mirror of
https://github.com/MBCProject/mbc-markdown
synced 2026-06-08 11:36:36 +00:00
Compare commits
297 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| e5b31bdd5b | |||
| 949209d597 | |||
| 1e42433220 | |||
| 00afb1d6b0 | |||
| 344da4eaea | |||
| 9937ebd631 | |||
| fa9f508370 | |||
| d5791ce5fe | |||
| a6096cb8df | |||
| 2f6093b0b9 | |||
| 503105dcd0 | |||
| dbf98ecfb7 | |||
| 5fc453ab53 | |||
| 9d267f438a | |||
| 389c9023ef | |||
| 99e472ad90 | |||
| 69055744bf | |||
| b3096ed9f2 | |||
| a1f14b90a8 | |||
| d107a3d89e | |||
| e677acfe93 | |||
| 5392791edc | |||
| 4c3cc0125f | |||
| 999696ad26 | |||
| 3f897ca2bb | |||
| 01df10e1cb | |||
| 580fadedcf | |||
| b3a7a36a27 | |||
| 9b8672cfe4 | |||
| 7dd6670274 | |||
| da26628e86 | |||
| 1410cd6076 | |||
| 22ac38a876 | |||
| 643fefd7b3 | |||
| 7168b1040a | |||
| 9d2dc7d065 | |||
| ff05de6422 | |||
| 804b913cb4 | |||
| d9e84725bf | |||
| 7c70e41d7b | |||
| a2b581728a | |||
| 7c769c8e3c | |||
| e5b8278174 | |||
| 61b5dfb051 | |||
| 950cfca2cc | |||
| 4d7c7f6dad | |||
| 79b42cba12 | |||
| 2a9bcd3ab5 | |||
| 1ed65e2692 | |||
| ddfc129ba1 | |||
| 40db622ee7 | |||
| 017d263ebb | |||
| 3e16f10c35 | |||
| 6d560ed105 | |||
| ac3e8b6859 | |||
| c2500c8f3f | |||
| 9932beb512 | |||
| 0ed931a0d8 | |||
| 34c87921d5 | |||
| f0f0235353 | |||
| 5e3a5cedf7 | |||
| a5a31f2f63 | |||
| ff57a87f7f | |||
| 24dca9d9c9 | |||
| 30f31bd245 | |||
| 7fe9a48518 | |||
| d8ba02ab00 | |||
| cd7b66d5b9 | |||
| c544962577 | |||
| a13dceeb1d | |||
| 19be37cdd4 | |||
| 95b1f2e854 | |||
| 42520d3108 | |||
| a1efa1509c | |||
| 98b2fe9c8a | |||
| a7fe0c17eb | |||
| a6624a0eef | |||
| 10d4eaf12d | |||
| c5b4a95793 | |||
| 3e49062c21 | |||
| b2502e69eb | |||
| bf7da3f24f | |||
| b934db3501 | |||
| ff5678fddd | |||
| a9b6502475 | |||
| b921f533e3 | |||
| 64864b7c86 | |||
| e0b0e039c7 | |||
| c8114ef336 | |||
| 486c764c1b | |||
| a4e9e9ec12 | |||
| a040511b06 | |||
| 9a4629884f | |||
| 9463964215 | |||
| 34e355110a | |||
| e07e00f4d4 | |||
| 48a1f3615d | |||
| 52b3e23281 | |||
| 2a6cb7a397 | |||
| cbceef7c44 | |||
| 0966565798 | |||
| f71ff004fa | |||
| 9e473ed965 | |||
| 0db4607e2f | |||
| 286c0106c4 | |||
| 7287afb877 | |||
| f6d2f58b7c | |||
| fb9882c0b9 | |||
| b6b1a12db1 | |||
| 9791a68096 | |||
| 975c21c7bc | |||
| 5a57d01e4e | |||
| 8092d86ae3 | |||
| ff62030726 | |||
| e1b1756c93 | |||
| 4e6d8a44aa | |||
| ce6453a692 | |||
| c648c032a3 | |||
| cb553d3681 | |||
| 40ddc39e3c | |||
| 556c01f636 | |||
| 67c9b4d30c | |||
| 08b41c057f | |||
| 2524861df3 | |||
| 2f87c60a47 | |||
| dcdc71c325 | |||
| 7375cf16c6 | |||
| 8b97ca31cd | |||
| af0350ec08 | |||
| f97bfd8794 | |||
| af8df39833 | |||
| ee207f35a3 | |||
| 6449769ac2 | |||
| 077d21c73c | |||
| 813557e591 | |||
| ed5892d24b | |||
| 2facfec1a5 | |||
| 6908afc46c | |||
| 610f5987e8 | |||
| ba705ca09e | |||
| 1129ca7fb8 | |||
| bf1dfa48ab | |||
| c00fc1ffa9 | |||
| 7827b3aae4 | |||
| bb1fac5043 | |||
| a57e9877bf | |||
| b0c11f1d27 | |||
| 5973e9ed53 | |||
| 77fcac8a7b | |||
| 71ca24ac1e | |||
| 1a7004b446 | |||
| 81d5cfcc3e | |||
| 9b7f830ea5 | |||
| d4be3586f3 | |||
| 41868fd892 | |||
| 457b3ffc5e | |||
| ce075ef813 | |||
| d90c97259c | |||
| 4b21e889ef | |||
| 2da03d54cf | |||
| cd945062f1 | |||
| 41d63c6ba0 | |||
| f1b45c1d0e | |||
| 6828164c2d | |||
| a9870c628a | |||
| 9d4cf70b4d | |||
| 115d7f39d7 | |||
| 1e34931072 | |||
| f4a3a74727 | |||
| 5c3147ff60 | |||
| d7c814302b | |||
| 49038fa484 | |||
| 968b94e64b | |||
| 2e0245bf9a | |||
| 0bf66d6231 | |||
| 974f8c212a | |||
| 6ad2921191 | |||
| 35d73c5606 | |||
| 66dc492f9e | |||
| 248207bd4b | |||
| 14e747fc1f | |||
| 052ad8283c | |||
| e0fffe4d5c | |||
| 859544e548 | |||
| e966d8aed7 | |||
| f109dc51e0 | |||
| b03c99f6f5 | |||
| 42028462cd | |||
| 7557f6e586 | |||
| 0f6be9ff0c | |||
| bd95692b9e | |||
| ed7ca2a97e | |||
| 271092a6a9 | |||
| c688df3c0c | |||
| cc1b649e77 | |||
| a29e07bee2 | |||
| b87371ce86 | |||
| f60855e3b0 | |||
| efcea74ba0 | |||
| f6335e7ca5 | |||
| d17c52f4c4 | |||
| 28daf463db | |||
| 083d599a80 | |||
| d202803387 | |||
| bf008e50af | |||
| 03d47b6132 | |||
| 24c6946732 | |||
| 7ea2aaee05 | |||
| fe28548c49 | |||
| e89098ec73 | |||
| 0a6c7dede6 | |||
| 9a177f67b5 | |||
| e72f620fec | |||
| a3b719feac | |||
| 93c17e23bb | |||
| 7c505a8d54 | |||
| f33b64450f | |||
| dd9f1a49c2 | |||
| ee203c560f | |||
| da38b519c8 | |||
| 376dedeb7b | |||
| 6ca7ab1abe | |||
| 29b9bcb718 | |||
| 2ac0ab1dc9 | |||
| 258a0f9505 | |||
| fdfeb243d6 | |||
| c1582b2154 | |||
| 19e07cc26f | |||
| 46cfb30300 | |||
| 7ff8aa8713 | |||
| c4dddba7d9 | |||
| c9aee04283 | |||
| f175b7e0be | |||
| d9af0e5834 | |||
| a828f02795 | |||
| 536f884758 | |||
| 6d7cc638d4 | |||
| a3edfa54e8 | |||
| 8841eb32d4 | |||
| e47cf276f7 | |||
| e02767caef | |||
| 716aff8bd2 | |||
| 73dd104efa | |||
| 8307ba5c4e | |||
| a9db388317 | |||
| 060d2fcba8 | |||
| f89cbccdd7 | |||
| c7af1687ad | |||
| 78a84c74b4 | |||
| a2e78f2ea4 | |||
| ade5b26988 | |||
| 7bca9d6a64 | |||
| 01a7d974d8 | |||
| 6d29b37130 | |||
| a265c73431 | |||
| b7197c785d | |||
| 59b66b0844 | |||
| 28028ce5c6 | |||
| 1c4eef4c69 | |||
| f4af7f5769 | |||
| 76d72bf9fc | |||
| c0a7760da9 | |||
| 3e5d257030 | |||
| 4f381c5ae4 | |||
| ed2a32e60b | |||
| 74d816deb1 | |||
| 2207d845ae | |||
| 3559ac6c87 | |||
| 93367ba757 | |||
| b751693952 | |||
| 16d6fb8683 | |||
| 4820c04475 | |||
| b04a1fda23 | |||
| 5cbe88a51e | |||
| 1d925d7cdd | |||
| fa085a5c99 | |||
| 32b2e1c3b8 | |||
| 56bdad5d9a | |||
| cc6b3c2e36 | |||
| d96dc61157 | |||
| fb3468f1ed | |||
| 4267de524a | |||
| 14a78d1f55 | |||
| defb0b5e24 | |||
| ca14135a9d | |||
| 7fe389267b | |||
| c213644049 | |||
| 5e1b764c7a | |||
| 546656036d | |||
| 23f65a2963 | |||
| 889a7080b5 | |||
| 4354ef806d | |||
| 09fa140a39 | |||
| a7d03c7fc3 | |||
| 4811478d72 | |||
| 7fc84b1135 | |||
| 085b46baec |
@@ -1,38 +1,144 @@
|
||||
# <a name="mbc"></a>Malware Behavior Catalog #
|
||||
The Malware Behavior Catalog (MBC) is a catalog of malware objectives and behaviors, created to support malware analysis-oriented use cases, such as labeling, similarity analysis, and standardized reporting. Please see the [FAQ](https://github.com/MBCProject/mbc-markdown/blob/master/yfaq/README.md) page for answers to common questions.
|
||||
# <a name="mbc"></a>Malware Behavior Catalog v2.2 #
|
||||
The Malware Behavior Catalog (MBC) is a catalog of malware objectives and behaviors, created to support malware analysis-oriented use cases, such as labeling, similarity analysis, and standardized reporting. Please see the [FAQ](./yfaq/README.md) page for answers to common questions, and read the [newsletters](./ynewsletters/README.md) for information on the most recent MBC updates and activity.
|
||||
|
||||
Check out the [MBC presentation](https://www.youtube.com/watch?v=KY8Ty-0sdVU) given at BSides DC (October 2019).
|
||||
Check out the MBC presentations:
|
||||
|
||||
* [Standardized Reporting with the Malware Behavior Catalog](https://youtu.be/qZef-SoREdY), VB2020 localhost (October 2020)
|
||||
* [Malware Behavior Catalog](https://youtu.be/KY8Ty-0sdVU), BSides DC (October 2019)
|
||||
|
||||
We've also mapped MBC (and ATT&CK) to two open-source malware analysis tools:
|
||||
|
||||
* [Cuckoo community signatures](https://github.com/MBCProject/community)
|
||||
* [capa rules](https://github.com/fireeye/capa-rules) - see the [mapping distribution](./capa.md)
|
||||
|
||||
To join the **MBC mailing list**, please send a request to mbc@mitre.org.
|
||||
|
||||
### Objectives ###
|
||||
As shown below, malware objectives are based on [ATT&CK Tactics](https://attack.mitre.org/tactics/enterprise/), and are tailored for the malware analysis use case of characterizing malware based on known objectives and behaviors. Two malware analysis-specific objectives not in ATT&CK are also defined (ANTI-BEHAVIORAL ANALYSIS and ANTI-STATIC ANALYSIS).
|
||||
As shown below, malware objectives are based on [ATT&CK tactics](https://attack.mitre.org/tactics/enterprise/), and are tailored for the malware analysis use case of characterizing malware based on known objectives and behaviors. Two malware analysis-specific objectives not in ATT&CK are also defined (ANTI-BEHAVIORAL ANALYSIS and ANTI-STATIC ANALYSIS).
|
||||
|
||||
### Behaviors ###
|
||||
Under each objective, MBC captures all behaviors and code characteristics discovered during malware analysis, with links to [ATT&CK Techniques](https://attack.mitre.org/techniques/enterprise/) as appropriate. Names of MBC behaviors may or may not match related ATT&CK techniques. Any content provided on behavior pages is *supplemental* to ATT&CK content. In other words, ATT&CK content is not duplicated in MBC, and MBC users will want to reference ATT&CK while capturing malware behaviors.
|
||||
Under each objective, MBC captures all behaviors and code characteristics discovered during malware analysis, with links to [ATT&CK techniques](https://attack.mitre.org/techniques/enterprise/) as appropriate. Names of MBC behaviors may or may not match related ATT&CK techniques. Any content provided on behavior pages is *supplemental* to ATT&CK content. In other words, ATT&CK content is not duplicated in MBC, and MBC users will reference ATT&CK while capturing malware behaviors.
|
||||
|
||||
### Methods ###
|
||||
Methods are associated with behaviors and serve different roles, depending on the behavior. In some cases, a method further refines a behavior (i.e., sub-behavior); in other cases, a method is an implementation of a behavior. Previously, methods had no ATT&CK counterpart, but beginning in April 2020, ATT&CK defines sub-techniques, which are similar to methods.
|
||||
|
||||
Note that a method cannot be used without a behavior.
|
||||
|
||||
### Micro-behaviors ###
|
||||
Some malware behaviors are low-level, support many objectives and other behaviors, and aren't necessarily malicious. For example, a TCP socket may be created, or a string may be checked for some condition. Because such behaviors are often noted in malware analysis, they are captured in MBC. See [Micro-behaviors](./micro-behaviors/README.md) for details.
|
||||
|
||||
### <a name="ids"></a>Identifiers ###
|
||||
The first letter of a behavior identifier indicates whether the behavior is a stub referencing an ATT&CK technique ("T", matching the ATT&CK identifier; e.g. T1234), whether it enhances an ATT&CK technique with malware-specific details ("E"; e.g. E1234), or whether it is a newly defined behavior in MBC ("M"; e.g. M1234). When two or more MBC behaviors refine the same ATT&CK technique, each is given an MBC identifier and each references the ATT&CK identifier. When a new ATT&CK technique is defined *after* an MBC behavior has been defined, the preexisting MBC identifier is preserved and the new ATT&CK identifier is referenced.
|
||||
As shown below, the letter of an identifier relays information about a behavior. Note that letters used in MBC v2 are changed from MBC v1.
|
||||
|
||||
### Example Malware ###
|
||||
The MBC also contains a collection of [example malware](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/) that are characterized with malware behaviors.
|
||||
|**Letter**|**Example**|**Description**|
|
||||
|---|---|---|
|
||||
|**B**|*B0040*|An MBC behavior.|
|
||||
|**C**|*C0015*|An MBC micro-behavior.|
|
||||
|**T**|*T1234*|An ATT&CK technique.|
|
||||
|**E**|*E1234*|An ATT&CK technique that has been enhanced with malware-specific details. The numerical portion of the identifier will match the ATT&CK ID (e.g., E1234 enhances T1234).|
|
||||
|**F**|*F0004*|An ATT&CK sub-technique that has been enhanced with malware-specific details.|
|
||||
|
||||
Two letters of an identifier relay information about an objective.
|
||||
|
||||
|**Letter**|**Example**|**Description**|
|
||||
|---|---|---|
|
||||
|**OB**|*OB0001*|An MBC objective.|
|
||||
|**OC**|*OC0003*|An MBC micro-objective.|
|
||||
|
||||
Identifiers of methods are formatted in the same way as ATT&CK sub-techniques. If MBC defines a new method for an existing ATT&CK technique, the identifier is changed from "T" to "E" and an "m" identifier is added (e.g., a method added to T1234 would be denoted *E1234.m01* and is different than *T1234.001*, although both refer to the T1234 ATT&CK technique). Method identifiers of "B", "C", and "F" behaviors are defined without the "m" (e.g., *B0008.009*; *C0005.002*; *F0001.005*).
|
||||
|
||||
When two or more MBC behaviors refine the same ATT&CK technique, each is given an MBC identifier and each references the ATT&CK identifier. When a new ATT&CK technique is defined *after* an MBC behavior has been defined, the preexisting MBC identifier is preserved and the new ATT&CK identifier is referenced.
|
||||
|
||||
In cases where an MBC behavior enhances a technique/sub-technique that is defined in both ATT&CK Mobile and Enterprise, the "E" identifier used in MBC corresponds to the Enterprise identifier. For example, the Obfuscated Files or Information technique has identifier <a href="https://attack.mitre.org/techniques/T1027/">T1027</a> in Enterprise, identifier <a href="https://attack.mitre.org/techniques/T1406/">T1406</a> in Mobile, and identifier <a href="./defense-evasion/obfuscated-files-or-information.md">E1027</a> in MBC.
|
||||
|
||||
### Canonical Representation ###
|
||||
The canonical representation for MBC content is **OBJECTIVE::Behavior::Method**. For example, *ANTI-BEHAVIORAL ANALYSIS::Debugger Detection::Process Environment Block*.
|
||||
|
||||
Objectives and behaviors can be used alone, but a method *must* be associated with a behavior.
|
||||
|
||||
### Navigator View ###
|
||||
This visual representation of the MBC Matrix is based on the ATT&CK Navigator. Two views are available:
|
||||
|
||||
* <a href="https://raw.githubusercontent.com/MBCProject/mbc-markdown/master/yfaq/mbc_matrix_with_ids.svg" target="_blank">Matrix with identifiers</a>
|
||||
* <a href="https://raw.githubusercontent.com/MBCProject/mbc-markdown/master/yfaq/mbc_matrix_without_ids.svg" target="_blank">Matrix without identifiers</a>
|
||||
|
||||
### Malware Corpus ###
|
||||
The MBC contains a [malware corpus](./xample-malware/README.md) where each malware entry is decomposed into behaviors that are mapped to ATT&CK and MBC. The mappings are based on open source malware analysis reports.
|
||||
|
||||
## Micro-behavior Objectives ##
|
||||
[Micro-behaviors](./micro-behaviors/README.md) and their associated objectives are under development.
|
||||
|
||||
## Malware Objective Descriptions ##
|
||||
Malware objectives are defined below. Follow the links to view associated behaviors. Please see the [MBC Matrix](http://maecproject.github.io/ema/index.html) to view all behaviors.
|
||||
Malware objectives are defined in the table below. Follow the links to view associated behaviors.
|
||||
|
||||
|**Objective**|**Description**|
|
||||
|------------------------------------------------------------------|----------------------------|
|
||||
|[**Anti-Behavioral Analysis**](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/README.md) |Malware aims to prevent, obstruct, or evade behavioral analysis done in a sandbox, debugger, etc.|
|
||||
|[**Anti-Static Analysis**](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/README.md)| Malware aims to prevent static analysis or make it more difficult. Simpler static analysis identifies features such as embedded strings, executable header information, hash values, and file metadata. More involved static analysis involves the disassembly of the binary code.|
|
||||
|[**Collection**](https://github.com/MBCProject/mbc-markdown/blob/master/collection/README.md) | Malware aims to identify and gather information, such as sensitive files, from a target network prior to exfiltration. This objective includes locations on a system or network where the malware may look for information to exfiltrate.|
|
||||
|[**Command and Control**](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/README.md) |Malware aims to communicate (receive and/or execute remotely submitted commands) with controlling or controlled systems within a target network (C2 servers, bots, etc.).|
|
||||
|[**Credential Access**](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/README.md)|Malware aims to obtain credential access, allowing it or its underlying threat actor to assume control of an account, with the associated system and network permissions.|
|
||||
|[**Defense Evasion**](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/README.md)|Malware aims to evade detection or avoid other cybersecurity defenses.|
|
||||
|[**Discovery**](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/README.md)|Malware aims to gain knowledge about the system and internal network.|
|
||||
|[**Execution**](https://github.com/MBCProject/mbc-markdown/blob/master/execution/README.md)| Malware aims to execute its code on a system to achieve a variety of goals.|
|
||||
|[**Exfiltration**](https://github.com/MBCProject/mbc-markdown/blob/master/exfiltration/README.md)| Malware aims to steal data from the system on which it executes. This includes stored data (e.g., files) as well as data input into applications (e.g., web browser).|
|
||||
|[**Impact**](https://github.com/MBCProject/mbc-markdown/blob/master/impact/README.md)| Malware aims to achieve its mission of manipulating, interrupting, or destroying systems and data.|
|
||||
|[**Lateral Movement**](https://github.com/MBCProject/mbc-markdown/blob/master/lateral-movement/README.md)|Malware aims to propagate through the infection of a system or is able to infect a file after executing on a system. The malware may infect actively (e.g., gain access to a machine directly) or passively (e.g., send malicious email).|
|
||||
|[**Persistence**](https://github.com/MBCProject/mbc-markdown/blob/master/persistence/README.md)|Malware aims to remain on a system regardless of system events.|
|
||||
|[**Privilege Escalation**](https://github.com/MBCProject/mbc-markdown/blob/master/privilege-escalation/README.md)|Malware aims to obtain a higher level of privilege for execution.|
|
||||
|---|---|
|
||||
|[**Anti-Behavioral Analysis**](./anti-behavioral-analysis/README.md)|Malware aims to prevent, obstruct, or evade behavioral analysis, such as analysis done using a sandbox or debugger.|
|
||||
|[**Anti-Static Analysis**](./anti-static-analysis/README.md)|Malware aims to prevent static analysis or make it more difficult.|
|
||||
|[**Collection**](./collection/README.md)|Malware aims to identify and gather information from a machine or network.|
|
||||
|[**Command and Control**](./command-and-control/README.md)|Malware aims to communicate with compromised systems to control them.|
|
||||
|[**Credential Access**](./credential-access/README.md)|Malware aims to steal account names and passwords.|
|
||||
|[**Defense Evasion**](./defense-evasion/README.md)|Malware aims to evade detection.|
|
||||
|[**Discovery**](./discovery/README.md)|Malware aims to gain knowledge about the environment.|
|
||||
|[**Execution**](./execution/README.md)|Malware aims to execute code on a system.|
|
||||
|[**Exfiltration**](./exfiltration/README.md)|Malware aims to steal data.|
|
||||
|[**Impact**](./impact/README.md)|Malware aims to manipulate, interrupt, or destroy systems or data.|
|
||||
|[**Lateral Movement**](./lateral-movement/README.md)|Malware aims to propagate or otherwise move through an environment. Lateral movement may be active, happening via direct machine access, or may be passive (for example, done via malicious email).|
|
||||
|[**Persistence**](./persistence/README.md)|Malware aims to remain on a system.|
|
||||
|[**Privilege Escalation**](./privilege-escalation/README.md)|Malware aims to obtain higher level permissions.|
|
||||
|
||||
## MBC Behaviors ##
|
||||
The table below lists MBC behaviors and related ATT&CK techniques. In most cases, related ATT&CK techniques were defined *after* the MBC behavior was defined.
|
||||
|
||||
|**ID**|**Objective(s)**|**Behavior**|**Related ATT&CK Technique**|
|
||||
|---|---|---|---|
|
||||
|**B0001**|ANTI-BEHAVIORAL ANALYSIS|**Debugger Detection**|*none*|
|
||||
|**B0002**|ANTI-BEHAVIORAL ANALYSIS|**Debugger Evasion**|Debugger Evasion ([T1622](https://attack.mitre.org/techniques/T1622))|
|
||||
|**B0003**|ANTI-BEHAVIORAL ANALYSIS|**Dynamic Analysis Evasion**|Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/techniques/T1497),[T1633](https://attack.mitre.org/techniques/T1633))|
|
||||
|**B0004**|ANTI-BEHAVIORAL|**Emulator Detection**|*none*|
|
||||
|**B0005**|ANTI-BEHAVIORAL|**Emulator Evasion**|*none*|
|
||||
|**B0006**|ANTI-BEHAVIORAL|**Memory Dump Evasion**|*none*|
|
||||
|**B0007**|ANTI-BEHAVIORAL|**Sandbox Detection**|Virtualization/Sandbox Evasion: System Checks ([T1497.001](https://attack.mitre.org/techniques/T1497/001),[T1633.001](https://attack.mitre.org/techniques/T1633/001)); Virtualization/Sandbox Evasion: User Activity Based Checks ([T1497.002](https://attack.mitre.org/techniques/T1497/002))|
|
||||
|**B0008**|ANTI-BEHAVIORAL ANALYSIS, ANTI-STATIC ANALYSIS|**Executable Code Virtualization**|*none*|
|
||||
|**B0009**|ANTI-BEHAVIORAL ANALYSIS|**Virtual Machine Detection**|Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/techniques/T1497),[T1633](https://attack.mitre.org/techniques/T1633))|
|
||||
|**B0010**|ANTI-STATIC ANALYSIS|**Call Graph Generation Evasion**|*none*|
|
||||
|**B0011**|EXECUTION|**Remote Commands**|Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/techniques/T1497),[T1633](https://attack.mitre.org/techniques/T1633))|
|
||||
|**B0012**|ANTI-STATIC ANALYSIS|**Disassembler Evasion**|*none*|
|
||||
|**B0013**|DISCOVERY|**Analysis Tool Discovery**|*none*|
|
||||
|**B0014**|DISCOVERY|**SMTP Connection Discovery**|*none*|
|
||||
|**B0015**|*not defined*|---|---|
|
||||
|**B0016**|IMPACT|**Compromise Data Integrity**|Data Manipulation: Stored Data Manipulation ([T1565.001](https://attack.mitre.org/techniques/T1565/001))|
|
||||
|**B0017**|IMPACT|**Destroy Hardware**|*none*|
|
||||
|**B0018**|IMPACT|**Resource Hijacking**|Resource Hijacking ([T1496](https://attack.mitre.org/techniques/T1496))|
|
||||
|**B0019**|IMPACT|**Manipulate Network Traffic**|Data Manipulation: Transmitted Data Manipulation ([T1565.002](https://attack.mitre.org/techniques/T1565/002))|
|
||||
|**B0020**|EXECUTION, LATERAL MOVEMENT|**Send Email**|Phishing ([T1566](https://attack.mitre.org/techniques/T1566))|
|
||||
|**B0021**|EXECUTION, LATERAL MOVEMENT|**Send Poisoned Email**|*none*|
|
||||
|**B0022**|IMPACT, PERSISTENCE|**Remote Access**|*none*|
|
||||
|**B0023**|EXECUTION|**Install Additional Program**|*none*|
|
||||
|**B0024**|EXECUTION|**Prevent Concurrent Execution**|*none*|
|
||||
|**B0025**|ANTI-BEHAVIORAL ANALYSIS//EXECUTION|**Conditional Execution**|Execution Guardrails ([T1480](https://attack.mitre.org/techniques/T1480))|
|
||||
|**B0026**|LATERAL MOVEMENT, PERSISTENCE|**Malicious Network Driver**|*none*|
|
||||
|**B0027**|DEFENSE EVASION|**Alternative Installation Location**|*none*|
|
||||
|**B0028**|CREDENTIAL ACCESS|**Cryptocurrency**|*none*|
|
||||
|**B0029**|DEFENSE EVASION|**Polymorphic Code**|*none*|
|
||||
|**B0030**|COMMAND AND CONTROL|**Command and Control Communication**|*none*|
|
||||
|**B0031**|COMMAND AND CONTROL|**Domain Name Generation**|Dynamic Resolution: Domain Name Generation ([T1568.002](https://attack.mitre.org/techniques/T1568/002))|
|
||||
|**B0032**|ANTI-STATIC ANALYSIS|**Executable Code Obfuscation**|*none*|
|
||||
|**B0033**|IMPACT|**Denial of Service**|Network Denial of Service ([T1498](https://attack.mitre.org/techniques/T1498))|
|
||||
|**B0034**|ANTI-STATIC ANALYSIS|**Executable Code Obfuscation**|*none*|
|
||||
|**B0035**|PERSISTENCE|**Shutdown Event**|*none*|
|
||||
|**B0036**|ANTI-BEHAVIORAL ANALYSIS|**Capture Evasion**|*none*|
|
||||
|**B0037**|DEFENSE EVASION|**Bypass Data Execution Prevention**|*none*|
|
||||
|**B0038**|DISCOVERY|**Self Discovery**|*none*|
|
||||
|**B0039**|IMPACT|**Spamming**|*none*|
|
||||
|**B0040**|DEFENSE EVASION|**Covert Location**|*none*|
|
||||
|**B0041**|*not defined*|---|---|
|
||||
|**B0042**|IMPACT|**Modify Hardware**|*none*|
|
||||
|**B0043**|DISCOVERY|**Taskbar Discovery**|*none*|
|
||||
|**B0044**|EXECUTION|**Execution Dependency**|*none*|
|
||||
|**B0045**|ANTI-STATIC ANALYSIS|**Data Flow Analysis Evasion**|*none*|
|
||||
|**B0046**|DISCOVERY|**Code Discovery**|*none*|
|
||||
|**B0047**|DEFENSE EVASION, PERSISTENCE|**Install Insecure or Malicious Code**|*none*|
|
||||
|
||||
**Copyright 2022 The MITRE Corporation. [Terms of Use.](./tou.md)**
|
||||
|
||||
|
||||
@@ -1,30 +1,29 @@
|
||||
|||
|
||||
|--|-----|
|
||||
|**ID**|**M9001**|
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>OB0001</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
# Anti-Behavioral Analysis
|
||||
Behaviors that prevent, obstruct, or evade behavioral analysis (sandbox, debugger, etc). Because the underlying methods differ, separate "detection" and "evasion" behaviors are defined for some anti-behavioral analysis areas (e.g., anti-debugger).
