) | Ursnif is sometimes delivered via exploit kit. [[1]](#1)|
References
----------
+1 -1
View File
@@ -23,7 +23,7 @@ Behaviors
|[Command-Line Interface](https://github.com/MBCProject/mbc-markdown/blob/master/execution/command-line.md) | From the command line, drops and unzips a password-protected Cabinet archive file. [[1]](#1) |
|[Install Additional Program](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/install-second-prog.md)| Downloads and executes Claymore's Zcash miner from a remote server. [[1]](#1) |
|[Conditional Execution](https://github.com/MBCProject/mbc-markdown/blob/master/execution/conditional-execute.md) | Executes differently depending on whether it's running on an x86 or x64 system. [[1]](#1) |
|[Hijack System Resources](https://github.com/MBCProject/mbc-markdown/blob/master/effects/hijack-system-resources.md)| Drops software that mines for cryptocurrency: Cryptonight or Claymore's Zcash miner, depending on system architecture. [[1]](#1)|
|[Hijack System Resources](https://github.com/MBCProject/mbc-markdown/blob/master/impact/hijack-system-resources.md)| Drops software that mines for cryptocurrency: Cryptonight or Claymore's Zcash miner, depending on system architecture. [[1]](#1)|
|[Dynamic Analysis Evasion](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/evade-dynamic-analysis.md) | [[1]](#1)|
|[Emulator Evasion](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/evade-emulator.md) | [[1]](#1)|
|[Virtual Machine Detection](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/detect-vm.md) | [[1]](#1)|