|
||||
Behaviors that prevent, obstruct, or evade behavioral analysis of malware--for example, analysis done using a sandbox or debugger. Because the underlying methods differ, separate "detection" and "evasion" behaviors are defined for some anti-behavioral analysis areas.
|
||||
|
||||
Two primary resources for anti-behavioral analysis behaviors are [[1]](#1) and [[2]](#2).
|
||||
|
||||
* **Capture Evasion** [M0036](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/evade-capture.md)
|
||||
* **Debugger Detection** [M0001](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/detect-debugger.md)
|
||||
* **Debugger Evasion** [M0002](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/evade-debugger.md)
|
||||
* **Dynamic Analysis Evasion** [M0003](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/evade-dynamic-analysis.md)
|
||||
* **Emulator Detection** [M0004](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/detect-emulator.md)
|
||||
* **Emulator Evasion** [M0005](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/evade-emulator.md)
|
||||
* **Executable Code Virtualization** [M0008](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/exe-code-virtualize.md)
|
||||
* **Execution Guardrails** [E1480](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/execution-guardrails.md)
|
||||
* **Hooking** [E1179](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/hooking.md)
|
||||
* **Memory Dump Evasion** [M0006](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/evade-memory-dump.md)
|
||||
* **Sandbox Detection** [M0007](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/detect-sandbox.md)
|
||||
* **Software Packing** [E1045](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/software-packing.md)
|
||||
* **Virtual Machine Detection** [M0009](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/detect-vm.md)
|
||||
* **Capture Evasion** [B0036](../anti-behavioral-analysis/capture-evasion.md)
|
||||
* **Conditional Execution** [B0025](../execution/conditional-execution.md)
|
||||
* **Debugger Detection** [B0001](../anti-behavioral-analysis/debugger-detection.md)
|
||||
* **Debugger Evasion** [B0002](../anti-behavioral-analysis/debugger-evasion.md)
|
||||
* **Dynamic Analysis Evasion** [B0003](../anti-behavioral-analysis/dynamic-analysis-evasion.md)
|
||||
* **Emulator Detection** [B0004](../anti-behavioral-analysis/emulator-detection.md)
|
||||
* **Emulator Evasion** [B0005](../anti-behavioral-analysis/emulator-evasion.md)
|
||||
* **Executable Code Virtualization** [B0008](../anti-static-analysis/executable-code-virtualization.md)
|
||||
* **Hijack Execution Flow** [F0015](../defense-evasion/hijack-execution-flow.md)
|
||||
* **Memory Dump Evasion** [B0006](../anti-behavioral-analysis/memory-dump-evasion.md)
|
||||
* **Sandbox Detection** [B0007](../anti-behavioral-analysis/sandbox-detection.md)
|
||||
* **Software Packing** [F0001](../anti-static-analysis/software-packing.md)
|
||||
* **Virtual Machine Detection** [B0009](../anti-behavioral-analysis/virtual-machine-detection.md)
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> Unprotect Project, a database about malware self-defense and protection. http://unprotect.tdgt.org/index.php/Unprotect_Project
|
||||
<a name="1">[1]</a> Unprotect Project, a database about malware self-defense and protection. https://search.unprotect.it/map
|
||||
|
||||
<a name="2">[2]</a> InDepthUnpacking, course content for teaching malware anti-analysis techniques and mitigations, with emphasis on packers. https://github.com/knowmalware/InDepthUnpacking
|
||||
|
||||
|
||||
|
||||
@@ -0,0 +1,28 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0036</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Capture Evasion
|
||||
===============
|
||||
Malware has characteristics enabling it to evade capture from the infected system.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Encrypted Payloads**|B0036.002|Decryption key is stored external to the executable or never touches the disk.|
|
||||
|**Memory-only Payload**|B0036.001|Malware is never written to disk (e.g., RAT plugins received from the controller are never written to disk).|
|
||||
|**Multiple Stages of Loaders**|B0036.003|Multiple stages of loaders are used with an encoded payload.|
|
||||
@@ -0,0 +1,96 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0001</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Debugger Detection
|
||||
==================
|
||||
Malware detects whether it's being executed inside a debugger. If so, conditional execution selects a benign execution path. [[1]](#1), [[2]](#2)
|
||||
|
||||
Details on methods of detecting debuggers are given in the references; many are listed below.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**API Hook Detection**|B0001.001|Module bounds based [[7]](#7).|
|
||||
|**Anti-debugging Instructions**|B0001.034|Malware code contains mnemonics related to anti-debugging (e.g., rdtsc, icebp).|
|
||||
|**CheckRemoteDebuggerPresent**|B0001.002|The kernel32!CheckRemoteDebuggerPresent function calls NtQueryInformationProcess with ProcessInformationClass parameter set to 7 (ProcessDebugPort constant).|
|
||||
|**Check Processes**|B0001.038|The malware may check running processes for specific strings such as "malw" to detect a analysis environment.|
|
||||
|**CloseHandle**|B0001.003|(NtClose); If an invalid handle is passed to the CloseHandle function and a debugger is present, then an EXCEPTION_INVALID_HANDLE (0xC0000008) exception will be raised. [[7]](#7)|
|
||||
|**Debugger Artifacts**|B0001.004|Malware may detect a debugger by its artifact (window title, device driver, exports, etc.).|
|
||||
|**Hardware Breakpoints**|B0001.005|(SEH/GetThreadContext); Debug registers will indicate the presence of a debugger. See [[7]](#7) for details.|
|
||||
|**Interruption**|B0001.006|If an interruption is mishandled by the debugger, it can cause a single-byte instruction to be inadvertently skipped, which can be detected by malware. Examples include Interrupt 0x2d and Interrupt 1 [7].|
|
||||
|**IsDebuggerPresent**|B0001.008|The kernel32!IsDebuggerPresent API function call checks the PEB BeingDebugged flag to see if the calling process is being debugged. It returns 1 if the process is being debugged, 0 otherwise. This is one of the most common ways of debugger detection.|
|
||||
|**Memory Breakpoints**|B0001.009|(PAGE_GUARD); Guard pages trigger an exception the first time they are accessed and can be used to detect a debugger. See [[7]](#7) for details.|
|
||||
|**Memory Write Watching**|B0001.010|[[7]](#7)|
|
||||
|**Monitoring Thread**|B0001.011|Malware may spawn a monitoring thread to detect tampering, breakpoints, etc.|
|
||||
|**NtQueryInformationProcess**|B0001.012|Calling NtQueryInformationProcess with its ProcessInformationClass parameter set to 0x07 (ProcessDebugPort constant) will cause the system to set ProcessInformation to -1 if the process is being debugged. Calling with ProcessInformationClass set to 0x0E (ProcessDebugFlags) or 0x11 (ProcessDebugObject) are used similarly. Testing "ProcessDebugPort" is equivalent to using the kernel32!CheckRemoteDebuggerPresent API call (see next method).|
|
||||
|**NtQueryObject**|B0001.013|The ObjectTypeInformation and ObjectAllTypesInformation flags are checked for debugger detection.|
|
||||
|**NtSetInformationThread**|B0001.014|Calling this API with a fake class length or thread handle can indicate whether it is hooked. After calling NtSetInformationThread properly, the HideThreadFromDebugger flag is checked with the NtQueryInformationThread API. [[7]](#7)|
|
||||
|**NtYieldExecution/SwitchToThread**|B0001.015|[[7]](#7)|
|
||||
|**OutputDebugString**|B0001.016|(GetLastError); The OutputDebugString function will demonstrate different behavior depending whether or not a debugger is present. See [[7]](#7) for details.|
|
||||
|**Page Exception Breakpoint Detection**|B0001.017|[[7]](#7)|
|
||||
|**Parent Process**|B0001.018|(Explorer.exe); Executing an application by a debugger will result in the parent process being the debugger process rather than the shell process (Explorer.exe) or the command line. Malware checks its parent process; if it's not explorer.exe, it's assumed to be a debugger. [[7]](#7)|
|
||||
|**Process Environment Block**|B0001.019|The Process Environment Block (PEB) is a Windows data structure associated with each process that contains several fields, such as "BeingDebugged," "NtGlobalFlag," and "IsDebugged". Testing the value of this PEB field of a particular process can indicate whether the process is being debugged. Testing "BeingDebugged" is equivalent to using the kernel32!IsDebuggerPresent API call (see separate method).|
|
||||
|**Process Environment Block BeingDebugged**|B0001.035|The BeingDebugged field is tested to determine whether the process is being debugged.|
|
||||
|**Process Environment Block IsDebugged**|B0001.037|The IsDebugged field is tested to determine whether the process is being debugged.|
|
||||
|**Process Environment Block NtGlobalFlag**|B0001.036|The NtGlobalFlag field is tested to determine whether the process is being debugged.|
|
||||
|**Process Jobs**|B0001.020|[[7]](#7)|
|
||||
|**ProcessHeap**|B0001.021|Process heaps are affected by debuggers. Malware can detect a debugger by checking heap header fields such as Flags (debugger present if value greater than 2) or ForceFlags (debugger present if value greater than 0).|
|
||||
|**RtlAdjustPrivilege**|B0001.022|Malware may call RtlAdjustPrivilege to detect if a debugger is attached (or to prevent a debugger from attaching).|
|
||||
|**SeDebugPrivilege**|B0001.023|(Csrss.exe); Using the OpenProcess function on the csrss.exe process can detect a debugger. [[7]](#7)|
|
||||
|**SetHandleInformation**|B0001.024|(Protected Handle)|
|
||||
|**Software Breakpoints**|B0001.025|(INT3/0xCC)|
|
||||
|**Stack Canary**|B0001.026|Similar to the anti-exploitation method of the same name, malware may try to detect mucking with values on the stack.|
|
||||
|**TIB Aware**|B0001.027|Malware may access information in the Thread Information Block (TIB) for debug detection or process obfuscation detection. The TIB can be accessed as an offset of the segment register (e.g., fs:[20h]).|
|
||||
|**TLS Callbacks**|B0001.029|[[7]](#7)|
|
||||
|**Timing/Delay Check**|B0001.028|Malware may compare time between two points to detect unusual execution, such as the (relative) massive delays introduced by debugging.|
|
||||
|**Timing/Delay Check GetTickCount**|B0001.032|Malware uses GetTickCount function in a timing/delay check.|
|
||||
|**Timing/Delay Check QueryPerformanceCounter**|B0001.033|Malware uses QueryPerformanceCounter in a timing/delay check.|
|
||||
|**UnhandledExceptionFilter**|B0001.030|The UnhandledExceptionFilter function is called if no registered exception handlers exist, but it will not be reached if a debugger is present. See [[7]](#7) for details.|
|
||||
|**WudfIsAnyDebuggerPresent**|B0001.031|Includes use of WudfIsAnyDebuggerPresent, WudfIsKernelDebuggerPresent, WudfIsUserDebuggerPresent.|
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Redhip**](../xample-malware/redhip.md)|January 2011|Redhip uses general approaches to detecting user level debuggers (e.g., Process Environment Block 'Being Debugged' field), as well as specific checks for kernel level debuggers like SOFTICE. [[4]](#4)|
|
||||
|[**Gamut**](../xample-malware/gamut.md)|2014|The malware detects debuggers using an INT 03h trap and IsDebuggerPresent[[8]](#8)|
|
||||
|[**Rombertik**](../xample-malware/rombertik.md)|2015|an anti-analysis function within the packer is called to check the username and filename of the executing process for strings like “malwar”, “sampl”, “viru”, and “sandb”. [[9]](#9)|
|
||||
|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|Poison Ivy Variant checks for breakpoints and exits immediately if found [[10]](#10)|
|
||||
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> Alexander Antukh, "Anti-debugging Techniques Cheat Sheet," 19 January 2015. http://antukh.com/blog/2015/01/19/malware-techniques-cheat-sheet.
|
||||
|
||||
<a name="2">[2]</a> Joshua Cannell, Malwarebytes Labs, "Five Anti-Analysis Tricks that sometimes Fool Analysts," 31 March 2016. https://blog.malwarebytes.com/threat-analysis/2014/09/five-anti-debugging-tricks-that-sometimes-fool-analysts.
|
||||
|
||||
<a name="3">[3]</a> Peter Ferrie, "The 'Ultimate' Anti-Debugging Reference," 4 May 2011. https://anti-reversing.com/Downloads/Anti-Reversing/The_Ultimate_Anti-Reversing_Reference.pdf.
|
||||
|
||||
<a name="4">[4]</a> Atif Mushtaq, FireEye, "The Dead Giveaways of VM-Aware Malware," 27 January 2011. https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html.
|
||||
|
||||
<a name="5">[5]</a> Ayoub Faouzi (LordNoteworthy), Al-Khaser v0.79. https://github.com/LordNoteworthy/al-khaser
|
||||
|
||||
<a name="6">[6]</a> Nicolas Falliere, Symantec, "Windows Anti-Debug Reference," 11 September 2007. https://www.symantec.com/connect/articles/windows-anti-debug-reference.
|
||||
|
||||
<a name="7">[7]</a> Anti Debugging Tricks, Al-Khaser. https://github.com/LordNoteworthy/al-khaser/wiki/Anti-Debugging-Tricks
|
||||
|
||||
<a name="8">[8]</a> https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/gamut-spambot-analysis/
|
||||
|
||||
<a name="9">[9]</a> https://blogs.cisco.com/security/talos/rombertik
|
||||
|
||||
<a name="10">[10]</a> https://www.mandiant.com/sites/default/files/2021-09/rpt-poison-ivy.pdf
|
||||
@@ -0,0 +1,81 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0002</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Debugger Evasion (<a href="https://attack.mitre.org/techniques/T1622/">T1622</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Debugger Evasion
|
||||
================
|
||||
Behaviors that make debugging difficult.
|
||||
|
||||
A thorough reference for anti-debugging, both detection and evasion, is given in [[1]](#1).
|
||||
|
||||
The related **Debugger Evasion ([T1622](https://attack.mitre.org/techniques/T1622/))** ATT&CK technique was defined subsequent to this MBC behavior.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Block Interrupts**|B0002.001|Block interrupt (via hooking) 1 and/or 3 to prevent debuggers from working.|
|
||||
|**Break Point Clearing**|B0002.002|Intentionally clearing software or hardware breakpoints.|
|
||||
|**Byte Stealing**|B0002.003|Move or copy the first bytes / instructions of the original code elsewhere. AKA stolen bytes or code splicing. For example, a packer may incorporate the first few instructions of the original EntryPoint (EP) into its unpacking stub before the tail transition in order to confuse automated unpackers and novice analysts. This can make it harder for rebuilding and may bypass breakpoints if set prematurely.|
|
||||
|**Change SizeOfImage**|B0002.004|Changing this value during run time can prevent some debuggers from attaching. Also confuses some unpackers and dumpers.|
|
||||
|**Code Integrity Check**|B0002.005|Check that the unpacking code is unmodified. Variation exists where unpacking code is part of the "key" used to unpack, therefore any Software Breakpoints during debugging causes unpacking to completely fail or result in malformed unpacked code.|
|
||||
|**Exception Misdirection**|B0002.006|Using exception handling (SEH) to cause flow of program to non-obvious paths.|
|
||||
|**Get Base Indirectly**|B0002.007|CALL to a POP; finds base of code or data, often the packed version of the code; also used often in obfuscated/packed shellcode.|
|
||||
|**Guard Pages**|B0002.008|Encrypt blocks of code individually and decrypt temporarily only upon execution.|
|
||||
|**Hook Interrupt**|B0002.009|Modification of interrupt vector or descriptor tables.|
|
||||
|**Import Obfuscation**|B0002.010|Add obfuscation between imports calls and APIs.|
|
||||
|**Inlining**|B0002.011|Variation of static linking where full API code inserted everywhere it would have been called.|
|
||||
|**Loop Escapes**|B0002.012|Use SEH or other methods to break out of a loop instead of a conditional jump.|
|
||||
|**Malloc Use**|B0002.013|Instead of unpacking into a pre-defined section/segment (ex: .text) of the binary, use malloc() / VirtualAlloc() to create a new segment. This makes keeping track of memory locations across different runs more difficult, as there is no guarantee that malloc/VirtualAlloc will assign the same address range each time.|
|
||||
|**Modify PE Header**|B0002.014|Any part of the header is changed or erased.|
|
||||
|**Nanomites**|B0002.015|int3 with code replacement table; debugs itself.|
|
||||
|**Obfuscate Library Use**|B0002.016|LoadLibrary API calls or direct access of kernel32 via PEB (fs[0]) pointers, used to rebuild IAT or just obfuscate library use.|
|
||||
|**Parallel Threads**|B0002.017|Use several parallel threads to make analysis harder.|
|
||||
|**Pipeline Misdirection**|B0002.018|Take advantage of pipelining in modern processors to misdirect debugging, emulation, or static analysis tools. An unpacker can assume a certain number of opcodes will be cached and then proceed to overwrite them in memory, causing a debugger/emulator/analyzer to follow different code than is normally executed.|
|
||||
|**Pre-Debug**|B0002.019|Prevents debugger from attaching to process or to break until after the code of interest has been executed.|
|
||||
|**Relocate API Code**|B0002.020|Relocate API code in separate buffer (calls don’t lead to imported DLLs).|
|
||||
|**Return Obfuscation**|B0002.021|Overwrite the RET address on the stack or the code at the RET address. Variation seen that writes to the start-up code or main module that called the malware's WinMain or DllMain.|
|
||||
|**RtlAdjustPrivilege**|B0002.022|Calling RtlAdjustPrivilege to either prevent a debugger from attaching or to detect if a debugger is attached.|
|
||||
|**Section Misalignment**|B0002.023|Some analysis tools cannot handle binaries with misaligned sections.|
|
||||
|**Self-Debugging**|B0002.024|Debug itself to prevent another debugger to be attached.|
|
||||
|**Self-Unmapping**|B0002.025|UnmapViewOfFile() on itself.|
|
||||
|**Static Linking**|B0002.026|Copy locally the whole content of API code.|
|
||||
|**Stolen API Code**|B0002.027|A variation of "byte stealing" where the first few instructions or bytes of an API are executed in user code, allowing the IAT to point into the middle of an API function. This confuses IAT rebuilders such as ImpRec and Scylla and may bypass breakpoints.|
|
||||
|**Tampering**|B0002.028|Erase or corrupt specific file parts to prevent rebuilding (header, packer stub, etc.).|
|
||||
|**Thread Timeout**|B0002.029|Setting dwMilliseconds in WaitForSingleObject to a small number will timeout the thread before the analyst can step through and analyze the code executing in the thread. Modifying this via patch, register, or stack to the value `0xFFFFFFFF`, the **INFINITE** constant circumvents this anti-debugging technique.|
|
||||
|**Use Interrupts**|B0002.030|The unpacking code relies on use of int 1 or int 3, or it uses the interrupt vector table as part of the decryption "key".|
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|**Fake Adobe Flash Update OS X**|February 2016|[[2]](#2)|
|
||||
|**Dridex**|March 2015|[[3]](#3)|
|
||||
|[**Redhip**](../xample-malware/redhip.md)|2011|Redhip uses general approaches to detecting user level debuggers (e.g., Process Environment Block 'Being Debugged' field), as well as specific checks for kernel level debuggers like SOFICE. [[6]](#6)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://anti-reversing.com/Downloads/Anti-Reversing/The_Ultimate_Anti-Reversing_Reference.pdf
|
||||
|
||||
<a name="2">[2]</a> https://www.synack.com/2016/02/17/analyzing-the-anti-analysis-logic-of-an-adware-installer/
|
||||
|
||||
<a name="3">[3]</a> http://phishme.com/dridex-code-breaking-modify-the-malware-to-bypass-the-vm-bypass/
|
||||
|
||||
<a name="4">[4]</a> http://antukh.com/blog/2015/01/19/malware-techniques-cheat-sheet/
|
||||
|
||||
<a name="5">[5]</a> https://search.unprotect.it/map/
|
||||
|
||||
<a name="6">[6]</a> https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
|
||||
@@ -1,69 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**M0001**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
|
||||
Debugger Detection
|
||||
==================
|
||||
Malware detects whether it's being executed inside a debugger. If so, conditional execution selects a benign execution path. [[1]](#1), [[2]](#2)
|
||||
|
||||
Details on methods of detecting debuggers are given in the references; many are listed below.
|
||||
|
||||
Methods
|
||||
-------
|
||||
* **API Hook Detection**: module bounds based [[7]](#7)
|
||||
* **CheckRemoteDebuggerPresent**: The kernel32!CheckRemoteDebuggerPresent function calls NtQueryInformationProcess with ProcessInformationClass parameter set to 7 (ProcessDebugPort constant).
|
||||
* **CloseHandle**: (NtClose); If an invalid handle is passed to the CloseHandle function and a debugger is present, then an EXCEPTION_INVALID_HANDLE (0xC0000008) exception will be raised. [[7]](#7)
|
||||
* **Debugger Artifacts**: Malware may detect a debugger by its artifact (window title, device driver, exports, etc.).
|
||||
* **Hardware Breakpoints**: (SEH/GetThreadContext); Debug registers will indicate the presence of a debugger. See [[7]](#7) for details.
|
||||
* **Interrupt 0x2d**: If int 0x2d is mishandled by the debugger, it can cause a single-byte instruction to be inadvertently skipped, which can be detected by malware.
|
||||
* **Interrupt 1**: [[7]](#7)
|
||||
* **IsDebuggerPresent**: The kernel32!IsDebuggerPresent API function call checks the PEB BeingDebugged flag to see if the calling process is being debugged. It returns 1 if the process is being debugged, 0 otherwise. This is one of the most common ways of debugger detection.
|
||||
* **Memory Breakpoints**: (PAGE_GUARD); Guard pages trigger an exception the first time they are accessed and can be used to detect a debugger. See [[7]](#7) for details.
|
||||
* **Memory Write Watching**: [[7]](#7)
|
||||
* **Monitoring Thread**: Malware may spawn a monitoring thread to detect tampering, breakpoints, etc.
|
||||
* **NtQueryInformationProcess**: Calling NtQueryInformationProcess with its ProcessInformationClass parameter set to 0x07 (ProcessDebugPort constant) will cause the system to set ProcessInformation to -1 if the process is being debugged. Calling with ProcessInformationClass set to 0x0E (ProcessDebugFlags) or 0x11 (ProcessDebugObject) are used similarly. Testing "ProcessDebugPort" is equivalent to using the kernel32!CheckRemoteDebuggerPresent API call (see next method).
|
||||
* **NtQueryObject**: The ObjectTypeInformation and ObjectAllTypesInformation flags are checked for debugger detection.
|
||||
* **NtSetInformationThread**: Calling this API with a fake class length or thread handle can indicate whether it is hooked. After calling NtSetInformationThread properly, the HideThreadFromDebugger flag is checked with the NtQueryInformationThread API. [[7]](#7)
|
||||
* **NtYieldExecution/SwitchToThread**: [[7]](#7)
|
||||
* **OutputDebugString**: (GetLastError); The OutputDebugString function will demonstrate different behavior depending whether or not a debugger is present. See [[7]](#7) for details.
|
||||
* **Page Exception Breakpoint Detection**: [[7]](#7)
|
||||
* **Parent Process**: (Explorer.exe); Executing an application by a debugger will result in the parent process being the debugger process rather than the shell process (Explorer.exe) or the command line. Malware checks its parent process; if it's not explorer.exe, it's assumed to be a debugger. [[7]](#7)
|
||||
* **Process Environment Block**: The Process Environment Block (PEB) is a Windows data structure associated with each process that contains several fields, such as "BeingDebugged," "NtGlobalFlag," and "IsDebugged". Testing the value of this PEB field of a particular process can indicate whether the process is being debugged. Testing "BeingDebugged" is equivalent to using the kernel32!IsDebuggerPresent API call (see next method).
|
||||
* **Process Jobs**: [[7]](#7)
|
||||
* **ProcessHeap**: Process heaps are affected by debuggers. Malware can detect a debugger by checking heap header fields such as Flags (debugger present if value greater than 2) or ForceFlags (debugger present if value greater than 0).
|
||||
* **RtlAdjustPrivilege**: Malware may call RtlAdjustPrivilege to detect if a debugger is attached (or to prevent a debugger from attaching).
|
||||
* **SeDebugPrivilege**: (Csrss.exe); Using the OpenProcess function on the csrss.exe process can detect a debugger. [[7]](#7)
|
||||
* **SetHandleInformation**: (Protected Handle);
|
||||
* **Software Breakpoints**: (INT3/0xCC)
|
||||
* **Stack Canary**: Similar to the anti-exploitation method of the same name, malware may try to detect mucking with values on the stack.
|
||||
* **TIB Aware**: Malware may access information in the Thread Information Block (TIB) for debug detection or process obfuscation detection. The TIB can be accessed as an offset of the segment register (e.g., fs:[20h]).
|
||||
* **Timing/Delay Checks**: Malware may compare time between two points to detect unusual execution, such as the (relative) massive delays introduced by debugging.
|
||||
* **TLS Callbacks**: [[7]](#7)
|
||||
* **UnhandledExceptionFilter**: The UnhandledExceptionFilter function is called if no registered exception handlers exist, but it will not be reached if a debugger is present. See [[7]](#7) for details.
|
||||
* **WudfIsAnyDebuggerPresent**: WudfIsAnyDebuggerPresent, WudfIsKernelDebuggerPresent, WudfIsUserDebuggerPresent
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|--------|-----------------------------|
|
||||
|[**Redhip**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/redhip.md)|January 2011|Redhip uses general approaches to detecting user level debuggers (e.g., Process Environment Block 'Being Debugged' field), as well as specific checks for kernel level debuggers like SOFICE. [[4]](#4)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> Alexander Antukh, "Anti-debugging Techniques Cheat Sheet," 19 January 2015. http://antukh.com/blog/2015/01/19/malware-techniques-cheat-sheet.
|
||||
|
||||
<a name="2">[2]</a> Joshua Cannell, Malwarebytes Labs, "Five Anti-Analysis Tricks that sometimes Fool Analysts," 31 March 2016. https://blog.malwarebytes.com/threat-analysis/2014/09/five-anti-debugging-tricks-that-sometimes-fool-analysts.
|
||||
|
||||
<a name="3">[3]</a> Peter Ferrie, "The 'Ultimate' Anti-Debugging Reference," 4 May 2011. https://anti-reversing.com/Downloads/Anti-Reversing/The_Ultimate_Anti-Reversing_Reference.pdf.
|
||||
|
||||
<a name="4">[4]</a> Atif Mushtaq, FireEye, "The Dead Giveaways of VM-Aware Malware," 27 January 2011. https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html.
|
||||
|
||||
<a name="5">[5]</a> Ayoub Faouzi (LordNoteworthy), Al-Khaser v0.79. https://github.com/LordNoteworthy/al-khaser
|
||||
|
||||
<a name="6">[6]</a> Nicolas Falliere, Symantec, "Windows Anti-Debug Reference," 11 September 2007. https://www.symantec.com/connect/articles/windows-anti-debug-reference.
|
||||
|
||||
<a name="7">[7]</a> Anti Debugging Tricks, Al-Khaser. https://github.com/LordNoteworthy/al-khaser/wiki/Anti-Debugging-Tricks
|
||||
|
||||
@@ -1,29 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**M0004**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
|
||||
Emulator Detection
|
||||
==================
|
||||
Detects whether the malware instance is being executed inside an emulator. If so, conditional execution selects a benign execution path.
|
||||
|
||||
Methods
|
||||
-------
|
||||
* **Check for Emulator-related Files**: Checks whether particular files (e.g., QEMU files) exist.
|
||||
* **Check for WINE Version**: Checks for WINE via the `get_wine_version` function from WINE's `ntdll.dll`.
|
||||
* **Check Emulator-related Registry Keys**: Emulators register artifacts in the registry, which can be detected by malware. For example, installation of QEMU results in the registry key: *HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 0\Target Id 0\Logical Unit Id 0* with value=*Identifier* and data=*QEMU*, or registry key: *HARDWARE\Description\System* with value=*SystemBiosVersion* and data=*QEMU*. [[1]](#1)
|
||||
* **Failed Network Connections**: Some emulated systems fail to handle some network communications; such failures will indicate the emulated environment.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|--------|-----------------------------|
|
||||
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> http://unprotect.tdgt.org/index.php/Sandbox_Evasion
|
||||
|
||||
|
||||
@@ -1,39 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**M0007**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
|
||||
Sandbox Detection
|
||||
=================
|
||||
Detects whether the malware instance is being executed inside an instrumented sandbox environment (e.g., Cuckoo Sandbox). If so, conditional execution selects a benign execution path.
|
||||
|
||||
The Sandbox Detection behavior relates to anti-analysis, whereas a related ATT&CK technique relates to [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion): for details, see the ATT&CK: [**Virtualization/Sandbox Evasion**](https://attack.mitre.org/techniques/T1497/).
|
||||
|
||||
Methods
|
||||
-------
|
||||
* **Check Clipboard Data**: Checks clipboard data which can be used to detect whether execution is inside a sandbox.
|
||||
* **Check Files**: Sandboxes create files on the file system. Malware can check the different folders to find sandbox artifacts.
|
||||
* **Human User Check**: Detects whether there is any "user" activity on the machine, such as the movement of the mouse cursor, non-default wallpaper, or recently opened Office files. If there is no human activity, the machine is suspected to be a virtualized machine and/or sandbox. Other items used to detect a user: mouse clicks (single/double), DialogBox, scrolling, color of background pixel [[3]](#3).
|
||||
* **Injected DLL Testing**: Testing for the name of a particular DLL that is known to be injected by a sandbox for API hooking is a common way of detecting sandbox environments. This can be achieved through the kernel32!GetModuleHandle API call and other means.
|
||||
* **Product Key/ID Testing**: Checking for a particular product key/ID associated with a sandbox environment (commonly associated with the Windows host OS used in the environment) can be used to detect whether a malware instance is being executed in a particular sandbox. This can be achieved through several means, including testing for the Key/ID in the Windows registry.
|
||||
* **Screen Resolution Testing**: Sandboxes aren't used in the same manner as a typical user environment, so most of the time the screen resolution stays at the minimum 800x600 or lower. No one is actually working on a such small screen. Malware could potentially detect the screen resolution to determine if it's a user machine or a sandbox.
|
||||
* **Self Check**: Malware may check its own characteristics to determine whether it's running in a sandbox. For example, a malicious Office document might check its file name or VB project name.
|
||||
* **Timing/Date Checks**: Calling GetSystemTime or equiv and only executing code if the current date/hour/minute/second passes some check. Often this is for running only after or only until a specific date. This behavior can be mitigated in non-automated analysis environments.
|
||||
* **Timing/Uptime Check**: Comparing single GetTickCount with some value to see if system has been started at least *X* amount ago. This behavior can be mitigated in non-automated analysis environments.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|--------|-----------------------------|
|
||||
|[**Redhip**](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/redhip.md)|January 2011|Redhip detects publicly available automated analysis workbenches (e.g., Joe Box) by considering OS product keys and special DLLs. [[1]](#1)|
|
||||
|**Rombertik**|May 2015|[[2]](#2)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
|
||||
|
||||
<a name="2">[2]</a> http://labs.lastline.com/exposing-rombertik-turning-the-tables-on-evasive-malware
|
||||
|
||||
<a name="3">[3]</a> https://github.com/LordNoteworthy/al-khaser
|
||||
@@ -1,72 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**M0009**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis)|
|
||||
|**Related ATT&CK Technique**|[Virtualization/Sandbox Evasion](https://attack.mitre.org/techniques/T1497/)|
|
||||
|
||||
|
||||
Virtual Machine Detection
|
||||
=========================
|
||||
Detects whether the malware instance is being executed in a virtual machine (VM), such as VMWare. If so, conditional execution selects a benign execution path. [[1]](#1)
|
||||
|
||||
The Virtual Machine Detection behavior relates to anti-analysis, whereas a related ATT&CK technique relates to [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion): for details, see the ATT&CK: [**Virtualization/Sandbox Evasion**](https://attack.mitre.org/techniques/T1497/).
|
||||
|
||||
Methods
|
||||
-------
|
||||
* **Check File and Directory Artifacts**: Virtual machines create files on the file system (e.g., VMware creates files in the installation directory C:\Program Files\VMware\VMware Tools). Malware can check the different folders to find virtual machine artifacts (e.g., Virtualbox has the artifact VBoxMouse.sys). [[2]](#2)
|
||||
* **Check Memory Artifacts**: VMware leaves many artifacts in memory. Some are critical processor structures, which, because they are either moved or changed on a virtual machine, leave recognizable footprints. Malware can search through physical memory for the strings VMware, commonly used to detect memory artifacts. [[2]](#2)
|
||||
* **Check Named System Objects**: Virtual machines often include specific named system objects by default, such as Windows device drivers, which can be detected by testing for specific strings, whether found in the Windows registry or other places.
|
||||
* **Check Processes**: The VMware Tools use processes like VMwareServices.exe or VMwareTray.exe, to perform actions on the virtual environment. Malware can list the process and searches for the VMware string. Process related to Virtualbox can be detected by malware by query the process list. [[2]](#2)
|
||||
* **Check Registry Keys**: Virtual machines register artifacts in the registry, which can be detected by malware. For example, a search for "VMware" or "VBOX" in the registry might reveal keys that include information about a virtual hard drive, adapters, running services, or virtual mouse. [[2]](#2) Example registry key value artifacts include "HARDWARE\Description\System (SystemBiosVersion) (VBOX)" and "SYSTEM\ControlSet001\Control\SystemInformation (SystemManufacturer) (VMWARE)"; example registry key artifacts include "SOFTWARE\VMware, Inc.\VMware Tools (VMWARE)" and "SOFTWARE\Oracle\VirtualBox Guest Additions (VBOX)". [[5]](#5)
|
||||
* **Check Running Services**: VMwareService.exe runs the VMware Tools Service as a child of services.exe. It can be identified by listing services. [[2]](#2)
|
||||
* **Check Virtual Devices**: The presence of virtual devices can indicate a virtualized environment (e.g., "\\.\VBoxTrayIPC"). [[5]](#5)
|
||||
* **Check Windows**: Malware may check windows for VM-related characteristics such as:
|
||||
* *Window size*: tiny window size may indicate a VM.
|
||||
* *Unique windows*: may check for the presence of known windows from analysis tools running in a VM.
|
||||
* *Title bars*: may inject malicious code to svchost.exe to check all open window title bar text to a list of strings indicating virtualized environment.
|
||||
* **Guest Process Testing**: Virtual machines offer guest additions that can be installed to add functionality such as clipboard sharing. Detecting the process responsible for these tasks, via its name or other methods, is a technique employed by malware for detecting whether it is being executed in a virtual machine.
|
||||
* **HTML5 Performance Object Check**: In three browser families, it is possible to extract the frequency of the Windows performance counter frequency, using standard HTML and Javascript. This value can then be used to detect whether the code is being executed in a virtual machine, by detecting two specific frequencies commonly used in virtual but not physical machines.
|
||||
* **Human User Check**: Detects whether there is any "user" activity on the machine, such as the movement of the mouse cursor, non-default wallpaper, or recently opened Office files. If there is no human activity, the machine is suspected to be a virtualized machine and/or sandbox. Other items used to detect a user: mouse clicks (single/double), DialogBox, scrolling, color of background pixel, change in foreground window [[5]](#5).
|
||||
* **Modern Specs Check**: Different aspects of the hardware are inspected to determine whether the machine has modern characteristics. A machine with substandard specifications indicates a virtual environment:
|
||||
* *Total physical memory*: most modern machines have at leave 4 GB of memory. (GlobalMemoryStatusEx) [[5]](#5).
|
||||
* *Drive size*: most modern machines have at least 80 GB disks. May use DeviceloControl (IOCTL_DISK_GET_LENGTH_INFO) or GetDiskFreeSpaceEx (TotalNumberOfBytes) [[5]](#5).
|
||||
* *USB drive*: checks whether there is a potential USB drive; if not a virtual environment is suspected.
|
||||
* *Printer*: checks whether there is a potential connected printer or default Windows printers; if not a virtual environment is suspected.
|
||||
* *Processor count*: checks number of processors; single CPU machines are suspect.
|
||||
* *Keyboard layout*
|
||||
* *Software*: checks whether software is relatively current.
|
||||
* **Unique Hardware/Firmware Check**: Malware may check for hardware characteristics unique to being virtualized, allowing the malware to detect the virtual environment. Items checked include:
|
||||
* *BIOS*: characteristics of the BIOS, such as version, can indicate virtualization.
|
||||
* *I/O Communication Port*: VMware uses virtual I/O ports for communication between the virtual machine and the host operating system to support functionality like copy and paste between the two systems. The port can be queried and compared with a magic number VMXh to identify the use of VMware.
|
||||
* *CPU Name*
|
||||
* *CPU Location*: When an Operating System is virtualized, the CPU is relocated. [[2]](#2)
|
||||
* *MAC Address*: VMware uses specific virtual MAC address that can be detected. The usual MAC address used started with the following numbers: "00:0C:29", "00:1C:14", "00:50:56", "00:05:69". Virtualbox uses specific virtual MAC address that can be detected by Malware. The usual MAC address used started with the following numbers: 08:00:27. [[2]](#2)
|
||||
* **x86 Instruction Testing**: The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2)
|
||||
* *SIDT (red pill)*: Red Pill is an anti-VM technique that executes the SIDT instruction to grab the value of the IDTR register. The virtual machine monitor must relocate the guest's IDTR to avoid conflict with the host's IDTR. Since the virtual machine monitor is not notified when the virtual machine runs the SIDT instruction, the IDTR for the virtual machine is returned.
|
||||
* *SGDT/SLDT (no pill)*: The No Pill technique relies on the fact that the LDT structure is assigned to a processor not an Operating System. The LDT location on a host machine will be zero and on a virtual machine will be non-zero.
|
||||
* *SMSW*
|
||||
* *STR*
|
||||
* *CPUID*: Checking the CPU ID found within the registry can provide information to system type.
|
||||
* *IN*
|
||||
* *RDTSC*
|
||||
* *VMCPUID*
|
||||
* *VPCEXT*
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|-----------|-----------------------------|
|
||||
|**GravityRAT**|May 2018|GravityRAT checks system temperature by recording thermal readings for detecting VMs. Heat levels indicate whether the system is a VM. [[3]](#3)|
|
||||
|[**WebCobra**](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/webcobra.md)|2018|WebCobra injects malicious code to svchost.exe and uses an infinite loop to check all open windows and to compare each window’s title bar text with a set of strings to determine whether it is running in an isolated, malware analysis environment [[4]](#4)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
|
||||
|
||||
<a name="2">[2]</a> http://unprotect.tdgt.org/index.php/Sandbox_Evasion
|
||||
|
||||
<a name="3">[3]>/a> https://www.hackread.com/gravityrat-malware-evades-detection-targets-india/
|
||||
|
||||
<a name="4">[4]</a> https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/webcobra-malware-uses-victims-computers-to-mine-cryptocurrency/
|
||||
|
||||
<a name="5">[5]</a> https://github.com/LordNoteworthy/al-khaser
|
||||
@@ -0,0 +1,69 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0003</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Virtualization/Sandbox Evasion (<a href="https://attack.mitre.org/techniques/T1497/">T1497</a>, <a href="https://attack.mitre.org/techniques/T1633/">T1633</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Dynamic Analysis Evasion
|
||||
========================
|
||||
Malware may obstruct dynamic analysis in a sandbox, emulator, or virtual machine.
|
||||
|
||||
See **Emulator Evasion ([B0004](../anti-behavioral-analysis/emulator-evasion.md))** for an emulator-specific evasion behavior, and see **Conditional Execution ([B0025](../anti-behavioral-analysis/execution-guardrails.md))** for a behavior that constrains dynamic execution based on environmental conditions.
|
||||
|
||||
The related **Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/techniques/T1497/), [T1633](https://attack.mitre.org/techniques/T1633/))** ATT&CK techniques were defined subsequent to this MBC behavior.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Alternative ntdll.dll**|B0003.001|A copy of ntdll.dll is dropped to the filesystem and then loaded. This alternative DLL is used to execute function calls to evade sandboxes which use hooking in the operating system's ntdll.dll.|
|
||||
|**API Hammering**|B0003.012|Uses of a huge number of calls to Windows APIs as a form of extended sleep to evade analysis in sandbox environments.|
|
||||
|**Code Integrity Check**|B0003.011|Compares memory-based and disk-based versions of itself. If differences are detected, the malware alters its execution, possibly acting destructively.|
|
||||
|**Data Flood**|B0003.002|Overloads a sandbox by generating a flood of meaningless behavioral data. [[1]](#1)|
|
||||
|**Delayed Execution**|B0003.003|Stalling code is typically executed before any malicious behavior. The malware's aim is to delay the execution of the malicious activity long enough so that an automated dynamic analysis system fails to extract the interesting malicious behavior. This method is very similar to ATT&CK's [Virtualization/Sandbox Evasion: Time Based Evasion](https://attack.mitre.org/techniques/T1497/003/) sub-technique.|
|
||||
|**Demo Mode**|B0003.004|Inclusion of a demo binary/mode that is executed when token is absent or not privileged enough.|
|
||||
|**Drop Code**|B0003.005|Original file is written to disk then executed. May confuse some sandboxes, especially if the dropped executable must be provided specific arguments and the original dropper is not associated with the drop file(s).|
|
||||
|**Encode File**|B0003.006|Encode a file on disk, such as an implant's config file.|
|
||||
|**Hook File System**|B0003.007|Execution happens when a particular file or directory is accessed, often through hooking certain API calls such as CreateFileA and CreateFileW.|
|
||||
|**Hook Interrupt**|B0003.008|Modification of interrupt vector or descriptor tables.|
|
||||
|**Illusion**|B0003.009|Creates an illusion; makes the analyst think something happened when it didn't.|
|
||||
|**Restart**|B0003.010|Restarts or shuts down system to bypass sandboxing.|
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Ursnif**](../xample-malware/ursnif.md)|May 2016|Ursnif uses malware macros to evade sandbox detection. [[2]](#2)|
|
||||
|[**Terminator**](../xample-malware/terminator.md)|October 2013|The Terminator rat evades a sandbox by not executing until after a reboot. Most sandboxes don't reboot during an analysis. [[3]](#3)|
|
||||
|**Nap**|2013|Trojan Nap (tied to the Kelihos Botnet) uses extended sleep calls to evade sandbox analysis. [[3]](#3)|
|
||||
|**Smokeloader**|2019|Smokeloader drops a copy of ntdll.dll to %APPDATA%\Local\Temp\ [[4]](#4)|
|
||||
|[**WebCobra**](../xample-malware/webcobra.md)|2018|Evades dynamic analysis.)|
|
||||
|[**Rombertik**](../xample-malware/rombertik.md)|2015|The malware stalls by writing a byte of random data to memory 960 million times which complicates analysis. It also calls specific Windows API functions [[5]](#5)|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Uses numerous printf loops to delay the execution process and overload the sandbox with junk data (API Hammering) [[6]](#6)|
|
||||
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> http://joe4security.blogspot.com/2013/06/overloading-sandboxes-new-generic.html
|
||||
|
||||
<a name="2">[2]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/ursnif
|
||||
|
||||
<a name="3">[3]</a> https://www.fireeye.com/content/dam/fireeye-www/current-threats/pdfs/pf/file/fireeye-hot-knives-through-butter.pdf
|
||||
|
||||
<a name="4">[4]</a> https://research.checkpoint.com/2019-resurgence-of-smokeloader/
|
||||
|
||||
<a name="5">[5]</a> https://blogs.cisco.com/security/talos/rombertik
|
||||
|
||||
<a name="6">[6]</a> https://www.joesecurity.org/blog/498839998833561473
|
||||
@@ -0,0 +1,43 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0004</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Emulator Detection
|
||||
==================
|
||||
Detects whether the malware instance is being executed inside an emulator. If so, conditional execution selects a benign execution path.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Check Emulator-related Registry Keys**|B0004.003|Emulators register artifacts in the registry, which can be detected by malware. For example, installation of QEMU results in the registry key: *HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 0\Target Id 0\Logical Unit Id 0* with value=*Identifier* and data=*QEMU*, or registry key: *HARDWARE\Description\System* with value=*SystemBiosVersion* and data=*QEMU*. [[1]](#1)|
|
||||
|**Check for Emulator-related Files**|B0004.001|Checks whether particular files (e.g., QEMU files) exist.|
|
||||
|**Check for WINE Version**|B0004.002|Checks for WINE via the `get_wine_version` function from WINE's `ntdll.dll`.|
|
||||
|**Failed Network Connections**|B0004.004|Some emulated systems fail to handle some network communications; such failures will indicate the emulated environment.|
|
||||
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|Stuxnet checks for specific operating systems on 32-bit machines, registry keys, and dates to profile a potential target machine before execution. If the conditions are not met to be considered a viable target, it will exit execution [[2]](#2)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://search.unprotect.it/map/sandbox-evasion/
|
||||
|
||||
<a name="2">[2]</a> https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en
|
||||
@@ -0,0 +1,35 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0005</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Emulator Evasion
|
||||
================
|
||||
Behaviors that obstruct analysis in an emulator.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Different Opcode Sets**|B0005.001|Use different opcodes sets (ex: FPU, MMX, SSE) to block emulators.|
|
||||
|**Extra Loops/Time Locks**|B0005.004|Add extra loops to make time-constraint emulators give up.|
|
||||
|**Undocumented Opcodes**|B0005.002|Use rare or undocumented opcodes to block non-exhaustive emulators.|
|
||||
|**Unusual/Undocumented API Calls**|B0005.003|Call unusual APIs to block non-exhaustive emulators (particularly anti-virus).|
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**WebCobra**](../xample-malware/webcobra.md)|2018|Evades emulator-based analysis.)|
|
||||
@@ -1,27 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**M0036**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
Capture Evasion
|
||||
===============
|
||||
Malware has characteristics enabling it to evade capture from the infected system.
|
||||
|
||||
Methods
|
||||
-------
|
||||
* **Memory-only Payload**: Malware is never written to disk (e.g., RAT plugins received from the controller are never written to disk).
|
||||
* **Encrypted Payloads**: Decryption key is stored external to the executable or never touches the disk.
|
||||
* **Multiple Stages of Loaders**: Multiple stages of loaders are used with an encoded payload.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|-----------|-----------------------------|
|
||||
| | | |
|
||||
|
||||
References
|
||||
----------
|
||||
|
||||
|
||||
|
||||
@@ -1,65 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**M0002**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
|
||||
Debugger Evasion
|
||||
================
|
||||
Behaviors that make debugging difficult.
|
||||
|
||||
A thorough reference for anti-debugging, both detection and evasion, is given in [[1]](#1).
|
||||
|
||||
Methods
|
||||
-------
|
||||
* **Block Interrupts**: Block interrupt (via hooking) 1 and/or 3 to prevent debuggers from working.
|
||||
* **Break Point Clearing**: Intentionally clearing software or hardware breakpoints.
|
||||
* **Byte Stealing**: Move or copy the first bytes / instructions of the original code elsewhere. AKA stolen bytes or code splicing. For example, a packer may incorporate the first few instructions of the original EntryPoint (EP) into its unpacking stub before the tail transition in order to confuse automated unpackers and novice analysts. This can make it harder for rebuilding and may bypass breakpoints if set prematurely.
|
||||
* **Change SizeOfImage**: Changinging this value during run time can prevent some debuggers from attaching. Also confuses some unpackers and dumpers.
|
||||
* **Code Integrity Check**: Check that the unpacking code is unmodified. Variation exists where unpacking code is part of the "key" used to unpack, therefore any Software Breakpoints during debugging causes unpacking to completely fail or result in malformed unpacked code.
|
||||
* **Exception Misdirection**: Using exception handling (SEH) to cause flow of program to non-obvious paths.
|
||||
* **Get Base Indirectly**: CALL to a POP; finds base of code or data, often the packed version of the code; also used often in obfuscated/packed shellcode.
|
||||
* **Guard Pages**: Encrypt blocks of code individually and decrypt temporarily only upon execution.
|
||||
* **Hook Interrupt**: modification of interrupt vector or descriptor tables.
|
||||
* **Import Obfuscation**: Add obfuscation between imports calls and APIs.
|
||||
* **Inlining**: variation of static linking where full API code inserted everywhere it would have been called.
|
||||
* **Loop Escapes**: Use SEH or other methods to break out of a loop instead of a conditional jump.
|
||||
* **Malloc Use**: Instead of unpacking into a pre-defined section/segment (ex: .text) of the binary, use malloc() / VirtualAlloc() to create a new segment. This makes keeping track of memory locations across different runs more difficult, as there is no guarantee that malloc/VirtualAlloc will assign the same address range each time.
|
||||
* **Modify PE Header**: Any part of the header is changed or erased.
|
||||
* **Nanomites**: int3 with code replacement table; debugs itself.
|
||||
* **Obfuscate Library Use**: LoadLibrary API calls or direct access of kernel32 via PEB (fs[0]) pointers, used to rebuild IAT or just obfuscate library use.
|
||||
* **Parallel Threads**: Use several parallel threads to make analysis harder.
|
||||
* **Pipeline Misdirection**: Take advantage of pipelining in modern processors to misdirect debugging, emulation, or static analysis tools. An unpacker can assume a certain number of opcodes will be cached and then proceed to overwrite them in memory, causing a debugger/emulator/analyzer to follow different code than is normally executed.
|
||||
* **Pre-Debug**: Prevents debugger from attaching to process or to break until after the code of interest has been executed
|
||||
* **Relocate API Code**: relocate API code in separate buffer (calls don’t lead to imported DLLs).
|
||||
* **Return Obfuscation**: Overwrite the RET address on the stack or the code at the RET address. Variation seen that writes to the start-up code or main module that called the malware's WinMain or DllMain.
|
||||
* **RtlAdjustPrivilege**: Calling RtlAdjustPrivilege to either prevent a debugger from attaching or to detect if a debugger is attached.
|
||||
* **Section Misalignment**: Some analysis tools cannot handle binaries with misaligned sections.
|
||||
* **Self-Debugging**: Debug itself to prevent another debugger to be attached.
|
||||
* **Self-Unmapping**: UnmapViewOfFile() on itself
|
||||
* **Static Linking**: Copy locally the whole content of API code.
|
||||
* **Stolen API Code**: A variation of "byte stealing" where the first few instructions or bytes of an API are executed in user code, allowing the IAT to point into the middle of an API function. This confuses IAT rebuilders such as ImpRec and Scylla and may bypass breakpoints.
|
||||
* **Tampering**: Erase or corrupt specific file parts to prevent rebuilding (header, packer stub, etc.).
|
||||
* **Thread Timeout**: Setting dwMilliseconds in WaitForSingleObject to a small number will timeout the thread before the analyst can step through and analyze the code executing in the thread. Modifying this via patch, register, or stack to the value `0xFFFFFFFF`, the **INFINITE** constant circumvents this anti-debugging technique.
|
||||
* **Use Interrupts**: The unpacking code relies on use of int 1 or int 3, or it uses the interrupt vector table as part of the decryption "key".
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|--------|-----------------------------|
|
||||
|**Fake Adobe Flash Update OS X**|February 2016|[[2]](#2)|
|
||||
|**Dridex**|March 2015|[[3]](#3)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://anti-reversing.com/Downloads/Anti-Reversing/The_Ultimate_Anti-Reversing_Reference.pdf
|
||||
|
||||
<a name="2">[2]</a> https://www.synack.com/2016/02/17/analyzing-the-anti-analysis-logic-of-an-adware-installer/
|
||||
|
||||
<a name="3">[3]</a> http://phishme.com/dridex-code-breaking-modify-the-malware-to-bypass-the-vm-bypass/
|
||||
|
||||
<a name="4">[4]</a> http://antukh.com/blog/2015/01/19/malware-techniques-cheat-sheet/
|
||||
|
||||
<a name="5">[5]</a> http://unprotect.tdgt.org/index.php/Unprotect_Project
|
||||
|
||||
@@ -1,43 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**M0003**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
Dynamic Analysis Evasion
|
||||
========================
|
||||
Malware may obstruct dynamic analysis in a sandbox, emulator, or virtual machine.
|
||||
|
||||
See [Emulator Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis/emulator-evade.md) for an emulator-specific evasion behavior, and see [Execution Guardrails](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/execution-guardrails.md) for a behavior that constrains dynamic execution based on environmental conditions.
|
||||
|
||||
Methods
|
||||
-------
|
||||
* **Alternative ntdll.dll** A copy of ntdll.dll is dropped to the filesystem and then loaded. This alternative DLL is used to execute function calls to evade sandboxes which use hooking in the operating system's ntdll.dll.
|
||||
* **Data Flood**: Overloads a sandbox by generating a flood of meaningless behavioral data. [[1]](#1)
|
||||
* **Delayed Execution** - Stalling code is typically executed before any malicious behavior. The malware's aim is to delay the execution of the malicious activity long enough so that an automated dynamic analysis system fails to extract the interesting malicious behavior.
|
||||
* **Demo Mode**: Inclusion of a demo binary/mode that is executed when token is absent or not enough privileged.
|
||||
* **Drop Code**: Original file is written to disk then executed. May confuse some sandboxes, especially if the dropped executable must be provided specific arguments and the original dropper is not associated with the drop file(s).
|
||||
* **Encode File**: Encode a file on disk, such as an implant's config file.
|
||||
* **Hook File System**: execution happens when a particular file or directory is accessed, often through hooking certain API calls such as CreateFileA and CreateFileW.
|
||||
* **Hook Interrupt**: modification of interrupt vector or descriptor tables.
|
||||
* **Illusion**: Creates an illusion; makes the analyst think something happened when it didn't.
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|-----------|-----------------------------|
|
||||
|[**Ursnif**](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/ursnif.md)|May 2016|Ursnif uses malware macros to evade sandbox detection. [[2]](#2)|
|
||||
|[**Terminator**](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/terminator.md)|October 2013|The Terminator rat evades a sandbox by not executing until after a reboot. Most sandboxes don't reboot during an analysis. [[3]](#3)|
|
||||
|**Nap**|2013|Trojan Nap (tied to the Kelihos Botnet) uses extended sleep calls to evade sandbox analysis. [[3]](#3)|
|
||||
|**Smokeloader**|2019|Smokeloader drops a copy of ntdll.dll to %APPDATA%\Local\Temp\ [[4]](#4)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> http://joe4security.blogspot.com/2013/06/overloading-sandboxes-new-generic.html
|
||||
|
||||
<a name="2">[2]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/ursnif
|
||||
|
||||
<a name="3">[3]</a> https://www.fireeye.com/content/dam/fireeye-www/current-threats/pdfs/pf/file/fireeye-hot-knives-through-butter.pdf
|
||||
|
||||
<a name="4">[4]</a> https://research.checkpoint.com/2019-resurgence-of-smokeloader/
|
||||
@@ -1,18 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**M0005**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
Emulator Evasion
|
||||
================
|
||||
Behaviors that obstruct analysis in an emulator.
|
||||
|
||||
Methods
|
||||
-------
|
||||
* **Different Opcode Sets**: Use different opcodes sets (ex: FPU, MMX, SSE) to block emulators.
|
||||
* **Undocumented Opcodes**: Use rare or undocumented opcodes to block non-exhaustive emulators.
|
||||
* **Unusual/Undocumented API Calls**: Call unusual APIs to block non-exhaustive emulators (particularly anti-virus).
|
||||
* **Extra Loops/Time Locks**: Add extra loops to make time-constraint emulators give up.
|
||||
|
||||
|
||||
@@ -1,39 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**M0006**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
Memory Dump Evasion
|
||||
===================
|
||||
Malware hinders retrieval and/or discovery of the contents of the physical memory of the system on which the malware instance is executing [[1]](#1).
|
||||
|
||||
Methods
|
||||
-------
|
||||
* **Code Encryption in Memory**: Encrypt the executing malware instance code in memory.
|
||||
* **Erase the PE header**: Erase PE header from memory.
|
||||
* **Hide virtual memory**: Hide arbitrary segments of virtual memory.
|
||||
* **SizeOfImage**: Set the SizeOfImage field of PEB.LoaderData to be huge.
|
||||
* **Tampering**: Erase or corrupt specific file parts to prevent rebuilding (header, packer stub, etc.).
|
||||
* **Guard Pages**: Encrypt blocks of code individually and decrypt temporarily only upon execution.
|
||||
* **On-the-Fly APIs**: Resolve API addresses before each use to prevent complete dumping.
|
||||
* **Feed Misinformation**: API behavior can be altered to prevent memory dumps. For example, inaccurate data can be reported when the contents of the physical memory of the system on which the malware instance is executing is retrieved. See [Hooking](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/hooking.md).
|
||||
* **Flow Opcode Obstruction**: flow opcodes (e.g., jumps, loops) are removed and emulated (or decrypted) by the packer during execution, resulting in incorrect dumps. [[4]](#4)
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|-----------|-----------------------------|
|
||||
|[Kraken](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/kraken.md)| April 2008| Dumping Kraken's c.dll module from the heap of its own process is tricky because its PE-header is erased in memory. [[2]](#2)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> J. Stuttgen, M. Cohen, Anti-forensic resilient memory acquisition, www.dfrws.org/sites/default/files/session-files/paper-anti-forensic_resilient_memory_acquisition.pdf
|
||||
|
||||
<a name="2">[2]</a> http://blog.threatexpert.com/2008/04/kraken-changes-tactics.html
|
||||
|
||||
<a name="3">[3]</a> http://waleedassar.blogspot.com/search/label/anti-dump
|
||||
|
||||
<a name="4">[4]</a> https://www.gironsec.com/code/packers.pdf
|
||||
|
||||
|
||||
@@ -1,32 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**E1480**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis), [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion)|
|
||||
|**Related ATT&CK Technique**|[Execution Guardrails](https://attack.mitre.org/techniques/T1480/)|
|
||||
|
||||
Execution Guardrails
|
||||
====================
|
||||
Malware may use execution guardrails (environmental conditions) to constrain execution. This behavior is related to the [Evade Dynamic Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis/evade-dynamic-analysis.md) behavior that obstructs dynamic analysis in a sandbox, emulator, or virtual machine.
|
||||
|
||||
**See ATT&CK:** [**Execution Guardrails**](https://attack.mitre.org/techniques/T1480/) (which under ATT&CK does not pertain to anti-behavioral analysis behaviors).
|
||||
|
||||
Methods
|
||||
-------
|
||||
* **Deposited Keys**: Parts of the code and/or data is encrypted or otherwise relies on data external to the file itself. For example, malware that contains code that is encrypted with a key that is downloaded from a server; malware that only runs if certain other software is installed on the system. Also see Environmental Keys Method.
|
||||
* **Environmental Keys**: Malware reads certain attributes of the system (BIOS version string, hostname, MAC address, etc.) and encrypts/decrypts portions of its code or data using those attributes as input, thus preventing itself from being run on an unintended system (e.g., sandbox, emulator, etc.). Also see Deposited Keys Method.
|
||||
* **GetVolumeInformation**: This Windows API call is used to get the GUID on a system drive. Malware compares it to a previous (targeted) GUID value and only executes maliciously if they match. This behavior can be mitigated in non-automated analysis environments.
|
||||
* **Host Fingerprint Check**: Compare a previously computed host fingerprint(e.g., based on installed applications) to the current system's to determine if the malware instance is still executing on the same system. If not, execution stops, making debugging or sandbox analysis more difficult.
|
||||
* **Secure Triggers**: Code and/or data is encrypted until the underlying system satisfies a preselected condition unknown to the analyst (this is a form of Deposited Keys).
|
||||
* **Token Check**: Presence check to allow the program to run (ex: dongle, CD/DVD, key, file, network, etc.). If the token is specific to a hardware element (ex: disk, OS, CPU, NIC MAC, etc.), it is considered fingerprinting.
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|-----------|-----------------------------|
|
||||
|
||||
|
||||
References
|
||||
----------
|
||||
|
||||
|
||||
@@ -0,0 +1,94 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0006</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Memory Dump Evasion
|
||||
===================
|
||||
Malware hinders retrieval and/or discovery of the contents of the physical memory of the system on which the malware instance is executing [[1]](#1).
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Code Encryption in Memory**|B0006.001|Encrypt the executing malware instance code in memory.|
|
||||
|**Erase the PE header**|B0006.002|Erase PE header from memory.|
|
||||
|**Feed Misinformation**|B0006.008|API behavior can be altered to prevent memory dumps. For example, inaccurate data can be reported when the contents of the physical memory of the system on which the malware instance is executing is retrieved. See [Hooking](../credential-access/hooking.md).|
|
||||
|**Flow Opcode Obstruction**|B0006.009|Flow opcodes (e.g., jumps, loops) are removed and emulated (or decrypted) by the packer during execution, resulting in incorrect dumps. [[4]](#4).|
|
||||
|**Guard Pages**|B0006.006|Encrypt blocks of code individually and decrypt temporarily only upon execution.|
|
||||
|**Hide virtual memory**|B0006.003|Hide arbitrary segments of virtual memory.|
|
||||
|**On-the-Fly APIs**|B0006.007|Resolve API addresses before each use to prevent complete dumping.|
|
||||
|**SizeOfImage**|B0006.004|Set the SizeOfImage field of PEB.LoaderData to be huge.|
|
||||
|**Tampering**|B0006.005|Erase or corrupt specific file parts to prevent rebuilding (header, packer stub, etc.).|
|
||||
|**Hook memory mapping APIs**|B0006.010|Hooking prevents memory dumps by preventing mapping of memory into the kernel's virtual address space. [[1]](#1)|
|
||||
|**Patch MmGetPhysicalMemoryRanges**|B0006.011|Patching this function to always return NULL prevents drivers from getting information about the physical address space layout, preventing memory dumps. [[1]](#1)|
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[Kraken](../xample-malware/kraken.md)|April 2008|Dumping Kraken's c.dll module from the heap of its own process is tricky because its PE-header is erased in memory. [[2]](#2)|
|
||||
|
||||
Code Snippets
|
||||
-------------
|
||||
**Memory Dump::Code Encryption in Memory** (B0006.011)
|
||||
<br/>MD5: b6e1a2048ea6bd6a941a72300b2d41ce
|
||||
```asm
|
||||
mov cl, 65h ; 'e'
|
||||
mov al, 70h ; 'p'
|
||||
mov [ebp+var_23], cl
|
||||
mov [ebp+var_1F], cl
|
||||
mov [ebp+String], bl
|
||||
mov [ebp+var_12], bl
|
||||
mov [ebp+var_2E], al
|
||||
mov [ebp+var_2D], al
|
||||
lea ecx, [ebp+String]
|
||||
mov al, 74h ; 't'
|
||||
mov bl, 2Eh ; '.'
|
||||
push ecx
|
||||
mov [ebp+var_13], 30h
|
||||
mov [ebp+var_11], 30h
|
||||
mov [ebp+var_10], 0
|
||||
mov [ebp+cp]
|
||||
mov [ebp+var_2F], 75h
|
||||
mov [ebp+var_2C], 6Fh
|
||||
mov [ebp+var_2B], 72h
|
||||
mov [ebp+var_2A], al
|
||||
mov [ebp+var_29], bl
|
||||
mov [ebp+var_28], 62h
|
||||
mov [ebp+var_27], 79h
|
||||
mov [ebp+var_26], 69h
|
||||
mov [ebp+var_25], dl
|
||||
mov [ebp+var_24], al
|
||||
mov [ebp+var_22], 72h
|
||||
mov [ebp+var_21], bl
|
||||
mov [ebp+var_20], dl
|
||||
mov [ebp+var_1E], al
|
||||
mov [ebp+var_1D], 0
|
||||
call ds:atoi
|
||||
add esp, 4
|
||||
mov dword ptr [ebp+hostshort], eax
|
||||
jmp short loc_401326
|
||||
```
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> J. Stuttgen, M. Cohen, Anti-forensic resilient memory acquisition, https://www.dfrws.org/sites/default/files/session-files/paper-anti-forensic_resilient_memory_acquisition.pdf
|
||||
|
||||
<a name="2">[2]</a> http://blog.threatexpert.com/2008/04/kraken-changes-tactics.html
|
||||
|
||||
<a name="3">[3]</a> http://waleedassar.blogspot.com/search/label/anti-dump
|
||||
|
||||
<a name="4">[4]</a> https://www.gironsec.com/code/packers.pdf
|
||||
@@ -0,0 +1,94 @@
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0007</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Virtualization/Sandbox Evasion Checks (<a href="https://attack.mitre.org/techniques/T1497/001/">T1497.001</a>, <a href="https://attack.mitre.org/techniques/T1633/001/">T1633.001</a>), Virtualization/Sandbox Evasion: User Activity Based Checks (<a href="https://attack.mitre.org/techniques/T1497/002/">T1497.002</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
Sandbox Detection
|
||||
=================
|
||||
Detects whether the malware instance is being executed inside an instrumented sandbox environment (e.g., Cuckoo Sandbox). If so, conditional execution selects a benign execution path.
|
||||
|
||||
The related **Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/techniques/T1497/), [T1633](https://attack.mitre.org/techniques/T1633/))** ATT&CK techniques were defined subsequent to this MBC behavior.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Check Clipboard Data**|B0007.001|Checks clipboard data which can be used to detect whether execution is inside a sandbox.|
|
||||
|**Check Files**|B0007.002|Sandboxes create files on the file system. Malware can check the different folders to find sandbox artifacts.|
|
||||
|**Human User Check**|B0007.003|Detects whether there is any "user" activity on the machine, such as the movement of the mouse cursor, non-default wallpaper, or recently opened Office files. Directories or file might be counted. If there is no human activity, the machine is suspected to be a virtualized machine and/or sandbox. Other items used to detect a user: mouse clicks (single/double), DialogBox, scrolling, color of background pixel [[3]](#3). This method is similar to ATT&CK's [Virtualization/Sandbox Evasion: User Activity Based Checks](https://attack.mitre.org/techniques/T1497/002/) sub-technique.|
|
||||
|**Injected DLL Testing**|B0007.004|Testing for the name of a particular DLL that is known to be injected by a sandbox for API hooking is a common way of detecting sandbox environments. This can be achieved through the kernel32!GetModuleHandle API call and other means.|
|
||||
|**Product Key/ID Testing**|B0007.005|Checking for a particular product key/ID associated with a sandbox environment (commonly associated with the Windows host OS used in the environment) can be used to detect whether a malware instance is being executed in a particular sandbox. This can be achieved through several means, including testing for the Key/ID in the Windows registry.|
|
||||
|**Screen Resolution Testing**|B0007.006|Sandboxes aren't used in the same manner as a typical user environment, so most of the time the screen resolution stays at the minimum 800x600 or lower. No one is actually working on a such small screen. Malware could potentially detect the screen resolution to determine if it's a user machine or a sandbox.|
|
||||
|**Self Check**|B0007.007|Malware may check its own characteristics to determine whether it's running in a sandbox. For example, a malicious Office document might check its file name or VB project name.|
|
||||
|**Timing/Date Check**|B0007.008|Calling GetSystemTime or equiv and only executing code if the current date/hour/minute/second passes some check. Often this is for running only after or only until a specific date. This behavior can be mitigated in non-automated analysis environments.|
|
||||
|**Timing/Uptime Check**|B0007.009|Comparing single GetTickCount with some value to see if system has been started at least *X* amount ago. This behavior can be mitigated in non-automated analysis environments.|
|
||||
|**Test API Routines**|B0007.010|Calls Windows API routines with invalid arguments to identify error supression.|
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Redhip**](../xample-malware/redhip.md)|January 2011|Redhip detects publicly available automated analysis workbenches (e.g., Joe Box) by considering OS product keys and special DLLs. [[1]](#1)|
|
||||
|[**Rombertik**](../xample-malware/rombertik.md)|May 2015|[[2]](#2)|
|
||||
|[**Terminator**](../xample-malware/terminator.md)|May 2013|The Terminator rat evades a sandbox by not executing until after a reboot. Most sandboxes don't reboot during an analysis. [[4]](#4)|
|
||||
|[**Ursnif**](../xample-malware/ursnif.md)|2016|Ursnif uses malware macros to evade sandbox detection.|
|
||||
|[**GotBotKR**](../xample-malware/gotbotkr.md)|2019|GoBotKR performs several checks on the compromised machine to avoid being emulated or executed in a sandbox. [[5]](#5)|
|
||||
|[**Rombertik**](../xample-malware/rombertik.md)|2015|The malware check for sandboxes that suppress errors returned from API routine calls the using ZwGetWriteWatch routine. [[6]](#6)|
|
||||
|
||||
|
||||
<a name="snippet"><a/>Code Snippets
|
||||
-------------
|
||||
**Sandbox Detection::Product Key/ID Testing** (B0007.005) - the value 55274-640-2673064-23950 corresponds to Joe Sandbox.
|
||||
```asm
|
||||
push ebx
|
||||
add esp, 0FFFFFEF4h
|
||||
xor ebx, ebx
|
||||
push esp ; phkResult
|
||||
push 1 ; samDesired
|
||||
push 0 ; ulOptions
|
||||
push offset SubKey ; "Software\Microsoft\Windows\CurrentVersi"...
|
||||
push 80000002h ; hKey
|
||||
call RegOpenKeyExA
|
||||
test eax, eax
|
||||
jnz short loc_405387
|
||||
mov [esp+110h+cbData], 101h
|
||||
lea eax, [esp+110h+cbData]
|
||||
push eax ; lpcbData
|
||||
lea eax, [esp+114h+Data]
|
||||
push eax ; lpData
|
||||
push 0 ; lpType
|
||||
push 0 ; lpReserved
|
||||
push offset ValueName ; "ProductId"
|
||||
mov eax, [esp+124h+hKey]
|
||||
push eax ; hKey
|
||||
call RegQueryValueExA
|
||||
lea eax, [esp+110h+Data]
|
||||
cmp eax, offset a55274640267306 ; "55274-640-2673064-23950"
|
||||
jnz short loc_405387
|
||||
mov bl, 1
|
||||
```
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
|
||||
|
||||
<a name="2">[2]</a> https://blogs.cisco.com/security/talos/rombertik
|
||||
|
||||
<a name="3">[3]</a> https://github.com/LordNoteworthy/al-khaser
|
||||
|
||||
<a name="4">[4]</a> https://www.fireeye.com/content/dam/fireeye-www/current-threats/pdfs/pf/file/fireeye-hot-knives-through-butter.pdf
|
||||
|
||||
<a name="5">[5]</a> https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/
|
||||
|
||||
<a name="6">[6]</a> https://blogs.cisco.com/security/talos/rombertik
|
||||
@@ -0,0 +1,130 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0009</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Virtualization/Sandbox Evasion (<a href="https://attack.mitre.org/techniques/T1497/">T1497</a>, <a href="https://attack.mitre.org/techniques/T1633/">T1633</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Virtual Machine Detection
|
||||
=========================
|
||||
Detects whether the malware instance is being executed in a virtual machine (VM), such as VMWare. If so, conditional execution selects a benign execution path. [[1]](#1)
|
||||
|
||||
The related **Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/techniques/T1497/), [T1633](https://attack.mitre.org/techniques/T1633/))** ATT&CK techniques were defined subsequent to this MBC behavior.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Check File and Directory Artifacts**|B0009.001|Virtual machines create files on the file system (e.g., VMware creates files in the installation directory C:\Program Files\VMware\VMware Tools). Malware can check the different folders to find virtual machine artifacts (e.g., Virtualbox has the artifact VBoxMouse.sys). [[2]](#2)|
|
||||
|**Check Memory Artifacts**|B0009.002|VMware leaves many artifacts in memory. Some are critical processor structures, which, because they are either moved or changed on a virtual machine, leave recognizable footprints. Malware can search through physical memory for the strings VMware, commonly used to detect memory artifacts. [[2]](#2)|
|
||||
|**Check Named System Objects**|B0009.003|Virtual machines often include specific named system objects by default, such as Windows device drivers, which can be detected by testing for specific strings, whether found in the Windows registry or other places.|
|
||||
|**Check Processes**|B0009.004|The VMware Tools use processes like VMwareServices.exe or VMwareTray.exe, to perform actions on the virtual environment. Malware can list the process and searches for the VMware string. Process related to Virtualbox can be detected by malware by query the process list. [[2]](#2)|
|
||||
|**Check Registry Keys**|B0009.005|Virtual machines register artifacts in the registry, which can be detected by malware. For example, a search for "VMware" or "VBOX" in the registry might reveal keys that include information about a virtual hard drive, adapters, running services, or virtual mouse. [[2]](#2) Example registry key value artifacts include "HARDWARE\Description\System (SystemBiosVersion) (VBOX)" and "SYSTEM\ControlSet001\Control\SystemInformation (SystemManufacturer) (VMWARE)"; example registry key artifacts include "SOFTWARE\VMware, Inc.\VMware Tools (VMWARE)" and "SOFTWARE\Oracle\VirtualBox Guest Additions (VBOX)". [[5]](#5)|
|
||||
|**Check Running Services**|B0009.006|VMwareService.exe runs the VMware Tools Service as a child of services.exe. It can be identified by listing services. [[2]](#2)|
|
||||
|**Check Software**|B0009.007|Malware may check software version; for example, to determine whether the software is relatively current.|
|
||||
|**Check Virtual Devices**|B0009.008|The presence of virtual devices can indicate a virtualized environment (e.g., "\\.\VBoxTrayIPC"). [[5]](#5)|
|
||||
|**Check Windows**|B0009.009|Malware may check windows for VM-related characteristics.|
|
||||
|**Check Windows - Title bars**|B0009.022|Malware may check windows for VM-related characteristics. May inject malicious code to svchost.exe to check all open window title bar text to a list of strings indicating virtualized environment.|
|
||||
|**Check Windows - Unique windows**|B0009.021|Malware may check windows for VM-related characteristics. May check for the presence of known windows from analysis tools running in a VM.|
|
||||
|**Check Windows - Window size**|B0009.020|Malware may check windows for VM-related characteristics. Tiny window size may indicate a VM.|
|
||||
|**Guest Process Testing**|B0009.010|Virtual machines offer guest additions that can be installed to add functionality such as clipboard sharing. Detecting the process responsible for these tasks, via its name or other methods, is a technique employed by malware for detecting whether it is being executed in a virtual machine.|
|
||||
|**HTML5 Performance Object Check**|B0009.011|In three browser families, it is possible to extract the frequency of the Windows performance counter frequency, using standard HTML and Javascript. This value can then be used to detect whether the code is being executed in a virtual machine, by detecting two specific frequencies commonly used in virtual but not physical machines.|
|
||||
|**Human User Check**|B0009.012|Detects whether there is any "user" activity on the machine, such as the movement of the mouse cursor, non-default wallpaper, or recently opened Office files. Directories or file might be counted. If there is no human activity, the machine is suspected to be a virtualized machine and/or sandbox. Other items used to detect a user: mouse clicks (single/double), DialogBox, scrolling, color of background pixel, change in foreground window [[5]](#5). This method is very similar to ATT&CK's [Virtualization/Sandbox Evasion: User Activity Based Checks](https://attack.mitre.org/techniques/T1497/002/) sub-technique.|
|
||||
|**Instruction Testing**|B0009.029|The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2)|
|
||||
|**Instruction Testing - CPUID**|B0009.034|The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2) Checking the CPU ID found within the registry can provide information to system type.|
|
||||
|**Instruction Testing - IN**|B0009.035|The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2)|
|
||||
|**Instruction Testing - RDTSC**|B0009.036|The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2)|
|
||||
|**Instruction Testing - SGDT/SLDT (no pill)**|B0009.031|The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2) The No Pill technique relies on the fact that the LDT structure is assigned to a processor not an Operating System. The LDT location on a host machine will be zero and on a virtual machine will be non-zero.|
|
||||
|**Instruction Testing - SIDT (red pill)**|B0009.030|The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2) Red Pill is an anti-VM technique that executes the SIDT instruction to grab the value of the IDTR register. The virtual machine monitor must relocate the guest's IDTR to avoid conflict with the host's IDTR. Since the virtual machine monitor is not notified when the virtual machine runs the SIDT instruction, the IDTR for the virtual machine is returned.|
|
||||
|**Instruction Testing - SMSW**|B0009.032|The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2)|
|
||||
|**Instruction Testing - STR**|B0009.033|The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2)|
|
||||
|**Instruction Testing - VMCPUID**|B0009.037|The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2)|
|
||||
|**Instruction Testing - VPCEXT**|B0009.038|The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2)|
|
||||
|**Modern Specs Check**|B0009.013|Different aspects of the hardware are inspected to determine whether the machine has modern characteristics. A machine with substandard specifications indicates a virtual environment.|
|
||||
|**Modern Specs Check - Drive size**|B0009.015|Different aspects of the hardware are inspected to determine whether the machine has modern characteristics. A machine with substandard specifications indicates a virtual environment. Most modern machines have at least 80 GB disks. May use DeviceloControl (IOCTL_DISK_GET_LENGTH_INFO) or GetDiskFreeSpaceEx (TotalNumberOfBytes) [[5]](#5).|
|
||||
|**Modern Specs Check - Keyboard layout**|B0009.019|Different aspects of the hardware are inspected to determine whether the machine has modern characteristics. A machine with substandard specifications indicates a virtual environment. Check keyboard layout.|
|
||||
|**Modern Specs Check - Printer**|B0009.017|Different aspects of the hardware are inspected to determine whether the machine has modern characteristics. A machine with substandard specifications indicates a virtual environment. Checks whether there is a potential connected printer or default Windows printers; if not a virtual environment is suspected.|
|
||||
|**Modern Specs Check - Processor count**|B0009.018|Different aspects of the hardware are inspected to determine whether the machine has modern characteristics. A machine with substandard specifications indicates a virtual environment. Checks number of processors; single CPU machines are suspect.|
|
||||
|**Modern Specs Check - Total physical memory**|B0009.014|Different aspects of the hardware are inspected to determine whether the machine has modern characteristics. A machine with substandard specifications indicates a virtual environment. Most modern machines have at leave 4 GB of memory. (GlobalMemoryStatusEx) [[5]](#5).|
|
||||
|**Modern Specs Check - USB drive**|B0009.016|Different aspects of the hardware are inspected to determine whether the machine has modern characteristics. A machine with substandard specifications indicates a virtual environment. Checks whether there is a potential USB drive; if not a virtual environment is suspected.|
|
||||
|**Unique Hardware/Firmware Check**|B0009.023|Malware may check for hardware characteristics unique to being virtualized, allowing the malware to detect the virtual environment.|
|
||||
|**Unique Hardware/Firmware Check - BIOS**|B0009.024|Malware may check for hardware characteristics unique to being virtualized, allowing the malware to detect the virtual environment. Characteristics of the BIOS, such as version, can indicate virtualization.|
|
||||
|**Unique Hardware/Firmware Check - CPU Location**|B0009.027|Malware may check for hardware characteristics unique to being virtualized, allowing the malware to detect the virtual environment. When an Operating System is virtualized, the CPU is relocated. [[2]](#2)|
|
||||
|**Unique Hardware/Firmware Check - CPU Name**|B0009.026|Malware may check for hardware characteristics unique to being virtualized, allowing the malware to detect the virtual environment. Checks the CPU name to determine virtualization.|
|
||||
|**Unique Hardware/Firmware Check - I/O Communication Port**|B0009.025|Malware may check for hardware characteristics unique to being virtualized, allowing the malware to detect the virtual environment. VMware uses virtual I/O ports for communication between the virtual machine and the host operating system to support functionality like copy and paste between the two systems. The port can be queried and compared with a magic number VMXh to identify the use of VMware.|
|
||||
|**Unique Hardware/Firmware Check - MAC Address**|B0009.028|Malware may check for hardware characteristics unique to being virtualized, allowing the malware to detect the virtual environment. VMware uses specific virtual MAC address that can be detected. The usual MAC address used started with the following numbers: "00:0C:29", "00:1C:14", "00:50:56", "00:05:69". Virtualbox uses specific virtual MAC address that can be detected by Malware. The usual MAC address used started with the following numbers: 08:00:27. [[2]](#2)|
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**GravityRAT**](../xample-malware/gravity-rat.md)|May 2018|GravityRAT checks system temperature by recording thermal readings for detecting VMs. Heat levels indicate whether the system is a VM. [[3]](#3)|
|
||||
|[**WebCobra**](../xample-malware/webcobra.md)|2018|WebCobra injects malicious code to svchost.exe and uses an infinite loop to check all open windows and to compare each window’s title bar text with a set of strings to determine whether it is running in an isolated, malware analysis environment [[4]](#4)|
|
||||
|[**Redhip**](../xample-malware/redhip.md)|2011|Redhip detects VMWare, Virtual PC and Virtual Box. It also detects VM environments in general by considering timing lapses. [[6]](#6)|
|
||||
|[**Emotet**](../xample-malware/emotet.md)|2018|Emotet checks for various processes that are associated with various virtual machines by comparing hash values of the process names with the hash values of the list of running process names [[7]](#7)|
|
||||
|
||||
|
||||
|
||||
Code Snippets
|
||||
-------------
|
||||
**Virtual Machine Detection::Instruction Testing** (B0009.029)
|
||||
<br/>MD5: 0e058126f26b54b3a4a950313ec5dbce
|
||||
```asm
|
||||
; ___unwind { // __except handler4
|
||||
push ebp
|
||||
mov ebp, esp
|
||||
push 0FFFFFFFEh
|
||||
push offset stru_413980
|
||||
push offset __except handler4
|
||||
mov eax, large fs:0
|
||||
push eax
|
||||
sub esp, 14h
|
||||
push ebx
|
||||
push esi
|
||||
push edi
|
||||
mov eax, ___security_cookie
|
||||
xor [epb+ms_exc.registration.ScopeTable], eax
|
||||
xor eax, ebp
|
||||
push eax
|
||||
lea eax, [ebp+ms_exc.registration]
|
||||
mov large fs:0 eax
|
||||
mov [ebp+var_19], al
|
||||
; __try { // __except at loc_401CB8
|
||||
mov [ebp+ms_exc.registration.TryLevel], eax
|
||||
push ebx
|
||||
mov ebx, 0
|
||||
mov eax, 1
|
||||
vpcext 7, 08h
|
||||
test ebx, ebx
|
||||
setz [ebp+var_19]
|
||||
pop ebx
|
||||
jmp short loc_401CBB
|
||||
```
|
||||
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
|
||||
|
||||
<a name="2">[2]</a> https://search.unprotect.it/map/sandbox-evasion/
|
||||
|
||||
<a name="3">[3]</a> https://www.hackread.com/gravityrat-malware-evades-detection-targets-india/
|
||||
|
||||
<a name="4">[4]</a> https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/webcobra-malware-uses-victims-computers-to-mine-cryptocurrency/
|
||||
|
||||
<a name="5">[5]</a> https://github.com/LordNoteworthy/al-khaser
|
||||
|
||||
<a name="6">[6]</a> https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
|
||||
|
||||
<a name="7">[7]</a> https://securelist.com/the-banking-trojan-emotet-detailed-analysis/69560/
|
||||
@@ -1,23 +1,25 @@
|
||||
|||
|
||||
|--|-----|
|
||||
|**ID**|**M9002**|
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>OB0002</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
# Anti-Static Analysis
|
||||
Behaviors and code characteristics that prevent static analysis or make it more difficult. Simple static analysis identifies features such as embedded strings, header information, hash values, and file metadata (e.g., creation date). More involved static analysis involves the disassembly of the binary code.
|
||||
|
||||
Two primary resources for anti-static analysis behaviors are [[1]](#1) and [[2]](#2).
|
||||
|
||||
* **Call Graph Generation Evasion** [M0010](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/evade-call-graph.md)
|
||||
* **Disassembler Evasion** [M0012](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/evade-disassembler.md)
|
||||
* **Executable Code Obfuscation** [M0032](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/exe-code-obfuscate.md)
|
||||
* **Executable Code Optimization** [M0034](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/exe-code-optimize.md)
|
||||
* **Executable Code Virtualization** [M0008](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/exe-code-virtualize.md)
|
||||
* **Obfuscated Files or Information** [E1027](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/obfuscate-files.md)
|
||||
* **Software Packing** [E1045](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/software-packing.md)
|
||||
Behaviors and code characteristics that prevent or hinder static analysis of the malware. Simple static analysis identifies features such as embedded strings, header information, or file metadata. More involved static analysis involves the disassembly of the binary code.
|
||||
|
||||
* **Call Graph Generation Evasion** [B0010](../anti-static-analysis/call-graph-generation-evasion.md)
|
||||
* **Disassembler Evasion** [B0012](../anti-static-analysis/disassembler-evasion.md)
|
||||
* **Data Flow Analysis Evasion** [B0045](../anti-static-analysis/data-flow-analysis-evasion.md)
|
||||
* **Executable Code Obfuscation** [B0032](../anti-static-analysis/executable-code-obfuscation.md)
|
||||
* **Executable Code Optimization** [B0034](../anti-static-analysis/executable-code-optimization.md)
|
||||
* **Executable Code Virtualization** [B0008](../anti-static-analysis/executable-code-virtualization.md)
|
||||
* **Obfuscated Files or Information** [E1027](../defense-evasion/obfuscated-files-or-information.md)
|
||||
* **Software Packing** [F0001](../anti-static-analysis/software-packing.md)
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> Unprotect Project, a database about malware self-defense and protection. http://unprotect.tdgt.org/index.php/Unprotect_Project
|
||||
<a name="1">[1]</a> Unprotect Project, a database about malware self-defense and protection. https://search.unprotect.it/map/sandbox-evasion/
|
||||
|
||||
<a name="2">[2]</a> InDepthUnpacking, course content for teaching malware anti-analysis techniques and mitigations, with emphasis on packers. https://github.com/knowmalware/InDepthUnpacking
|
||||
<a name="2">[2]</a> InDepthUnpacking, course content for teaching malware anti-analysis techniques and mitigations, with emphasis on packers. https://github.com/knowmalware/InDepthUnpacking
|
||||
|
||||
+20
-13
@@ -1,8 +1,18 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**M0010**|
|
||||
|**Objective(s)**| [Anti-Static Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-static-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0010</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-static-analysis">Anti-Static Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Call Graph Generation Evasion
|
||||
@@ -11,13 +21,10 @@ Malware code evades accurate call graph generation during disassembly. Call grap
|
||||
|
||||
Methods
|
||||
-------
|
||||
* **Two-layer Function Return**: two layer jumping confuses tools plotting call graphs. [[3]](#3)
|
||||
* **Invoke NTDLL System Calls via Encoded Table**: invokes ntdll.dll functions without using an export table; an encoded translation table on the stack is used instead. [[3]](#3)
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|--------|-----------------------------|
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Invoke NTDLL System Calls via Encoded Table**|B0010.002|Invokes ntdll.dll functions without using an export table; an encoded translation table on the stack is used instead. [[3]](#3)|
|
||||
|**Two-layer Function Return**|B0010.001|Two layer jumping confuses tools plotting call graphs. [[3]](#3)|
|
||||
|
||||
References
|
||||
----------
|
||||
@@ -27,4 +34,4 @@ References
|
||||
|
||||
<a name="3">[3]</a> http://fumalwareanalysis.blogspot.com/2012/01/malware-analysis-tutorial-10-tricks-for.html
|
||||
|
||||
<a name="4">[4]</a> S. Shang, N. Zheng, J. Xu, M. Xu, H. Zhang, "Detecting Malware Variants via Function-call Graph Similarity," IEEE 2010 5th International Conference on Malicious and Unwanted Software, 2010. http://seclab.hdu.edu.cn/static/uploads/paper/10-05.pdf
|
||||
<a name="4">[4]</a> S. Shang, N. Zheng, J. Xu, M. Xu, H. Zhang, "Detecting Malware Variants via Function-call Graph Similarity," IEEE 2010 5th International Conference on Malicious and Unwanted Software, 2010. http://seclab.hdu.edu.cn/static/uploads/paper/10-05.pdf
|
||||
@@ -0,0 +1,32 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0045</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-static-analysis">Anti-Static Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Data Flow Analysis Evasion
|
||||
==========================
|
||||
Malware code evades data flow analysis (also known as information flow analysis and taint-tracking).
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Control Dependence**|B0045.001|Data is propagated via an if-then-else clause instead of direct assignment.[[1]](#1)|
|
||||
|**Implicit Flows**|B0045.002|Data is propagated via semantic relationships, for example one variable not changing its state could imply the state of another variable.[[1]](#1)|
|
||||
|**Arbitrary Memory Corruption**|B0045.003|Data is propagated by corrupting memory, for example overwriting a region of stack space where a file pointer is held.[[1]](#1)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> http://www.seclab.cs.sunysb.edu/seclab/pubs/antitaint.pdf
|
||||
@@ -0,0 +1,40 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0012</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-static-analysis">Anti-Static Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Disassembler Evasion
|
||||
====================
|
||||
Malware code evades disassembly in a recursive or linear disassembler. Some methods apply to both types of disassemblers; others apply to one type and not the other.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Argument Obfuscation**|B0012.001|Simple number or string arguments to API calls are calculated at runtime, making linear disassembly more difficult.|
|
||||
|**Conditional Misdirection**|B0012.002|Conditional jumps are sometimes used to confuse disassembly engines, resulting in the wrong instruction boundaries and thus wrong mnemonic and operands; identified by instructions *jmp/jcc to a label+#* (e.g., JNE loc_401345fe+2).|
|
||||
|**VBA Stomping**|B0012.005|Typically, VBA source code is compiled into p-code, which is stored with compressed sourced code in the OLE file with VBA macros. VBA Stomping - when the VBA source code is removed and only the p-code remains - makes analysis much harder. See [[3]](#3) for an analysis of a VBA-Stomped malicious VBA Office document. See [[4]](#4) for information on Evil Clippy, a tool that creates malicious MS Office documents.|
|
||||
|**Value Dependent Jumps**|B0012.003|Explicit use of computed values for control flow, often many times in the same basic block or function.|
|
||||
|**Variable Recomposition**|B0012.004|Variables, often strings, are broken into multiple parts and store out of order, in different memory ranges, or both. They must then be recomposed before use.|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> http://staff.ustc.edu.cn/~bjhua/courses/security/2014/readings/anti-disas.pdf
|
||||
|
||||
<a name="2">[2]</a> http://www.kernelhacking.com/rodrigo/docs/blackhat2012-paper.pdf
|
||||
|
||||
<a name="3">[3]</a> https://isc.sans.edu/diary/Malicious+VBA+Office+Document+Without+Source+Code/24870
|
||||
|
||||
<a name="4">[4]</a> https://boingboing.net/2019/05/05/p-code-r-us.html
|
||||
@@ -1,33 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**M0012**|
|
||||
|**Objective(s)**| [Anti-Static Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-static-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
|
||||
Disassembler Evasion
|
||||
====================
|
||||
Malware code evades disassembly in a recursive or linear disassembler. Some methods apply to both types of disassemblers; others apply to one type and not the other.
|
||||
|
||||
Methods
|
||||
-------
|
||||
* **Argument Obfuscation**: Simple number or string arguments to API calls are calculated at runtime, making linear disassembly more difficult.
|
||||
* **Conditional Misdirection**: Conditional jumps are sometimes used to confuse disassembly engines, resulting in the wrong instruction boundaries and thus wrong mnemonic and operands; identified by instructions *jmp/jcc to a label+#* (e.g., JNE loc_401345fe+2).
|
||||
* **Value Dependent Jumps**: Explicit use of computed values for control flow, often many times in the same basic block or function.
|
||||
* **Variable Recomposition**: Variables, often strings, are broken into multiple parts and store out of order, in different memory ranges, or both. They must then be recomposed before use.
|
||||
* **VBA Stomping**: Typically, VBA source code is compiled into p-code, which is stored with compressed sourced code in the OLE file with VBA macros. VBA Stomping - when the VBA source code is removed and only the p-code remains - makes analysis much harder. See [[3]](#3) for an analysis of a VBA-Stomped malicious VBA Office document. See [[4]](#4) for information on Evil Clippy, a tool that creates malicious MS Office documents.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|--------|-----------------------------|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> http://staff.ustc.edu.cn/~bjhua/courses/security/2014/readings/anti-disas.pdf
|
||||
|
||||
<a name="2">[2]</a> http://www.kernelhacking.com/rodrigo/docs/blackhat2012-paper.pdf
|
||||
|
||||
<a name="3">[3]</a> https://isc.sans.edu/diary/Malicious+VBA+Office+Document+Without+Source+Code/24870
|
||||
|
||||
<a name="4">[4]</a> https://boingboing.net/2019/05/05/p-code-r-us.html
|
||||
@@ -1,49 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**M0032**|
|
||||
|**Objective(s)**| [Anti-Static Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-static-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
|
||||
Executable Code Obfuscation
|
||||
===========================
|
||||
Executable code can be obfuscated to hinder disassembly and static code analysis. This behavior is specific to a malware sample's executable code (data and text sections).
|
||||
|
||||
For encryption and encoding characteristics of malware samples, as well as malware obfuscation behaviors related to non-malware-sample files and information, see [**Obfuscated Files or Information**](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/obfuscate-files.md).
|
||||
|
||||
Methods
|
||||
-------
|
||||
* **API Hashing**: Instead of storing function names in the Import Address Table (IAT) and calling GetProcAddress, a DLL is loaded and the name of each of its exports is hashed until it matches a specific hash. Manual symbol resolution is then used to access and execute the exported function. This method is often used by shellcode because it reduces the size of each import from a human-readable string to a sequence of four bytes. The Method is also known as "Imports by Hash" and "GET_APIS_WITH_CRC." [[1]](#1)
|
||||
* **Code Insertion**: Insert code to impede disassembly.
|
||||
* *Dead Code Insertion*: Include "dead" code with no real functionality.
|
||||
* *Fake Code Insertion*: Add fake code similar to known packers or known goods to fool identification. Can confuse some automated unpackers.
|
||||
* *Jump Insertion*: Insert jumps to make analysis visually harder.
|
||||
* *Thunk Code Insertion*: Variation on Jump Insertion. Used by some compilers for user-generated functions.
|
||||
* *Junk Code Insertion*: Insert dummy code between relevant opcodes. Can make signature writing more complex.
|
||||
* **Data Value Obfuscation**: Obfuscate data values through indirection of local or global variables. For example, the instruction *if (a == 0) do x* can be obfuscated by setting a global variable, *Z*, to zero and using it in the instruction: *if (a==Z) do x*. [NEEDS REVIEW]
|
||||
* **Entry Point Obfuscation**: Obfuscate the entry point of the malware executable.
|
||||
* **Guard Pages**: Encrypt blocks of code individually and decrypt temporarily only upon execution.
|
||||
* **Import Address Table Obfuscation**: Obfuscate the import address table.
|
||||
* **Import Compression**: Store and load imports with a compact import table format. Each DLL needed by the executable is mentioned in the IAT, but only one function from each/most is imported; the rest are imported via GetProcAddress calls.
|
||||
* **Instruction Overlap**: Jump after the first byte of an instruction to confuse disassembler.
|
||||
* **Interleaving Code**: Split code into sections that may be rearranged and are connected by unconditional jumps.
|
||||
* **Merged Code Sections**: Merge all sections resulting in just one entry in the sections table to make readability more difficult. May affect some detection signatures if written to be section dependent.
|
||||
* **Structured Exception Handling (SEH)**: A portion of the code always generates an exception so that malicious code is executed with the exception handling. See [[3]](#3).
|
||||
* **Stack Strings**: Build and decrypt strings on the stack at each use, then discard to avoid obvious references.
|
||||
* **Symbol Obfuscation**: Remove or rename symbolic information commonly inserted by compilers for debugging purposes.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------------------------|--------|-----------------------------|
|
||||
|[**Heriplor Trojan**](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/heriplor.md)|March 2019|The Heriplor Trojan uses API Hashing. [[1]](#1)|
|
||||
|**Geodo**|August 2018|Geodo macros are heavily obfuscated with junk functions and string substitutions. [[2]](#2)|
|
||||
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://insights.sei.cmu.edu/cert/2019/03/api-hashing-tool-imagine-that.html
|
||||
|
||||
<a name="2">[2]</a> https://cofense.com/recent-geodo-malware-campaigns-feature-heavily-obfuscated-macros/
|
||||
|
||||
<a name="3">[3]</a> Rob Simmons, "Comparing Malicious Files," BSides, 2019. http://www.irongeek.com/i.php?page=videos/bsidescharm2019/2-04-comparing-malicious-files-robert-simmons
|
||||
@@ -1,24 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**M0034**|
|
||||
|**Objective(s)**| [Anti-Static Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-static-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
|
||||
Executable Code Optimization
|
||||
============================
|
||||
Code is optimized, making it harder to statically analyze.
|
||||
|
||||
Methods
|
||||
-------
|
||||
* **Jump/Call Absolute Address**: Relative operands of jumps and calls into are made absolute (better compression). May confuse some basic block detection algorithms.
|
||||
* **Minification**: Minification is 'the process of removing all unnecessary characters from source code without changing its functionality.' [[1]](#1) A simple example is when all the unnecessary whitespace and comments are removed. Minification is distinguished from compression in that it neither adds to nor changes the code seen by the interpreter. Minification is often used for malware written in interpreted languages, such as JavaScript, PHP, or Python. Legitimate code that is transmitted many times a second, such as JavaScript on websites, often uses minification to simply reduce the number of bytes transmitted.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|--------|-----------------------------|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://en.wikipedia.org/wiki/Minification_(programming)
|
||||
@@ -1,28 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**M0008**|
|
||||
|**Objective(s)**| [Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis), [Anti-Static Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-static-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
|
||||
Executable Code Virtualization
|
||||
==============================
|
||||
Original executable code is virtualized by translating the code into a special format that only a special virtual machine (VM) can run; the VM uses a customized virtual instruction set. A "stub" function calls the VM when the code is run. Virtualized code makes static analysis and reverse engineering more difficult; dumped code won’t run without the VM.
|
||||
|
||||
Virtualized code is a software protection technique. Themida is a commercial tool; WPProtect is an open source tool. [[1]](#1)
|
||||
|
||||
Methods
|
||||
-------
|
||||
* **Multiple VMs**: multiple virtual machines with different architectures (CISC, RISC, etc.) can be used inside of a single executable in order to make reverse engineering even more difficult.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|--------|-----------------------------|
|
||||
|[**Locky Bart**](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/locky-bart.md)|January 2017|Code virtualization is added to the Locky Bart binary using WPProtect. [[2]](#2)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://github.com/xiaoweime/WProtect
|
||||
|
||||
<a name="2">[2]</a> https://blog.malwarebytes.com/threat-analysis/2017/01/locky-bart-ransomware-and-backend-server-analysis/
|
||||
@@ -0,0 +1,132 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0032</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-static-analysis">Anti-Static Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Executable Code Obfuscation
|
||||
===========================
|
||||
Executable code can be obfuscated to hinder disassembly and static code analysis. This behavior is specific to a malware sample's executable code (data and text sections).
|
||||
|
||||
For encryption and encoding characteristics of malware samples, as well as malware obfuscation behaviors related to non-malware-sample files and information, see **Obfuscated Files or Information ([E1027](../defense-evasion/obfuscated-files-or-information.md))**.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**API Hashing**|B0032.001|Instead of storing function names in the Import Address Table (IAT) and calling GetProcAddress, a DLL is loaded and the name of each of its exports is hashed until it matches a specific hash. Manual symbol resolution is then used to access and execute the exported function. This method is often used by shellcode because it reduces the size of each import from a human-readable string to a sequence of four bytes. The Method is also known as "Imports by Hash" and "GET_APIS_WITH_CRC." [[1]](#1)|
|
||||
|**Code Insertion**|B0032.002|Insert code to impede disassembly.|
|
||||
|**Data Value Obfuscation**|B0032.008|Obfuscate data values through indirection of local or global variables. For example, the instruction *if (a == 0) do x* can be obfuscated by setting a global variable, *Z*, to zero and using it in the instruction: *if (a==Z) do x*. [NEEDS REVIEW]|
|
||||
|**Dead Code Insertion**|B0032.003|Include "dead" code with no real functionality.|
|
||||
|**Entry Point Obfuscation**|B0032.009|Obfuscate the entry point of the malware executable.|
|
||||
|**Fake Code Insertion**|B0032.004|Add fake code similar to known packers or known goods to fool identification. Can confuse some automated unpackers.|
|
||||
|**Guard Pages**|B0032.010|Encrypt blocks of code individually and decrypt temporarily only upon execution.|
|
||||
|**Import Address Table Obfuscation**|B0032.011|Obfuscate the import address table.|
|
||||
|**Import Compression**|B0032.012|Store and load imports with a compact import table format. Each DLL needed by the executable is mentioned in the IAT, but only one function from each/most is imported; the rest are imported via GetProcAddress calls.|
|
||||
|**Instruction Overlap**|B0032.013|Jump after the first byte of an instruction to confuse disassembler.|
|
||||
|**Interleaving Code**|B0032.014|Split code into sections that may be rearranged and are connected by unconditional jumps.|
|
||||
|**Jump Insertion**|B0032.005|Insert jumps to make analysis visually harder.|
|
||||
|**Junk Code Insertion**|B0032.007|Insert dummy code between relevant opcodes. Can make signature writing more complex.|
|
||||
|**Merged Code Sections**|B0032.015|Merge all sections resulting in just one entry in the sections table to make readability more difficult. May affect some detection signatures if written to be section dependent.|
|
||||
|**Stack Strings**|B0032.017|Build and decrypt strings on the stack at each use, then discard to avoid obvious references.|
|
||||
|**Structured Exception Handling (SEH)**|B0032.016|A portion of the code always generates an exception so that malicious code is executed with the exception handling. See [[3]](#3).|
|
||||
|**Symbol Obfuscation**|B0032.018|Remove or rename symbolic information commonly inserted by compilers for debugging purposes.|
|
||||
|**Thunk Code Insertion**|B0032.006|Variation on Jump Insertion. Used by some compilers for user-generated functions.|
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Heriplor**](../xample-malware/heriplor.md)|March 2019|The Heriplor Trojan uses API Hashing. [[1]](#1)|
|
||||
|[**Emotet**](../xample-malware/emotet.md)|2018|Emotet macros are heavily obfuscated with junk functions and string substitutions. [[2]](#2)|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
|[**Rombertik**](../anti-static-analysis/executable-code-obfuscation.md)|2015|Most of the malware file consists of unnecessary code or unnecessary data [[4]](#4)|
|
||||
|[**Ursnif**](../anti-static-analysis/executable-code-obfuscation.md)|2016|Creates an encrypted Registry key called TorClient to store its data [[5]](#5)|
|
||||
|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|Poison Ivy variant encrypts all its strings [[6]](#6)|
|
||||
|[**SamSam**](../xample-malware/samsam.md)|2015|SamSam obfuscates functions, class names and strings, including the list of targeted file extensions, the help file contents and environment variables using DES encryption with a fixed hard-coded key and the IV [[7]](#7)|
|
||||
|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|The configuration data block is encoded with a NOT XOR 0xFF operation [[8]](#8)|
|
||||
|
||||
|
||||
Code Snippets
|
||||
-------------
|
||||
**Obfuscated Files or Information::Encoding-Standard Algorithm** (E1027.m02)
|
||||
<br/>MD5: b6e1a2048ea6bd6a941a72300b2d41ce
|
||||
```asm
|
||||
jle short_40182F
|
||||
mov dl, byte ptr [ebp+eax+var_7CA8]
|
||||
xor dl, cl
|
||||
mov byte ptr [ebp+eax+var_7CA8], dl
|
||||
inc eax
|
||||
cmp eax, edi
|
||||
jl short loc_40181A
|
||||
```
|
||||
**Executable Code Obfuscation::Stack Strings** (B0032.017)
|
||||
<br/>MD5: b6e1a2048ea6bd6a941a72300b2d41ce
|
||||
```asm
|
||||
mov cl, 65h ; 'e'
|
||||
mov al, 70h ; 'p'
|
||||
mov [ebp+var_23], cl
|
||||
mov [ebp_var_1f], cl
|
||||
mov [ebp_Str], bl
|
||||
mov [ebp+var_12], bl
|
||||
mov [ebp+var_2E], al
|
||||
mov [ebp+var_2D], al
|
||||
lea ecx, [ebp+Str]
|
||||
mov al, 74h ; 't'
|
||||
mov bl, 2Eh ; '.'
|
||||
mov dl. 6Eh ; 'n'
|
||||
push ecx ; STR
|
||||
mov [ebp+var_13], 30h ; '0'
|
||||
mov [ebp+var_11], 30h ; '0'
|
||||
mov [ebp+var_10], 0
|
||||
mov [ebp+cp], 73h ; 's'
|
||||
mov [ebp+var_2F], 75h ; u'
|
||||
mov [ebp+var_2C], 6Fh ; 'o'
|
||||
mov [ebp+var_2B], 72h ; 'r'
|
||||
mov [ebp+var_2A], al
|
||||
mov [ebp+var_29], bl
|
||||
mov [ebp+var_28], 62h ; 'b'
|
||||
mov [ebp+var_27], 79h ; 'y'
|
||||
mov [ebp+var_26], 69h ; 'i'
|
||||
mov [ebp+var_25], dl
|
||||
mov [ebp+var_24], al
|
||||
mov [ebp+var_22], 72h ; 'r'
|
||||
mov [ebp+var_21], bl
|
||||
mov [ebp+var_20], dl
|
||||
mov [ebp+var_1E], al
|
||||
mov [ebp+var_1D], h
|
||||
call ds:atoi
|
||||
add esp, 4
|
||||
mov dword ptr [ebp+hostshort], eax
|
||||
jmp short loc_401326
|
||||
```
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://insights.sei.cmu.edu/cert/2019/03/api-hashing-tool-imagine-that.html
|
||||
|
||||
<a name="2">[2]</a> https://cofense.com/recent-geodo-malware-campaigns-feature-heavily-obfuscated-macros/
|
||||
|
||||
<a name="3">[3]</a> Rob Simmons, "Comparing Malicious Files," BSides, 2019. http://www.irongeek.com/i.php?page=videos/bsidescharm2019/2-04-comparing-malicious-files-robert-simmons
|
||||
|
||||
<a name="4">[4]</a> https://blogs.cisco.com/security/talos/rombertik
|
||||
|
||||
<a name="5">[5]</a> https://www.proofpoint.com/us/threat-insight/post/ursnif-variant-dreambot-adds-tor-functionality
|
||||
|
||||
<a name="6">[6]</a> https://www.mandiant.com/sites/default/files/2021-09/rpt-poison-ivy.pdf
|
||||
|
||||
<a name="7">[7]</a> https://blog.talosintelligence.com/2018/01/samsam-evolution-continues-netting-over.html
|
||||
|
||||
<a name="8">[8]</a> https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en
|
||||
@@ -0,0 +1,31 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0034</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-static-analysis">Anti-Static Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Executable Code Optimization
|
||||
============================
|
||||
Code is optimized, making it harder to statically analyze.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Jump/Call Absolute Address**|B0034.001|Relative operands of jumps and calls into are made absolute (better compression). May confuse some basic block detection algorithms.|
|
||||
|**Minification**|B0034.002|Minification is 'the process of removing all unnecessary characters from source code without changing its functionality.' [[1]](#1) A simple example is when all the unnecessary whitespace and comments are removed. Minification is distinguished from compression in that it neither adds to nor changes the code seen by the interpreter. Minification is often used for malware written in interpreted languages, such as JavaScript, PHP, or Python. Legitimate code that is transmitted many times a second, such as JavaScript on websites, often uses minification to simply reduce the number of bytes transmitted.|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://en.wikipedia.org/wiki/Minification_(programming)
|
||||
@@ -0,0 +1,40 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0008</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a>, <a href="../anti-static-analysis">Anti-Static Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Executable Code Virtualization
|
||||
==============================
|
||||
Original executable code is virtualized by translating the code into a special format that only a special virtual machine (VM) can run; the VM uses a customized virtual instruction set. A "stub" function calls the VM when the code is run. Virtualized code makes static analysis and reverse engineering more difficult; dumped code won’t run without the VM.
|
||||
|
||||
Virtualized code is a software protection technique. Themida is a commercial tool; VMProtect is an open source tool. [[1]](#1)
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Multiple VMs**|B0008.001|Multiple virtual machines with different architectures (CISC, RISC, etc.) can be used inside of a single executable in order to make reverse engineering even more difficult.|
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Locky Bart**](../xample-malware/locky-bart.md)|January 2017|Code virtualization is added to the Locky Bart binary using WPProtect. [[2]](#2)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://github.com/xiaoweime/WProtect
|
||||
|
||||
<a name="2">[2]</a> https://blog.malwarebytes.com/threat-analysis/2017/01/locky-bart-ransomware-and-backend-server-analysis/
|
||||
@@ -1,33 +1,68 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**E1045**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis), [Anti-Static Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-static-analysis), [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion)|
|
||||
|**Related ATT&CK Technique**|[Software Packing](https://attack.mitre.org/techniques/T1045/)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>F0001</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a>, <a href="../anti-static-analysis">Anti-Static Analysis</a>, <a href="../defense-evasion">Defense Evasion</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Obfuscated Files or Information: Software Packing (<a href="https://attack.mitre.org/techniques/T1027/002/">T1027.002</a>, <a href="https://attack.mitre.org/techniques/T1406/002/">T1406.002</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
Software Packing
|
||||
================
|
||||
This code characteristic - Software Packing - can make static and behavioral analysis difficult and includes packing with a software protectors, such as Themida and Armadillo [[1]](#1). Methods related to anti-analysis are below.
|
||||
This code characteristic - Software Packing - can make static and behavioral analysis difficult and includes packing with software protectors, such as Themida and Armadillo [[1]](#1). Methods related to anti-analysis are below. This behavior covers both characteristics of the malware (i.e., how it is packed) as well as behaviors of the malware (e.g., the malware packs another executable file).
|
||||
|
||||
This description refines the ATT&CK [**Software Packing**](https://attack.mitre.org/techniques/T1045/) technique.
|
||||
This description refines the ATT&CK **Obfuscated Files or Information: Software Packing ([T1027.002](https://attack.mitre.org/techniques/T1027/002/), [T1406.002](https://attack.mitre.org/techniques/T1406/002/))** techniques.
|
||||
|
||||
Methods
|
||||
-------
|
||||
* **Nested Packing**: the malware is packed by one packer, the result is packed, etc.
|
||||
* **Standard Compression**: Uses a standard algorithm, such as UPX or LZMA, to compress an executable file.
|
||||
* **Standard Compression of Code**: Uses a standard algorithm to compress the opcode mnemonics.
|
||||
* **Standard Compression of Data**: Uses a standard algorithm to compress strings and variables (executable file data).
|
||||
* **Custom Compression**: Uses a custom algorithm to compress an executable file.
|
||||
* **Custom Compression of Code**: Uses a custom algorithm to compress opcode mnemonics.
|
||||
* **Custom Compression of Data**: Uses a custom algorithm to compress strings and variables (executable file data).
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Armadillo**|F0001.012|Uses Armadillo.|
|
||||
|**ASPack**|F0001.013|Uses ASPack.|
|
||||
|**Confuser**|F0001.009|Uses Confuser packer.|
|
||||
|**Custom Compression**|F0001.005|Uses a custom algorithm to compress an executable file.|
|
||||
|**Custom Compression of Code**|F0001.006|Uses a custom algorithm to compress opcode mnemonics.|
|
||||
|**Custom Compression of Data**|F0001.007|Uses a custom algorithm to compress strings and variables (executable file data).|
|
||||
|**Nested Packing**|F0001.001|The malware is packed by one packer, the result is packed, etc.|
|
||||
|**Standard Compression**|F0001.002|Uses a standard algorithm, such as UPX or LZMA, to compress an executable file.|
|
||||
|**Standard Compression of Code**|F0001.003|Uses a standard algorithm to compress the opcode mnemonics.|
|
||||
|**Standard Compression of Data**|F0001.004|Uses a standard algorithm to compress strings and variables (executable file data).|
|
||||
|**Themida**|F0001.011|Uses Themida.|
|
||||
|**UPX**|F0001.008|Uses UPX packer.|
|
||||
|**VMProtect**|F0001.010|Uses VMProtect.|
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|-----------|-----------------------------|
|
||||
|---|---|---|
|
||||
|[**Redhip**](../xample-malware/redhip.md)|2011|Redhip samples are packed with different custom packers. [[3]](#3)|
|
||||
|[**Kovter**](../xample-malware/kovter.md)|2016|The malware comes packed by a crypter/FUD [[4]](#4)|
|
||||
|[**Conficker**](../xample-malware/conficker.md)|2008|Conficker is propagated as a DLL which has been backed using the UPX packer [[5]](#5)|
|
||||
|[**DarkComet**](../xample-malware/dark-comet.md)|2008|Has the option to compress its payload using UPX or MPRESS [[6]](#6)|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Has a custom packer to obfuscate itself [[7]](#7)|
|
||||
|[**Emotet**](../xample-malware/emotet.md)|2018|Emotet uses custom packers which first decrypt the loaders and the loaders decrypt and load Emotet's main payloads [[8]](#8)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> Ange Albertini, Packers, 5 April 2010, https://gironsec.com/code/packers.pdf
|
||||
|
||||
<a name="2">[2]</a> Jiang Ming et al, Towards Paving the Way for Large-Scale Windows Malware Analysis: Generic Binary Unpacking with Orders-of-Magnitude Performance Boost, October 2018, https://dl.acm.org/citation.cfm?id=3243771.
|
||||
|
||||
|
||||
<a name="3">[3]</a> https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
|
||||
|
||||
<a name="4">[4]</a> https://www.bleepingcomputer.com/virus-removal/remove-kovter-trojan
|
||||
|
||||
<a name="5">[5]</a> http://www.csl.sri.com/users/vinod/papers/Conficker/
|
||||
|
||||
<a name="6">[6]</a> https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/
|
||||
|
||||
<a name="7">[7]</a> https://www.securityartwork.es/wp-content/uploads/2017/07/Trickbot-report-S2-Grupo.pdf
|
||||
|
||||
<a name="8">[8]</a> https://documents.trendmicro.com/assets/white_papers/ExploringEmotetsActivities_Final.pdf
|
||||
|
||||
@@ -0,0 +1,448 @@
|
||||
# capa Rule Distribution #
|
||||
15 August 2022
|
||||
|
||||
## Histograms ##
|
||||
Histograms showing the number of capa rules mapped into each ATT&CK tactic, MBC objective, and MBC micro-objective are shown below. Details of the tactics and objectives follow.
|
||||
|
||||
### ATT&CK Mapping Histogram ###
|
||||
|
||||
| **TACTIC** | **Number** | |
|
||||
|-----|-----|-----|
|
||||
|Reconnaissance |0| |
|
||||
|Resource Development|0| |
|
||||
|Initial Access |0| |
|
||||
|**Execution**|8| **XXXXXXXX** |
|
||||
|**Persistence**|13| **XXXXXXXXXXXXX** |
|
||||
|**Privilege Escalation**|1 | **X** |
|
||||
|**Defense Evasion**|32| **XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX** |
|
||||
|**Credential Access**|4| **XXXX** |
|
||||
|**Discovery**|17| **XXXXXXXXXXXXXXXXX** |
|
||||
|Lateral Movement|0| |
|
||||
|**Collection**|7| **XXXXXXX** |
|
||||
|**Command and Control**|1| **X** |
|
||||
|Exfiltration|0| |
|
||||
|**Impact**|5| **XXXXX** |
|
||||
|
||||
### MBC Mapping Histogram (Objectives) ###
|
||||
|
||||
| **OBJECTIVE** | **Number** | |
|
||||
|-----|-----|-----|
|
||||
|**Anti-Behavioral Analysis** |20| **XXXXXXXXXXXXXXXXXXXX**|
|
||||
|**Anti-Static Analysis**|9| **XXXXXXXXX** |
|
||||
|**Collection**|4| **XXXX** |
|
||||
|**Command and Control**|3| **XXX** |
|
||||
|Credential Access|0| |
|
||||
|**Defense Evasion**|13| **XXXXXXXXXXXXX** |
|
||||
|**Discovery**|6| **XXXXXX** |
|
||||
|**Execution**|1| **X** |
|
||||
|Exfiltration|0| |
|
||||
|**Impact**|5| **XXXXX** |
|
||||
|Lateral Movement|0| |
|
||||
|Persistence|0| |
|
||||
|Privilege Escalation|0 | |
|
||||
|
||||
### MBC Mapping Histogram (Micro-Objectives) ###
|
||||
|
||||
| **MICRO-OBJECTIVE** | **Number** | |
|
||||
|-----|-----|-----|
|
||||
|**Communication** |34| **XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX**|
|
||||
|**Cryptography**|16| **XXXXXXXXXXXXXXXX** |
|
||||
|**Data**|15| **XXXXXXXXXXXXXXX** |
|
||||
|**File System**|11| **XXXXXXXXXXX** |
|
||||
|**Hardware**|4| **XXXX** |
|
||||
|**Memory**|2| **XX** |
|
||||
|**Operating System**|11| **XXXXXXXXXXX** |
|
||||
|**Process**|14| **XXXXXXXXXXXXXX** |
|
||||
|
||||
|
||||
## ATT&CK MAPPINGS ##
|
||||
|
||||
### Collection: ###
|
||||
num: 7
|
||||
- Archive Collected Data::Archive via Library [T1560.002]
|
||||
- Clipboard Data [T1115]
|
||||
- Video Capture [T1125]
|
||||
- Input Capture::Keylogging [T1056.001]
|
||||
- Data from Information Repositories [T1213]
|
||||
- Audio Capture [T1123]
|
||||
- Screen Capture [T1113]
|
||||
|
||||
### Command and Control: ###
|
||||
num: 1
|
||||
- Ingress Tool Transfer [T1105]
|
||||
|
||||
### Credential Access: ###
|
||||
num: 4
|
||||
- Credentials from Password Stores::Windows Credential Manager [T1555.004]
|
||||
- Credentials from Password Stores::Password Managers [T1555.005]
|
||||
- Credentials from Password Stores [T1555]
|
||||
- Credentials from Password Stores::Credentials from Web Browsers [T1555.003]
|
||||
|
||||
### Defense Evasion: ###
|
||||
num: 32
|
||||
- Obfuscated Files or Information::Software Packing [T1027.002]
|
||||
- Virtualization/Sandbox Evasion::System Checks [T1497.001]
|
||||
- Impair Defenses::Disable or Modify Tools [T1562.001]
|
||||
- Virtualization/Sandbox Evasion::User Activity Based Checks [T1497.002]
|
||||
- Virtualization/Sandbox Evasion [T1497]
|
||||
- Indicator Removal on Host [T1070]
|
||||
- Impair Defenses::Disable Windows Event Logging [T1562.002]
|
||||
- Process Injection [T1055]
|
||||
- Access Token Manipulation::Parent PID Spoofing [T1134.004]
|
||||
- Indicator Removal on Host::Clear Windows Event Logs [T1070.001]
|
||||
- Indicator Removal on Host::File Deletion [T1070.004]
|
||||
- Indicator Removal on Host::Timestomp [T1070.006]
|
||||
- Obfuscated Files or Information [T1027]
|
||||
- Obfuscated Files or Information::Indicator Removal from Tools [T1027.005]
|
||||
- Deobfuscate/Decode Files or Information [T1140]
|
||||
- Obfuscated Files or Information [T1027.002]
|
||||
- Subvert Trust Controls::Mark-of-the-Web Bypass [T1553.005]
|
||||
- File and Directory Permissions Modification [T1222]
|
||||
- Hide Artifacts::Hidden Window [T1564.003]
|
||||
- Hide Artifacts [T1564]
|
||||
- "Process Injection::Process Doppelg\xE4nging [T1055.013]"
|
||||
- Process Injection::Portable Executable Injection [T1055.002]
|
||||
- Process Injection::Dynamic-link Library Injection [T1055.001]
|
||||
- Process Injection::Thread Execution Hijacking [T1055.003]
|
||||
- Process Injection::Asynchronous Procedure Call [T1055.004]
|
||||
- Process Injection::Process Hollowing [T1055.012]
|
||||
- Modify Registry [T1112]
|
||||
- Impair Defenses::Safe Mode Boot [T1562.009]
|
||||
- Subvert Trust Controls::Code Signing Policy Modification [T1553.006]
|
||||
- Abuse Elevation Control Mechanism::Bypass User Account Control [T1548.002]
|
||||
- Hijack Execution Flow [T1574]
|
||||
- BITS Jobs [T1197]
|
||||
|
||||
### Discovery: ###
|
||||
num: 17
|
||||
|
||||
- File and Directory Discovery [T1083]
|
||||
- System Information Discovery [T1082]
|
||||
- Process Discovery [T1057]
|
||||
- System Location Discovery::System Language Discovery [T1614.001]
|
||||
- System Service Discovery [T1007]
|
||||
- Application Window Discovery [T1010]
|
||||
- System Owner/User Discovery [T1033]
|
||||
- Account Discovery [T1087]
|
||||
- Query Registry [T1012]
|
||||
- Software Discovery::Security Software Discovery [T1518.001]
|
||||
- Software Discovery [T1518]
|
||||
- System Network Configuration Discovery::Internet Connection Discovery [T1016.001]
|
||||
- System Network Configuration Discovery [T1016]
|
||||
- Network Sniffing [T1040]
|
||||
- System Location Discovery [T1614]
|
||||
- Group Policy Discovery [T1615]
|
||||
- Domain Trust Discovery [T1482]
|
||||
|
||||
### Execution: ###
|
||||
num: 8
|
||||
|
||||
- Command and Scripting Interpreter [T1059]
|
||||
- Windows Management Instrumentation [T1047]
|
||||
- System Services::Service Execution [T1569.002]
|
||||
- Command and Scripting Interpreter::PowerShell [T1059.001]
|
||||
- Shared Modules [T1129]
|
||||
- Command and Scripting Interpreter::Python [T1059.006]
|
||||
- Command and Scripting Interpreter::Unix Shell [T1059.004]
|
||||
- Command and Scripting Interpreter::Windows Command Shell [T1059.003]
|
||||
|
||||
### Exfiltration: ###
|
||||
num: 0
|
||||
|
||||
### Impact: ###
|
||||
num: 5
|
||||
|
||||
- Endpoint Denial of Service [T1499]
|
||||
- System Shutdown/Reboot [T1529]
|
||||
- Data Manipulation::Transmitted Data Manipulation [T1565.002]
|
||||
- Inhibit System Recovery [T1490]
|
||||
- Disk Wipe::Disk Structure Wipe [T1561.002]
|
||||
|
||||
### Initial Access: ###
|
||||
num: 0
|
||||
|
||||
### Lateral Movement: ###
|
||||
num: 0
|
||||
|
||||
### Persistence: ###
|
||||
num: 13
|
||||
|
||||
- Create or Modify System Process::Windows Service [T1543.003]
|
||||
- Event Triggered Execution::Unix Shell Configuration Modification [T1546.004]
|
||||
- Boot or Logon Autostart Execution::XDG Autostart Entries [T1547.013]
|
||||
- Server Software Component::IIS Components [T1505.004]
|
||||
- Modify Authentication Process [T1556]
|
||||
- Modify Authentication Process::Password Filter DLL [T1556.002]
|
||||
- Boot or Logon Initialization Scripts::RC Scripts [T1037.004]
|
||||
- Scheduled Task/Job::Scheduled Task [T1053.005]
|
||||
- Boot or Logon Autostart Execution::Active Setup [T1547.014]
|
||||
- Event Triggered Execution::AppInit DLLs [T1546.010]
|
||||
- Event Triggered Execution [T1546]
|
||||
- Boot or Logon Autostart Execution::Winlogon Helper DLL [T1547.004]
|
||||
- Boot or Logon Autostart Execution::Registry Run Keys / Startup Folder [T1547.001]
|
||||
|
||||
### Privilege Escalation: ###
|
||||
num: 1
|
||||
|
||||
- Access Token Manipulation [T1134]
|
||||
|
||||
### Reconnaissance: ###
|
||||
num: 0
|
||||
|
||||
### Resource Development: ###
|
||||
num: 0
|
||||
|
||||
|
||||
|
||||
## MBC MAPPINGS ##
|
||||
|
||||
### Anti-Behavioral Analysis: ###
|
||||
num: 20
|
||||
|
||||
- Emulator Detection [B0004]
|
||||
- Virtual Machine Detection [B0009]
|
||||
- Virtual Machine Detection::Human User Check [B0009.012]
|
||||
- Sandbox Detection::Product Key/ID Testing [B0007.005]
|
||||
- Debugger Detection [B0001]
|
||||
- Debugger Detection::Software Breakpoints [B0001.025]
|
||||
- Debugger Detection::Process Environment Block BeingDebugged [B0001.035]
|
||||
- Debugger Detection::Timing/Delay Check GetTickCount [B0001.032]
|
||||
- Debugger Detection::SetHandleInformation [B0001.024]
|
||||
- Debugger Detection::OutputDebugString [B0001.016]
|
||||
- Debugger Detection::Memory Write Watching [B0001.010]
|
||||
- Debugger Detection::Timing/Delay Check QueryPerformanceCounter [B0001.033]
|
||||
- Debugger Detection::Hardware Breakpoints [B0001.005]
|
||||
- Debugger Detection::NtQueryInformationProcess [B0001.012]
|
||||
- Debugger Detection::CheckRemoteDebuggerPresent [B0001.002]
|
||||
- Debugger Detection::Process Environment Block NtGlobalFlag [B0001.036]
|
||||
- Debugger Detection::Anti-debugging Instructions [B0001.034]
|
||||
- Conditional Execution::Runs as Service [B0025.007]
|
||||
- Debugger Detection::Process Environment Block [B0001.019]
|
||||
- Dynamic Analysis Evasion::Delayed Execution [B0003.003]
|
||||
|
||||
### Anti-Static Analysis: ###
|
||||
num: 9
|
||||
|
||||
- Disassembler Evasion [B0012]
|
||||
- Software Packing [F0001]
|
||||
- Software Packing::Themida [F0001.011]
|
||||
- Software Packing::VMProtect [F0001.010]
|
||||
- Software Packing::Standard Compression [F0001.002]
|
||||
- Software Packing::Confuser [F0001.009]
|
||||
- Software Packing::UPX [F0001.008]
|
||||
- Executable Code Obfuscation [B0032]
|
||||
- Disassembler Evasion::Argument Obfuscation [B0012.001]
|
||||
|
||||
### Collection: ###
|
||||
num: 4
|
||||
|
||||
- Keylogging::Polling [F0002.002]
|
||||
- Keylogging::Application Hook [F0002.001]
|
||||
- Screen Capture::WinAPI [E1113.m01]
|
||||
- Screen Capture [E1113]
|
||||
|
||||
### Command and Control: ###
|
||||
num: 3
|
||||
|
||||
- C2 Communication::Send Data [B0030.001]
|
||||
- C2 Communication::Receive Data [B0030.002]
|
||||
- C2 Communication::Server to Client File Transfer [B0030.003]
|
||||
|
||||
### Credential Access: ###
|
||||
num: 0
|
||||
|
||||
### Defense Evasion: ###
|
||||
num: 13
|
||||
|
||||
- Disable or Evade Security Tools::Heavens Gate [F0004.008]
|
||||
- Disable or Evade Security Tools::Modify Policy [F0004.005]
|
||||
- Process Injection::Patch Process Command Line [E1055.m04]
|
||||
- Self Deletion::COMSPEC Environment Variable [F0007.001]
|
||||
- Obfuscated Files or Information::Encryption [E1027.m04]
|
||||
- Obfuscated Files or Information::Encryption-Standard Algorithm [E1027.m05]
|
||||
- Obfuscated Files or Information::Encoding-Standard Algorithm [E1027.m02]
|
||||
- Disable or Evade Security Tools::Bypass Windows File Protection [F0004.007]
|
||||
- Process Injection [E1055]
|
||||
- Disable or Evade Security Tools::Disable Code Integrity [F0004.009]
|
||||
- Hijack Execution Flow::Abuse Windows Function Calls [F0015.006]
|
||||
- Process Injection::Injection via Windows Fibers [E1055.m05]
|
||||
- Hijack Execution Flow::Import Address Table (IAT) Hooking [F0015.003]
|
||||
|
||||
### Discovery: ###
|
||||
num: 6
|
||||
|
||||
- Analysis Tool Discovery::Process detection [B0013.001]
|
||||
- Application Window Discovery::Window Text [E1010.m01]
|
||||
- Taskbar Discovery [B0043]
|
||||
- File and Directory Discovery::Log File [E1083.m01]
|
||||
- Code Discovery::Enumerate PE Sections [B0046.001]
|
||||
- Code Discovery::Inspect Section Memory Permissions [B0046.002]
|
||||
|
||||
### Execution: ###
|
||||
num: 1
|
||||
|
||||
- Install Additional Program [B0023]
|
||||
|
||||
### Exfiltration: ###
|
||||
num: 0
|
||||
|
||||
### Impact: ###
|
||||
num: 5
|
||||
|
||||
- Modify Hardware::Mouse [B0042.002]
|
||||
- Modify Hardware::CDROM [B0042.001]
|
||||
- Clipboard Modification [E1510]
|
||||
- Data Destruction::Delete Shadow Copies [E1485.m04]
|
||||
- Remote Access::Reverse Shell [B0022.001]
|
||||
|
||||
### Lateral Movement: ###
|
||||
num: 0
|
||||
|
||||
### Persistence: ###
|
||||
num: 0
|
||||
|
||||
### Privilege Escalation: ###
|
||||
num: 0
|
||||
|
||||
|
||||
## MBC MICRO-BEHAVIOR MAPPINGS ##
|
||||
|
||||
### Communication: ###
|
||||
num: 34
|
||||
|
||||
- DNS Communication::Resolve [C0011.001]
|
||||
- HTTP Communication::Read Header [C0002.014]
|
||||
- HTTP Communication::WinHTTP [C0002.008]
|
||||
- HTTP Communication::IWebBrowser [C0002.010]
|
||||
- HTTP Communication::Set Header [C0002.013]
|
||||
- HTTP Communication::Start Server [C0002.018]
|
||||
- HTTP Communication::Receive Request [C0002.015]
|
||||
- HTTP Communication::Send Response [C0002.016]
|
||||
- HTTP Communication::Get Response [C0002.017]
|
||||
- HTTP Communication::Send Request [C0002.003]
|
||||
- HTTP Communication::Download URL [C0002.006]
|
||||
- HTTP Communication::Create Request [C0002.012]
|
||||
- HTTP Communication::Send Data [C0002.005]
|
||||
- HTTP Communication::Open URL [C0002.004]
|
||||
- HTTP Communication::Connect to Server [C0002.009]
|
||||
- HTTP Communication::Extract Body [C0002.011]
|
||||
- Socket Communication::Start TCP Server [C0001.005]
|
||||
- Socket Communication::TCP Client [C0001.008]
|
||||
- Interprocess Communication::Create Pipe [C0003.001]
|
||||
- Interprocess Communication::Write Pipe [C0003.004]
|
||||
- Interprocess Communication::Connect Pipe [C0003.002]
|
||||
- Interprocess Communication::Read Pipe [C0003.003]
|
||||
- FTP Communication::Send File [C0004.001]
|
||||
- DNS Communication::Server Connect [C0011.002]
|
||||
- Socket Communication::Get Socket Status [C0001.012]
|
||||
- Socket Communication::Set Socket Config [C0001.001]
|
||||
- Socket Communication::Initialize Winsock Library [C0001.009]
|
||||
- Socket Communication::Connect Socket [C0001.004]
|
||||
- Socket Communication::Create TCP Socket [C0001.011]
|
||||
- Socket Communication::Send TCP Data [C0001.014]
|
||||
- Socket Communication::Create UDP Socket [C0001.010]
|
||||
- Socket Communication::Send Data [C0001.007]
|
||||
- Socket Communication::Receive Data [C0001.006]
|
||||
- ICMP Communication::Echo Request [C0014.002]
|
||||
|
||||
### Cryptography: ###
|
||||
num: 16
|
||||
|
||||
- Encryption Key::Import Public Key [C0028.001]
|
||||
- Decrypt Data [C0031]
|
||||
- Encryption Key [C0028]
|
||||
- Decrypt Data::AES [C0031.001]
|
||||
- Encrypt Data [C0027]
|
||||
- Encrypt Data::RC4 [C0027.009]
|
||||
- Cryptographic Hash [C0029]
|
||||
- Cryptographic Hash::Tiger [C0029.005]
|
||||
- Cryptographic Hash::SHA1 [C0029.002]
|
||||
- Cryptographic Hash::SHA256 [C0029.003]
|
||||
- Cryptographic Hash::MD5 [C0029.001]
|
||||
- Cryptographic Hash::SHA224 [C0029.004]
|
||||
- Hashed Message Authentication Code [C0061]
|
||||
- Generate Pseudo-random Sequence::Use API [C0021.003]
|
||||
- Generate Pseudo-random Sequence::Mersenne Twister [C0021.005]
|
||||
- Crypto Library [C0059]
|
||||
|
||||
### Data: ###
|
||||
num: 15
|
||||
|
||||
- Checksum::CRC32 [C0032.001]
|
||||
- Checksum::Luhn [C0032.002]
|
||||
- Checksum::Adler [C0032.005]
|
||||
- Non-Cryptographic Hash::MurmurHash [C0030.001]
|
||||
- Non-Cryptographic Hash::FNV [C0030.005]
|
||||
- Non-Cryptographic Hash [C0030]
|
||||
- Encode Data::Base64 [C0026.001]
|
||||
- Decompress Data::aPLib [C0025.003]
|
||||
- Decompress Data::IEncodingFilterFactory [C0025.002]
|
||||
- Compress Data [C0024]
|
||||
- Decompress Data::QuickLZ [C0025.001]
|
||||
- Decompress Data [C0025]
|
||||
- Check String [C0019]
|
||||
- Modulo [C0058]
|
||||
- Compression Library [C0060]
|
||||
|
||||
### File System: ###
|
||||
num: 11
|
||||
|
||||
- Set File Attributes [C0050]
|
||||
- Create Directory [C0046]
|
||||
- Delete File [C0047]
|
||||
- Delete Directory [C0048]
|
||||
- Get File Attributes [C0049]
|
||||
- Move File [C0063]
|
||||
- Writes File [C0052]
|
||||
- Copy File [C0045]
|
||||
- Read File [C0051]
|
||||
- Read Virtual Disk [C0056]
|
||||
- Create File [C0016]
|
||||
|
||||
### Hardware: ###
|
||||
num: 4
|
||||
|
||||
- Simulate Hardware::Ctrl-Alt-Del [C0057.001]
|
||||
- Install Driver [C0037]
|
||||
- Install Driver::Minifilter [C0037.001]
|
||||
- Load Driver::Minifilter [C0023.001]
|
||||
|
||||
### Memory: ###
|
||||
num: 2
|
||||
|
||||
- Free Memory [C0044]
|
||||
- Allocate Memory [C0007]
|
||||
|
||||
### Operating System: ###
|
||||
num: 11
|
||||
|
||||
- Environment Variable::Set Variable [C0034.001]
|
||||
- Environment Variable::Get Variable [C0034.002]
|
||||
- Wallpaper [C0035]
|
||||
- Console [C0033]
|
||||
- Registry::Set Registry Key [C0036.001]
|
||||
- Registry::Create Registry Key [C0036.004]
|
||||
- Registry::Open Registry Key [C0036.003]
|
||||
- Registry::Query Registry Key [C0036.005]
|
||||
- Registry::Query Registry Value [C0036.006]
|
||||
- Registry::Delete Registry Key [C0036.002]
|
||||
- Registry::Delete Registry Value [C0036.007]
|
||||
|
||||
### Process: ###
|
||||
num: 14
|
||||
|
||||
- Create Thread [C0038]
|
||||
- Suspend Thread [C0055]
|
||||
- Terminate Thread [C0039]
|
||||
- Resume Thread [C0054]
|
||||
- Enumerate Threads [C0064]
|
||||
- Create Mutex [C0042]
|
||||
- Check Mutex [C0043]
|
||||
- Allocate Thread Local Storage [C0040]
|
||||
- Set Thread Local Storage Value [C0041]
|
||||
- Create Process [C0017]
|
||||
- Create Process::Create Suspended Process [C0017.003]
|
||||
- Terminate Process [C0018]
|
||||
- Open Process [C0065]
|
||||
- Open Thread [C0066]
|
||||
|
||||
+13
-21
@@ -1,24 +1,16 @@
|
||||
|||
|
||||
|--|-----|
|
||||
|**ID**|**M9003**|
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>OB0003</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
# Collection #
|
||||
Behaviors that identify and gather information, such as sensitive files, from a target network prior to exfiltration. This objective includes locations on a system or network where the malware may look for information to exfiltrate.
|
||||
Behaviors that enable malware to identify and gather information, such as sensitive files, from a machine or network. Sources often targeted include drives, browsers, audio/video, and email. Often the malware's next objective is to exfiltrate the information gathered.
|
||||
|
||||
* **Access Call Log** [T1433](https://github.com/MBCProject/mbc-markdown/blob/master/collection/access-call-log.md)
|
||||
* **Access Sensitive Data or Credentials in Files** [T1409](https://github.com/MBCProject/mbc-markdown/blob/master/collection/access-sensitive-data.md)
|
||||
* **Audio Capture** [T1123](https://github.com/MBCProject/mbc-markdown/blob/master/collection/audio-capture.md)
|
||||
* **Automated Collection** [T1119](https://github.com/MBCProject/mbc-markdown/blob/master/collection/auto-collect.md)
|
||||
* **Capture SMS Message** [T1412](https://github.com/MBCProject/mbc-markdown/blob/master/collection/capture-sms.md)
|
||||
* **Clipboard Data** [T1115](https://github.com/MBCProject/mbc-markdown/blob/master/collection/clipboard-data.md)
|
||||
* **Data from Local System** [T1005](https://github.com/MBCProject/mbc-markdown/blob/master/collection/data-local-system.md)
|
||||
* **Data from Network Shared Drive** [T1039](https://github.com/MBCProject/mbc-markdown/blob/master/collection/data-network-share.md)
|
||||
* **Data from Removable Media** [T1025](https://github.com/MBCProject/mbc-markdown/blob/master/collection/data-removable-media.md)
|
||||
* **Data Staged** [T1074](https://github.com/MBCProject/mbc-markdown/blob/master/collection/data-staged.md)
|
||||
* **Email Collection** [T1114](https://github.com/MBCProject/mbc-markdown/blob/master/collection/email-collect.md)
|
||||
* **Input Capture** [T1056](https://github.com/MBCProject/mbc-markdown/blob/master/collection/input-capture.md)
|
||||
* **Location Tracking** [T1430](https://github.com/MBCProject/mbc-markdown/blob/master/collection/location-track.md)
|
||||
* **Man in the Browser** [T1185](https://github.com/MBCProject/mbc-markdown/blob/master/collection/man-in-browser.md)
|
||||
* **Microphone or Camera Capture** [T1429](https://github.com/MBCProject/mbc-markdown/blob/master/collection/micro-cam-capture.md)
|
||||
* **Screen Capture** [T1113](https://github.com/MBCProject/mbc-markdown/blob/master/collection/screen-capture.md)
|
||||
* **Video Capture** [T1125](https://github.com/MBCProject/mbc-markdown/blob/master/collection/video-capture.md)
|
||||
* **Cryptocurrency** [B0028](../collection/cryptocurrency.md)
|
||||
* **Hijack Execution Flow** [F0015](../defense-evasion/hijack-execution-flow.md)
|
||||
* **Input Capture** [E1056](../collection/input-capture.md)
|
||||
* **Keylogging** [F0002](../collection/keylogging.md)
|
||||
* **Screen Capture** [E1113](../collection/screen-capture.md)
|
||||
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1433**|
|
||||
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|
||||
|**Related ATT&CK Technique**|[Access Call Log](https://attack.mitre.org/techniques/T1433/)|
|
||||
|
||||
Access Call Log
|
||||
===============
|
||||
Malware gathers call log data.
|
||||
|
||||
**See ATT&CK:** [**Access Call Log**](https://attack.mitre.org/techniques/T1433/).
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**E1409**|
|
||||
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection), [Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access)|
|
||||
|**Related ATT&CK Technique**|[Access Sensitive Data or Credentials in Files](https://attack.mitre.org/techniques/T1409/)|
|
||||
|
||||
Access Sensitive Data or Credentials in Files
|
||||
=============================================
|
||||
Malware accesses files that contain sensitive data or credentials (e.g., passwords). Access of Bitcoin and other cryptocurrency wallets also fall under this behavior.
|
||||
|
||||
**See ATT&CK:** [**Access Sensitive Data or Credentials in Files**](https://attack.mitre.org/techniques/T1409/).
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1123**|
|
||||
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|
||||
|**Related ATT&CK Technique**|[Audio Capture](https://attack.mitre.org/techniques/T1123/)|
|
||||
|
||||
Audio Capture
|
||||
=============
|
||||
Malware leverages system's peripheral devices to capture audio.
|
||||
|
||||
**See ATT&CK:** [**Audio Capture**](https://attack.mitre.org/techniques/T1123/).
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1119**|
|
||||
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|
||||
|**Related ATT&CK Technique**|[Automated Collection](https://attack.mitre.org/techniques/T1119/)|
|
||||
|
||||
Automated Collection
|
||||
====================
|
||||
Malware uses automated techniques for collecting system data.
|
||||
|
||||
**See ATT&CK:** [**Automated Collection**](https://attack.mitre.org/techniques/T1119/).
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1412**|
|
||||
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection), [Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access)|
|
||||
|**Related ATT&CK Technique**|[Capture SMS Messages](https://attack.mitre.org/techniques/T1412/)|
|
||||
|
||||
Capture SMS Messages
|
||||
====================
|
||||
Malware captures data sent via SMS (e.g., authentication credentials).
|
||||
|
||||
**See ATT&CK:** [**Capture SMS Messages**](https://attack.mitre.org/techniques/T1412/).
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1115**|
|
||||
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|
||||
|**Related ATT&CK Technique**|[Clipboard Data](https://attack.mitre.org/techniques/T1115/)|
|
||||
|
||||
Clipboard Data
|
||||
==============
|
||||
Malware collects data stored in the Windows clipboard.
|
||||
|
||||
**See ATT&CK:** [**Clipboard Data**](https://attack.mitre.org/techniques/T1115/).
|
||||
@@ -0,0 +1,28 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0028</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../collection">Collection</a>, <a href="../credential-access">Credential Access</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Cryptocurrency
|
||||
==============
|
||||
Malware accesses files that contain sensitive data or credentials related to Bitcoin and other cryptocurrency wallets.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Bitcoin**|B0028.001|Access Bitcoin data.|
|
||||
|**Ethereum**|B0028.002|Access Ethereum data.|
|
||||
|**Zcash**|B0028.003|Access Zcash data.|
|
||||
@@ -1,22 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1005**|
|
||||
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|
||||
|**Related ATT&CK Technique**|[Data from Local System](https://attack.mitre.org/techniques/T1005/)|
|
||||
|
||||
Data from Local System
|
||||
======================
|
||||
Malware collects sensitive data from local system sources.
|
||||
|
||||
**See ATT&CK:** [**Data from Local System**](https://attack.mitre.org/techniques/T1005/).
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|-----------|-----------------------------|
|
||||
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
|[**Poison-Ivy**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/poison-ivy.md)|2005|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[1]](#1)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1039**|
|
||||
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|
||||
|**Related ATT&CK Technique**|[Data from Network Shared Drive](https://attack.mitre.org/techniques/T1039/)|
|
||||
|
||||
Data from Network Shared Drive
|
||||
==============================
|
||||
Malware collects from remote systems via shared network drives that are accessible from the compromised system.
|
||||
|
||||
**See ATT&CK:** [**Data from Network Shared Drive**](https://attack.mitre.org/techniques/T1039/).
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1025**|
|
||||
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|
||||
|**Related ATT&CK Technique**|[Data from Removable Media](https://attack.mitre.org/techniques/T1025/)|
|
||||
|
||||
Data from Removable Media
|
||||
=========================
|
||||
Malware collects from removable media connected to the compromised system.
|
||||
|
||||
**See ATT&CK:** [**Data from Removable Media**](https://attack.mitre.org/techniques/T1025/).
|
||||
@@ -1,21 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1074**|
|
||||
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|
||||
|**Related ATT&CK Technique**|[Data Staged](https://attack.mitre.org/techniques/T1074/)|
|
||||
|
||||
Data Staged
|
||||
===========
|
||||
Malware stages collected data prior to [Exfiltration](https://github.com/MBCProject/mbc-markdown/tree/master/exfiltration).
|
||||
|
||||
**See ATT&CK:** [**Data Staged**](https://attack.mitre.org/techniques/T1074/).
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|--------|-----------------------------|
|
||||
|[**Poison-Ivy**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/poison-ivy.md)|2005|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[1]](#1)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
|
||||
@@ -1,17 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1114**|
|
||||
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|
||||
|**Related ATT&CK Technique**|[Email Collection](https://attack.mitre.org/techniques/T1114/)|
|
||||
|
||||
Email Collection
|
||||
================
|
||||
Malware targets user email for collection.
|
||||
|
||||
**See ATT&CK:** [**Email Collection**](https://attack.mitre.org/techniques/T1114/).
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|-----------|-----------------------------|
|
||||
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
+32
-11
@@ -1,26 +1,47 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**E1056**|
|
||||
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection), [Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access)|
|
||||
|**Related ATT&CK Technique**|[Input Capture](https://attack.mitre.org/techniques/T1056/)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1056</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../collection">Collection</a>, <a href="../credential-access">Credential Access</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Input Capture (<a href="https://attack.mitre.org/techniques/T1056">T1056</a>, <a href="https://attack.mitre.org/techniques/T1417/">T1417</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Input Capture
|
||||
=============
|
||||
Malware captures user input.
|
||||
|
||||
**See ATT&CK:** [**Input Capture**](https://attack.mitre.org/techniques/T1056/).
|
||||
See ATT&CK: **Input Capture ([T1056](https://attack.mitre.org/techniques/T1056), [T1417](https://attack.mitre.org/techniques/T1417/))**.
|
||||
|
||||
Methods
|
||||
-------
|
||||
* **Mouse Events**: Mouse events are captured.
|
||||
* **Keyboard Events**: Keyboard events are captured.
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Mouse Events**|E1056.m01|Mouse events are captured.|
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|--------|-----------------------------|
|
||||
|[**Poison-Ivy**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/poison-ivy.md)|2005|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[1]](#1)|
|
||||
|---|---|---|
|
||||
|[**Rombertik**](../xample-malware/rombertik.md)|2015|The malware injects itself into a browser and captures user input data [[1]](#1)|
|
||||
|[**Ursnif**](../xample-malware/ursnif.md)|2016|Injects HTML into browser session to collect sensitive online banking information when the victim performs their online banking [[2]](#2)|
|
||||
|[**DarkComet**](../xample-malware/dark-comet.md)|2008|Can capture audio and video [[3]](#3)|
|
||||
|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|Can capture audio and video [[4]](#4)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
|
||||
<a name="1">[1]</a> https://blogs.cisco.com/security/talos/rombertik
|
||||
|
||||
<a name="2">[2]</a> https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/BKDR_URSNIF.SM?_ga=2.129468940.1462021705.1559742358-1202584019.1549394279
|
||||
|
||||
<a name="3">[3]</a> https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/
|
||||
|
||||
<a name="4">[4]</a> https://www.cyber.nj.gov/threat-center/threat-profiles/trojan-variants/poison-ivy
|
||||
|
||||
@@ -0,0 +1,52 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>F0002</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../collection">Collection</a>, <a href="../credential-access">Credential Access</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Input Capture: Keylogging (<a href="https://attack.mitre.org/techniques/T1056/001">T1056.001</a>, <a href="https://attack.mitre.org/techniques/T1417/001/">T1417.001</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Keylogging
|
||||
==========
|
||||
Malware captures user keyboard input.
|
||||
|
||||
See ATT&CK: **Input Capture: Keylogging ([T1056.001](https://attack.mitre.org/techniques/T1056/001), [T1417.001](https://attack.mitre.org/techniques/T1417/001/))**
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Application Hook**|F0002.001|Keystrokes are captured with an application hook.|
|
||||
|**Polling**|F0002.002|Keystrokes are captured via polling (e.g., user32.GetAsyncKeyState, user32.GetKeyState).|
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Hupigon**](../xample-malware/hupigon.md)|2013|Certain variants of the malware may have keylogging functionality [[1]](#1)|
|
||||
|[**UP007**](../xample-malware/up007.md)|2016|The malware logs keystrokes to a file [[2]](#2)|
|
||||
|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|Keylogger plugin allows for collection of keystrokes [[3]](#3)|
|
||||
|[**DarkComet**](../xample-malware/dark-comet.md)|2008|DarkComet can capture keystrokes [[4]](#4)|
|
||||
|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|Can capture keystrokes [[5]](#5)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.f-secure.com/v-descs/backdoor_w32_hupigon.shtml
|
||||
|
||||
<a name="2">[2]</a> https://citizenlab.ca/2016/04/between-hong-kong-and-burma/
|
||||
|
||||
<a name="3">[3]</a> https://securelist.com/be2-custom-plugins-router-abuse-and-target-profiles/67353/
|
||||
|
||||
<a name="4">[4]</a> https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/
|
||||
|
||||
<a name="5">[5]</a> https://www.cyber.nj.gov/threat-center/threat-profiles/trojan-variants/poison-ivy
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1430**|
|
||||
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|
||||
|**Related ATT&CK Technique**|[Location Tracking](https://attack.mitre.org/techniques/T1430/)|
|
||||
|
||||
Location Tracking
|
||||
=================
|
||||
Malware tracks a system's physical location.
|
||||
|
||||
**See ATT&CK:** [**Location Tracking**](https://attack.mitre.org/techniques/T1430/).
|
||||
@@ -1,17 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1185**|
|
||||
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|
||||
|**Related ATT&CK Technique**|[Man in the Browser](https://attack.mitre.org/techniques/T1185/)|
|
||||
|
||||
Man in the Browser
|
||||
==================
|
||||
Malware leverages vulnerabilities and functionality in browser software to change content, modify behavior, and intercept information.
|
||||
|
||||
**See ATT&CK:** [**Man in the Browser**](https://attack.mitre.org/techniques/T1185/).
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|-----------|-----------------------------|
|
||||
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1429**|
|
||||
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|
||||
|**Related ATT&CK Technique**|[Microphone or Camera Recordings](https://attack.mitre.org/techniques/T1429/), [Capture Camera](https://attack.mitre.org/techniques/T1512/), [Capture Audio](https://attack.mitre.org/techniques/T1429/)|
|
||||
|
||||
Microphone or Camera Capture
|
||||
============================
|
||||
Malware records activities using the device microphone and/or camera.
|
||||
|
||||
**See ATT&CK:** [**Microphone or Camera Recordings**](https://attack.mitre.org/techniques/T1429/), [Capture Camera](https://attack.mitre.org/techniques/T1512/), [Capture Audio](https://attack.mitre.org/techniques/T1429/).
|
||||
@@ -1,11 +1,45 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1113**|
|
||||
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|
||||
|**Related ATT&CK Technique**|[Screen Capture](https://attack.mitre.org/techniques/T1113/)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1113</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../collection">Collection</a>, <a href="../credential-access">Credential Access</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Screen Capture (<a href="https://attack.mitre.org/techniques/T1113/">T1113</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Screen Capture
|
||||
==============
|
||||
Malware takes screen captures.
|
||||
=============
|
||||
Malware takes screen captures of the desktop.
|
||||
|
||||
**See ATT&CK:** [**Screen Capture**](https://attack.mitre.org/techniques/T1113/).
|
||||
See ATT&CK: **Screen Capture ([T1113](https://attack.mitre.org/techniques/T1113/))**.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**WinAPI**|E1113.m01|Screen is captured using WinAPI functions (e.g., user32.GetDesktopWindow).|
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**GotBotKR**](../xample-malware/gotbotkr.md)|2019| GoBotKR is capable of capturing screenshots. [[1]](#1)|
|
||||
|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|Screenshot plugin allows for collection of screenshots [[2]](#2)|
|
||||
|[**DarkComet**](../xample-malware/dark-comet.md)|2008|Can take screenshots of victim's computer [[3]](#3)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/
|
||||
|
||||
<a name="2">[2]</a> https://securelist.com/be2-custom-plugins-router-abuse-and-target-profiles/67353/
|
||||
|
||||
<a name="3">[3]</a> https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/
|
||||
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1125**|
|
||||
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|
||||
|**Related ATT&CK Technique**|[Video Capture](https://attack.mitre.org/techniques/T1125/)|
|
||||
|
||||
Video Capture
|
||||
=============
|
||||
Malware captures video recordings.
|
||||
|
||||
**See ATT&CK:** [**Video Capture**](https://attack.mitre.org/techniques/T1125/).
|
||||
@@ -1,26 +1,25 @@
|
||||
|||
|
||||
|--|-----|
|
||||
|**ID**|**M9004**|
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>OB0004</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
# Command and Control
|
||||
Behaviors malware may use to communicate with systems under its control within a target network. There are many ways malware can establish command and control with various levels of covertness, depending on system configuration and network topology. Behaviors may relate to C2 servers or a bot that is part of a botnet.
|
||||
Behaviors that enable malware to communicate with systems such as C2 servers or bots. Malware can establish command and control with various levels of covertness, depending on system configuration and network topology.
|
||||
|
||||
* **Command and Control Communication** [M0030](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/command-control-comm.md)
|
||||
* **Commonly Used Port** [T1043](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/common-port.md)
|
||||
* **Connection Proxy** [T1090](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/connect-proxy.md)
|
||||
* **Custom Command and Control Protocol** [T1094](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/custom-c2-protocol.md)
|
||||
* **Custom Cryptographic Protocol** [T1024](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/custom-crypto-protocol.md)
|
||||
* **Data Encoding** [T1132](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/data-encode.md)
|
||||
* **Data Obfuscation** [T1001](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/data-obfuscate.md)
|
||||
* **Domain Name Generation** [M0031](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/domain-name-generate.md)
|
||||
* **Fallback Channels** [T1008](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/fallback-channels.md)
|
||||
* **Multi-hop Proxy** [T1188](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/multihop-proxy.md)
|
||||
* **Multi-Stage Channels** [T1104](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/multi-stage-channels.md)
|
||||
* **Port Knocking** [T1205](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/port-knocking.md)
|
||||
* **Remote Access Tools** [T1219](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/remote-access-tools.md)
|
||||
* **Remote File Copy** [E1105](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/remote-file-copy.md)
|
||||
* **Standard Application Layer Protocol** [T1071](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/std-app-protocol.md)
|
||||
* **Standard Cryptographic Protocol** [T1032](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/std-crypto-protocol.md)
|
||||
* **Standard Non-Application Layer Protocol** [T1095](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/std-non-app-protocol.md)
|
||||
* **Uncommonly Used Port** [T1065](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/uncommon-port.md)
|
||||
* **Web Service** [T1102](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/web-service.md)
|
||||
* **Command and Control Communication** [B0030](../command-and-control/c2-communication.md)
|
||||
* **Domain Name Generation** [B0031](../command-and-control/domain-name-generation.md)
|
||||
* **Ingress Tool Transfer** [E1105](../command-and-control/ingress-tool-transfer.md)
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**TrickBot**](../command-and-control/README.md)|2016| new email addresses are collected automatically from the victim's address books [[1]](#1)|
|
||||
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.bitdefender.com/blog/labs/trickbot-is-dead-long-live-trickbot/
|
||||
|
||||
@@ -0,0 +1,94 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0030</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../command-and-control">Command and Control</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
C2 Communication
|
||||
================
|
||||
All command and control malware use implant/controller communication. The methods listed below can be used to capture explicit communication details. Remote file copy behavior is captured separately, as is done in ATT&CK - see **Ingress Tool Transfer ([E1105](../command-and-control/ingress-tool-transfer.md))**.
|
||||
|
||||
Command and Control Communication relates to *autonomous* communications, not explicit, on-demand commands that malware provides to an adversary (such commands should be captured with [Remote Commands](../execution/remote-commands.md) under the Execution objective).
|
||||
|
||||
As "server" and "client" are confusing terminology, we use the terms "controller" and "implant". The controller is the software running on adversary-controlled infrastructure and used to send commands to the implant. The implant is the software running on victim-controlled infrastructure that receives commands from the adversary, executes those commands on the victim, and optionally sends the results back to the adversary.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Authenticate**|B0030.011|Implant may authenticate itself to the controller, controller may authenticate itself to implant, or both. This is often at or near the start of communication. Examples include but are not limited to a simple shared secret (e.g. password), challenge-response with symmetric encryption, or challenge-response with asymmetric encryption.|
|
||||
|**Check for Payload**|B0030.005|An implant may check with the controller for additional payloads or instructions, sometimes at a regular interval. This is also known as beaconing.|
|
||||
|**Directory Listing**|B0030.012|Controller requests a directory listing from the implant, optionally from a given path, optionally recursive.|
|
||||
|**Execute File**|B0030.013|Execute/run/open the file using default operating system functionality, optionally with provided command-and-scripting-interpreter arguments. The file may or may not already exist on the victim.|
|
||||
|**Execute Shell Command**|B0030.014|Execute/run the given command using a built-in program (e.g. cmd.exe, PowerShell, bash). This differs from Start Interactive Shell because the shell process is started only for the received command or set of commands and then exits. There is no loop looking for additional commands while the shell process is still running.|
|
||||
|**File search**|B0030.015|Controller requests the implant to search for a given filename pattern, often a [glob](https://en.wikipedia.org/wiki/Glob_(programming)).|
|
||||
|**Implant to Controller File Transfer**|B0030.004|File is transferred from implant to controller.|
|
||||
|**Receive Data**|B0030.002|Receive data or command from a controller.|
|
||||
|**Request Command**|B0030.008|Implant requests a command.|
|
||||
|**Request Email Address List**|B0030.010|Request email address list.|
|
||||
|**Request Email Template**|B0030.009|Request email template.|
|
||||
|**Send Data**|B0030.001|Send data to a controller.|
|
||||
|**Send Heartbeat**|B0030.007|Heartbeat sent.|
|
||||
|**Send System Information**|B0030.006|Implant sends system information.|
|
||||
|**Server to Client File Transfer**|B0030.003|File is transferred from controller to implant.|
|
||||
|**Start Interactive Shell**|B0030.016|Start an interactive shell using a built-in program (e.g. cmd.exe, PowerShell, bash). This is often implemented with polling the network connection from the controller for text commands to redirect to the shell's stdin and polling the shell's stdout and stderr to redirect over the network to the controller. This differs from Execute Shell Command because the shell process runs across multiple iterations of the recv-command(s)-send-result loop.|
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**CryptoWall**](../xample-malware/cryptowall.md)|2014|The malware sends a hash value generated from system information [[1]](#1)|
|
||||
|[**GotBotKR**](../xample-malware/gotbotkr.md)|2019|GoBotKR receives data from the C2 [[2]](#2)|
|
||||
|[**Terminator**](../xample-malware/terminator.md)|2013|The malware sends data to C2 [[3]](#3)|
|
||||
|[**UP007**](../xample-malware/up007.md)|2016|The malware receives payloads [[4]](#4)|
|
||||
|[**YiSpecter**](../xample-malware/yispecter.md)|2015|Connects to the command and control server using HTTP to send device information [[5]](#5)|
|
||||
|[**Ursnif**](../xample-malware/ursnif.md)|2016|Ursnif variant Dreambot authenticates and encrypts traffic to C2 server using TOR [[6]](#6)|
|
||||
|[**Emotet**](../xample-malware/emotet.md)|2018|New email addresses are collected automatically from the victim's address books [[7]](#7)|
|
||||
|
||||
|
||||
Code Snippets
|
||||
-------------
|
||||
**C2 Communication::Receive Data** (B0030.02)
|
||||
<br/>MD5: b6e1a2048ea6bd6a941a72300b2d41ce
|
||||
```asm
|
||||
loc_401981
|
||||
mov ecx, s
|
||||
mov edx, edi
|
||||
sub edx, esi
|
||||
push 0 ; flags
|
||||
lea eax, [esi+ebx]
|
||||
push edx ;len
|
||||
push eax ;buf
|
||||
push ecx ;s
|
||||
call recv
|
||||
jmp short loc_4019A2
|
||||
```
|
||||
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://news.sophos.com/en-us/2015/12/17/the-current-state-of-ransomware-cryptowall/
|
||||
|
||||
<a name="2">[2]</a> https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/
|
||||
|
||||
<a name="3">[3]</a> https://www.mandiant.com/resources/hot-knives-through-butter-evading-file-based-sandboxes
|
||||
|
||||
<a name="4">[4]</a> https://citizenlab.ca/2016/04/between-hong-kong-and-burma/
|
||||
|
||||
<a name="5">[5]</a> http://researchcenter.paloaltonetworks.com/2015/10/yispecter-first-ios-malware-attacks-non-jailbroken-ios-devices-by-abusing-private-apis/
|
||||
|
||||
<a name="6">[6]</a> https://www.proofpoint.com/us/threat-insight/post/ursnif-variant-dreambot-adds-tor-functionality
|
||||
|
||||
<a name="7">[7]</a> https://securelist.com/the-banking-trojan-emotet-detailed-analysis/69560/
|
||||
@@ -1,20 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**M0030**|
|
||||
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
C2 Communication
|
||||
================
|
||||
All command and control malware use client/server communication. The methods listed below can be used to capture explicit communication details. Remote file copy behavior is captured separately, as is done in ATT&CK - see [Remote File Copy](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/remote-file-copy.md).
|
||||
|
||||
Command and Control Communication relates to *autonomous* client/server communications, not explicit, on-demand commands that malware provides to an adversary (such commands should be captured with [Remote Commands](https://github.com/MBCProject/mbc-markdown/blob/master/execution/remote-commands.md) under the Execution objective).
|
||||
|
||||
Methods
|
||||
-------
|
||||
* **Check for Payload**
|
||||
* **Send System Information**
|
||||
* **Send Heartbeat**
|
||||
* **Request Command**
|
||||
* **Request Email Template**
|
||||
* **Request Email Address List**
|
||||
@@ -1,18 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1043**|
|
||||
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|
||||
|**Related ATT&CK Technique**|[Commonly Used Port](https://attack.mitre.org/techniques/T1043/), [Commonly Used Port - Mobile](https://attack.mitre.org/techniques/T1436/)|
|
||||
|
||||
Commonly Used Port
|
||||
==================
|
||||
Malware may use a common port to avoid detection of command and control activity.
|
||||
|
||||
**See ATT&CK:** [**Commonly Used Port**](https://attack.mitre.org/techniques/T1043/) and [**Commonly Used Port (Mobile)**](https://attack.mitre.org/techniques/T1436/).
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|-----------|-----------------------------|
|
||||
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1090**|
|
||||
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|
||||
|**Related ATT&CK Technique**|[Connection Proxy](https://attack.mitre.org/techniques/T1090/)|
|
||||
|
||||
Connection Proxy
|
||||
================
|
||||
Malware may use a connection proxy to manage command and control communications.
|
||||
|
||||
**See ATT&CK:** [**Connection Proxy**](https://attack.mitre.org/techniques/T1090/).
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1094**|
|
||||
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|
||||
|**Related ATT&CK Technique**|[Custom Command and Control Protocol](https://attack.mitre.org/techniques/T1094/)|
|
||||
|
||||
Custom Command and Control Protocol
|
||||
===================================
|
||||
Malware may use a custom command and control protocol instead of encapsulating commands and data in a [Standard Application Layer Protocol](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control/std-protocol.md).
|
||||
|
||||
**See ATT&CK:** [**Custom Command and Control Protocol**](https://attack.mitre.org/techniques/T1094/).
|
||||
@@ -1,17 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1024**|
|
||||
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|
||||
|**Related ATT&CK Technique**|[Custom Cryptographic Protocol](https://attack.mitre.org/techniques/T1024/)|
|
||||
|
||||
Custom Cryptographic Protocol
|
||||
=============================
|
||||
Malware may use a custom cryptographic protocol to hide command and control communications.
|
||||
|
||||
**See ATT&CK:** [**Custom Cryptographic Protocol**](https://attack.mitre.org/techniques/T1024/).
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|-----------|-----------------------------|
|
||||
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1132**|
|
||||
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|
||||
|**Related ATT&CK Technique**|[Data Encoding](https://attack.mitre.org/techniques/T1132/)|
|
||||
|
||||
Data Encoding
|
||||
=============
|
||||
Malware encodes its command and control information using a standard system such as Unicode, Base64, etc.
|
||||
|
||||
**See ATT&CK:** [**Data Encoding**](https://attack.mitre.org/techniques/T1132/).
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1001**|
|
||||
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|
||||
|**Related ATT&CK Technique**|[Data Obfuscation](https://attack.mitre.org/techniques/T1001/)|
|
||||
|
||||
Data Obfuscation
|
||||
================
|
||||
Malware hides its command and control information.
|
||||
|
||||
**See ATT&CK:** [**Data Obfuscation**](https://attack.mitre.org/techniques/T1001/).
|
||||
@@ -1,26 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**M0031**|
|
||||
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|
||||
|**Related ATT&CK Technique**|[Domain Generation Algorithms](https://attack.mitre.org/techniques/T1483/)|
|
||||
|
||||
Domain Name Generation
|
||||
======================
|
||||
Malware generates the domain name of the command and control server to which it connects. Access to on the fly domains enables C2 to operate as domains and IP addresses are blocked. The algorithm can be complicated in more advanced bots; understanding the details so that names can be predicted can be useful in mitigation and response. [[1]](#1)
|
||||
|
||||
The subsequently defined ATT&CK technique [Domain Generation Algorithms](https://attack.mitre.org/techniques/T1483/), which is oriented toward an adversary perspective (although its examples include malware), is related to this MBC behavior.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|--------|-----------------------------|
|
||||
|[**Kraken**](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/kraken.md) | April 2008 | Kraken uses a domain generating algorithm to provide new domains. [[2]](#2)|
|
||||
|[**Conficker**](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/conficker.md)| November 2008| Conficker uses a domain name generator. [[3]](#3)
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://blog.malwarebytes.com/security-world/2016/12/explained-domain-generating-algorithm/
|
||||
|
||||
<a name="2">[2]</a> http://blog.threatexpert.com/2008/04/kraken-changes-tactics.html
|
||||
|
||||
<a name="3">[3]</a> https://en.wikipedia.org/wiki/Conficker
|
||||
@@ -0,0 +1,43 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0031</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../command-and-control">Command and Control</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Dynamic Resolution: Domain Generation Algorithms (<a href="https://attack.mitre.org/techniques/T1568/002/">T1568.002</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Domain Name Generation
|
||||
======================
|
||||
Malware generates the domain name of the controller to which it connects. Access to on the fly domains enables C2 to operate as domains and IP addresses are blocked. The algorithm can be complicated in more advanced implants; understanding the details so that names can be predicted can be useful in mitigation and response. [[1]](#1)
|
||||
|
||||
The related **Dynamic Resolution: Domain Generation Algorithms ([T1568.002](https://attack.mitre.org/techniques/T1568/002/))** ATT&CK sub-technique (oriented toward an adversary perspective with examples that include malware) was defined subsequent to this MBC behavior.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Kraken**](../xample-malware/kraken.md)|April 2008|Kraken uses a domain generating algorithm to provide new domains. [[2]](#2)|
|
||||
|[**Conficker**](../xample-malware/conficker.md)|November 2008|Conficker uses a domain name generator. [[3]](#3)|
|
||||
|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|The malware sends a hash value generated from system information [[4]](#4|
|
||||
|[**Ursnif**](../xample-malware/ursnif.md)|2016|Ursnif has used a Domain name generation algorithm in the past [[5]](#5)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://blog.malwarebytes.com/security-world/2016/12/explained-domain-generating-algorithm/
|
||||
|
||||
<a name="2">[2]</a> http://blog.threatexpert.com/2008/04/kraken-changes-tactics.html
|
||||
|
||||
<a name="3">[3]</a> https://en.wikipedia.org/wiki/Conficker
|
||||
|
||||
<a name="4">[4]</a> https://www.secureworks.com/research/cryptolocker-ransomware
|
||||
|
||||
<a name="5">[5]</a> https://www.proofpoint.com/us/threat-insight/post/ursnif-variant-dreambot-adds-tor-functionality
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1008**|
|
||||
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|
||||
|**Related ATT&CK Technique**|[Fallback Channels](https://attack.mitre.org/techniques/T1008/)|
|
||||
|
||||
Fallback Channels
|
||||
=================
|
||||
Malware may contain a secondary command and control server or may communicate over a backup channel.
|
||||
|
||||
**See ATT&CK:** [**Fallback Channels**](https://attack.mitre.org/techniques/T1008/).
|
||||
@@ -0,0 +1,47 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1105</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../command-and-control">Command and Control</a>, <a href="../lateral-movement">Lateral Movement</a>, <a href="../persistence">Persistence</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Ingress Tool Transfer (<a href="https://attack.mitre.org/techniques/T1105/">T1105</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Ingress Tool Transfer
|
||||
================
|
||||
Malware may copy files from an external system to a system on a compromised network.
|
||||
|
||||
Note that this behavior is separate from possible execution (installation) of the file, which is covered by the **Install Additional Program ([B0023](../execution/install-additional-program.md))** behavior.
|
||||
|
||||
See ATT&CK: **Ingress Tool Transfer ([T1105](https://attack.mitre.org/techniques/T1105/))**.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|After the Poison-Ivy implant is running on the target machine, the attacker can use a Windows GUI controller to control the target computer. [[1]](#1)|
|
||||
|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|The malware receives a public key from the C2 [[2]](#2)|
|
||||
|[**Gamut**](../xample-malware/gamut.md)|2014|The malware receives data from C2 [[3]](#3)|
|
||||
|[**DarkComet**](../xample-malware/dark-comet.md)|2008|Can download files from remote repository upon instruction [[4]](#4)|
|
||||
|[**Shamoon**](../xample-malware/shamoon.md)|2012|Creates a folder on remote computers and then copies its executables (Shamoon and Filerase) into that directory [[5]](#5)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
|
||||
|
||||
<a name="2">[2]</a> https://www.secureworks.com/research/cryptolocker-ransomware
|
||||
|
||||
<a name="3">[3]</a> https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/gamut-spambot-analysis/
|
||||
|
||||
<a name="4">[4]</a> https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/
|
||||
|
||||
<a name="5">[5]</a> https://www.mcafee.com/blogs/other-blogs/mcafee-labs/shamoon-attackers-employ-new-tool-kit-to-wipe-infected-systems/
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1104**|
|
||||
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|
||||
|**Related ATT&CK Technique**|[Multi-Stage Channels](https://attack.mitre.org/techniques/T1104/)|
|
||||
|
||||
Multi-Stage Channels
|
||||
====================
|
||||
Malware may create multiple stages for command and control, making detection more difficult.
|
||||
|
||||
**See ATT&CK:** [**Multi-Stage Channels**](https://attack.mitre.org/techniques/T1104/).
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1188**|
|
||||
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|
||||
|**Related ATT&CK Technique**|[Multi-hop Proxy](https://attack.mitre.org/techniques/T1188/)|
|
||||
|
||||
Multi-hop Proxy
|
||||
===============
|
||||
Malware may chain together multiple proxies to disguise the source of malicious C2 traffic.
|
||||
|
||||
**See ATT&CK:** [**Multi-hop Proxy**](https://attack.mitre.org/techniques/T1188/).
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1205**|
|
||||
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control), [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion), [Persistence](https://github.com/MBCProject/mbc-markdown/tree/master/persistence)|
|
||||
|**Related ATT&CK Technique**|[Port Knocking](https://attack.mitre.org/techniques/T1205/)|
|
||||
|
||||
Port Knocking
|
||||
=============
|
||||
Malware may hide open ports.
|
||||
|
||||
**See ATT&CK:** [**Port Knocking**](https://attack.mitre.org/techniques/T1205/).
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1219**|
|
||||
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|
||||
|**Related ATT&CK Technique**|[Remote Access Tools](https://attack.mitre.org/techniques/T1219/)|
|
||||
|
||||
Remote Access Tools
|
||||
===================
|
||||
Malware may use legitimate desktop support and remote access software to establish an interactive command and control channel to target systems.
|
||||
|
||||
**See ATT&CK:** [**Remote Access Tools**](https://attack.mitre.org/techniques/T1219/).
|
||||
@@ -1,24 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**E1105**|
|
||||
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control), [Lateral Movement](https://github.com/MBCProject/mbc-markdown/tree/master/lateral-movement), [Persistence](https://github.com/MBCProject/mbc-markdown/tree/master/persistence)|
|
||||
|**Related ATT&CK Technique**|[Remote File Copy](https://attack.mitre.org/techniques/T1105/)|
|
||||
|
||||
Remote File Copy
|
||||
================
|
||||
Malware may copy files from one system to another.
|
||||
|
||||
Note that this behavior is separate from possible execution (installation) of the file, which is covered by the [Install Additional Program](https://github.com/MBCProject/mbc-markdown/blob/master/execution/install-prog.md) behavior.
|
||||
|
||||
**See ATT&CK:** [**Remote File Copy**](https://attack.mitre.org/techniques/T1105/).
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|-----------|-----------------------------|
|
||||
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
|[**Poison-Ivy**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/poison-ivy.md)|2005|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[1]](#1)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
|
||||
@@ -1,17 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1071**|
|
||||
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|
||||
|**Related ATT&CK Technique**|[Standard Application Layer Protocol](https://attack.mitre.org/techniques/T1071/)|
|
||||
|
||||
Standard Application Layer Protocol
|
||||
===================================
|
||||
Malware may use a standard application layer protocol (e.g., HTTP) to blend with usual traffic.
|
||||
|
||||
**See ATT&CK:** [**Standard Application Layer Protocol**](https://attack.mitre.org/techniques/T1071/).
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|-----------|-----------------------------|
|
||||
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
@@ -1,21 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1032**|
|
||||
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|
||||
|**Related ATT&CK Technique**|[Standard Cryptographic Protocol](https://attack.mitre.org/techniques/T1032/)|
|
||||
|
||||
Standard Cryptographic Protocol
|
||||
===============================
|
||||
Malware may use a standard cryptographic protocol to conceal command and control traffic or other data.
|
||||
|
||||
**See ATT&CK:** [**Standard Cryptographic Protocol**](https://attack.mitre.org/techniques/T1032/).
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|--------|-----------------------------|
|
||||
|[**Poison-Ivy**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/poison-ivy.md)|2005|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[1]](#1)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1095**|
|
||||
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|
||||
|**Related ATT&CK Technique**|[Standard Non-Application Layer Protocol](https://attack.mitre.org/techniques/T1095/)|
|
||||
|
||||
Standard Non-Application Layer Protocol
|
||||
=======================================
|
||||
Malware may use a standard non-application layer protocol (e.g., ICMP) because such protocols may be less commonly monitored, enabling communication to be hidden.
|
||||
|
||||
**See ATT&CK:** [**Standard Non-Application Layer Protocol**](https://attack.mitre.org/techniques/T1095/).
|
||||
@@ -1,22 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1065**|
|
||||
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|
||||
|**Related ATT&CK Technique**|[Uncommonly Used Port](https://attack.mitre.org/techniques/T1065/)|
|
||||
|
||||
Uncommonly Used Port
|
||||
====================
|
||||
Malware may use an uncommon port to bypass poorly configured boundary controllers.
|
||||
|
||||
**See ATT&CK:** [**Uncommonly Used Port**](https://attack.mitre.org/techniques/T1065/).
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|-----------|-----------------------------|
|
||||
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
|[**Poison-Ivy**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/poison-ivy.md)|2005|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[1]](#1)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1102**|
|
||||
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control), [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion)|
|
||||
|**Related ATT&CK Technique**|[Web Service](https://attack.mitre.org/techniques/T1102/)|
|
||||
|
||||
Web Service
|
||||
===========
|
||||
Malware may use existing external Web services for relaying C2 commands.
|
||||
|
||||
**See ATT&CK:** [**Web Service**](https://attack.mitre.org/techniques/T1102/).
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1171**|
|
||||
|**Objective(s)**|[Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access)|
|
||||
|**Related ATT&CK Technique**|[LLMNR/NBT-NS Poisoning](https://attack.mitre.org/techniques/T1171/)|
|
||||
|
||||
LLMNR/NBT-NS Poisoning
|
||||
======================
|
||||
Link-Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service (NBT-NS) are Microsoft Windows components that serve as alternate methods of host identification. Malware may spoof an authoritative source, poisoning the service.
|
||||
|
||||
**See ATT&CK:** [**LLMNR/NBT-NS Poisoning**](https://attack.mitre.org/techniques/T1171/).
|
||||
+11
-16
@@ -1,19 +1,14 @@
|
||||
|||
|
||||
|--|-----|
|
||||
|**ID**|**M9005**|
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>OB0006</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
# Credential Access
|
||||
Behaviors to obtain credential access, allowing it or its underlying threat actor to assume control of an account, with the associated system and network permissions.
|
||||
Behaviors to obtain credential access, allowing it or its underlying threat actor to assume control of an account with the associated system and network permissions.
|
||||
|
||||
* **Access Sensitive Data or Credentials in Files** [T1409](https://github.com/MBCProject/mbc-markdown/blob/master/collection/access-sensitive-data.md)
|
||||
* **Account Manipulation** [T1098](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/acct-manipulate.md)
|
||||
* **Capture SMS Messages** [T1412](https://github.com/MBCProject/mbc-markdown/blob/master/collection/capture-sms.md)
|
||||
* **Credential Dumping** [T1003](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/credential-dump.md)
|
||||
* **Credentials in Files** [T1081](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/credentials-in-files.md)
|
||||
* **Credentials in Registry** [T1214](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/credentials-in-registry.md)
|
||||
* **Credentials in Web Browsers** [T1503](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/credentials-in-web-browsers.md)
|
||||
* **Hooking** [E1179](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/hooking.md)
|
||||
* **Input Capture** [T1056](https://github.com/MBCProject/mbc-markdown/blob/master/collection/input-capture.md)
|
||||
* **LLMNR/NBT-NS Poisoning** [T1171](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/LLMNR-poison.md)
|
||||
* **Network Sniffing** [T1040](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/network-sniff.md)
|
||||
* **Private Keys** [T1145](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/private-keys.md)
|
||||
* **Cryptocurrency** [B0028](../collection/cryptocurrency.md)
|
||||
* **Input Capture** [E1056](../collection/input-capture.md)
|
||||
* **Keylogging** [F0002](../collection/keylogging.md)
|
||||
* **Screen Capture** [E1113](../collection/screen-capture.md)
|
||||
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1098**|
|
||||
|**Objective(s)**|[Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access)|
|
||||
|**Related ATT&CK Technique**|[Account Manipulation](https://attack.mitre.org/techniques/T1098/)|
|
||||
|
||||
Account Manipulation
|
||||
====================
|
||||
Malware may manipulate accounts to maintain access to credentials or permission levels.
|
||||
|
||||
**See ATT&CK:** [**Account Manipulation**](https://attack.mitre.org/techniques/T1098/).
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1003**|
|
||||
|**Objective(s)**|[Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access)|
|
||||
|**Related ATT&CK Technique**|[Credential Dumping](https://attack.mitre.org/techniques/T1003/)|
|
||||
|
||||
Credential Dumping
|
||||
==================
|
||||
Malware may obtain account login and password information.
|
||||
|
||||
**See ATT&CK:** [**Credential Dumping**](https://attack.mitre.org/techniques/T1003/).
|
||||
@@ -1,17 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1081**|
|
||||
|**Objective(s)**|[Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access)|
|
||||
|**Related ATT&CK Technique**|[Credentials in Files](https://attack.mitre.org/techniques/T1081/)|
|
||||
|
||||
Credentials in Files
|
||||
====================
|
||||
Malware may search local file system and remote file shares for files containing passwords.
|
||||
|
||||
**See ATT&CK:** [**Credentials in Files**](https://attack.mitre.org/techniques/T1081/).
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|-----------|-----------------------------|
|
||||
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
@@ -1,17 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1214**|
|
||||
|**Objective(s)**|[Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access)|
|
||||
|**Related ATT&CK Technique**|[Credentials in Registry](https://attack.mitre.org/techniques/T1214/)|
|
||||
|
||||
Credentials in Registry
|
||||
=======================
|
||||
Malware may query the Registry looking for credentials and passwords.
|
||||
|
||||
**See ATT&CK:** [**Credentials in Registry**](https://attack.mitre.org/techniques/T1214/).
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|-----------|-----------------------------|
|
||||
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
@@ -1,17 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1503**|
|
||||
|**Objective(s)**|[Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access)|
|
||||
|**Related ATT&CK Technique**|[Credentials in Web Browsers](https://attack.mitre.org/techniques/T1503/)|
|
||||
|
||||
Credentials in Web Browsers
|
||||
===========================
|
||||
Malware may acquire credentials from web browsers by reading files specific to the target browser.
|
||||
|
||||
**See ATT&CK:** [**Credentials in Web Browsers**](https://attack.mitre.org/techniques/T1503/).
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|-----------|-----------------------------|
|
||||
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
@@ -1,37 +0,0 @@
|
||||
|||
|
||||
|------------------|------------------------|
|
||||
|**ID**|**E1179**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis), [Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access), [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion), [Persistence](https://github.com/MBCProject/mbc-markdown/tree/master/persistence), [Privilege Escalation](https://github.com/MBCProject/mbc-markdown/tree/master/privilege-escalation)|
|
||||
|**Related ATT&CK Technique**|[Hooking](https://attack.mitre.org/techniques/T1179/)|
|
||||
|
||||
|
||||
Hooking
|
||||
=======
|
||||
Malware alters API behavior or redirects execution to a malicious API version for a variety of purposes. Malware may use hooking to load and execute code within the context of another process, hiding execution and gaining elevated privileges and access to the process's memory. Methods related to anti-behavioral analysis are below. For example, hooking can be used to prevent memory dumps - see also [Memory Dump Obstruction](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/memory-dump-obstruct.md).
|
||||
|
||||
For discussion related to the Credential Access, Persistence, and Privilege Escalation objectives, see ATT&CK: [**Hooking**](https://attack.mitre.org/techniques/T1179/).
|
||||
|
||||
Note that in MBC, but not in ATT&CK, Hooking is also associated with the [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion) and [Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis) objectives.
|
||||
|
||||
Methods
|
||||
-------
|
||||
* **Patch MmGetPhysicalMemoryRanges**: Patching this function to always return NULL prevents drivers from getting information about the physical address space layout, preventing memory dumps. [[1]](#1)
|
||||
* **Hook memory mapping APIs**: Prevents memory dumps by preventing mapping of memory into the kernel's virtual address space. [[1]](#1)
|
||||
* **Hook procedures**: Intercepts and executes designated code in response to events such as messages, keystrokes, and mouse inputs. [[3]](#3)
|
||||
* **Import Address Hooking (IAT) Hooking**: uses modifications to a process's IAT where pointers to imported API functions are stored.
|
||||
* **Inline Hooking**: overwrites the first bytes in an API function to redirect code flow.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|-----------|-----------------------------|
|
||||
|**Kronos**|June 2014 |Kronos hooks the API of processes to prevent detection. [[2]](#2)|
|
||||
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> J. Stuttgen, M. Cohen, Anti-forensic resilient memory acquisition, www.dfrws.org/sites/default/files/session-files/paper-anti-forensic_resilient_memory_acquisition.pdf
|
||||
|
||||
<a name="2">[2]</a> https://blog.malwarebytes.com/cybercrime/2017/08/inside-kronos-malware/
|
||||
|
||||
<a name="3">[3]</a> https://docs.microsoft.com/en-us/windows/win32/winmsg/about-hooks?redirectedfrom=MSDN#hook-procedures
|
||||
@@ -1,11 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1145**|
|
||||
|**Objective(s)**|[Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access)|
|
||||
|**Related ATT&CK Technique**|[Private Keys](https://attack.mitre.org/techniques/T1145/)|
|
||||
|
||||
Private Keys
|
||||
============
|
||||
Malware may gather private keys from compromised systems.
|
||||
|
||||
**See ATT&CK:** [**Private Keys**](https://attack.mitre.org/techniques/T1145/).
|
||||
+27
-51
@@ -1,54 +1,30 @@
|
||||
|||
|
||||
|--|-----|
|
||||
|**ID**|**M9006**|
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>OB0006</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
# Defense Evasion #
|
||||
Behaviors that evade detection or avoid other defenses.
|
||||
Behaviors that enable malware to evade detection.
|
||||
|
||||
* **Access Token Manipulation** [T1134](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/access-token.md)
|
||||
* **Alternative Installation Location** [M0027](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/alter-install-location.md)
|
||||
* **Application Discovery** [T1418](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/app-discover.md)
|
||||
* **Binary Padding** [T1009](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/binary-pad.md)
|
||||
* **BITS Jobs** [T1197](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/bits-jobs.md)
|
||||
* **Boot Sector Modification** [M0028](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/boot-sector-mod.md)
|
||||
* **Bypass User Account Control** [T1088](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/bypass-user-acct-cntl.md)
|
||||
* **Code Signing** [T1116](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/code-signing.md)
|
||||
* **Component Object Model Hijacking** [T1122](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/component-hijack.md)
|
||||
* **Configuration Modification** [E1478](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/config-mod.md)
|
||||
* **DCShadow** [T1207](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/dcshadow.md)
|
||||
* **Deobfuscate/Decode Files or Information** [T1140](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/deobfuscate-files.md)
|
||||
* **Disabling Security Tools** [E1089](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/disable-security-tools.md)
|
||||
* **DLL Search Order Hijacking** [T1038](https://github.com/MBCProject/mbc-markdown/blob/master/privilege-escalation/dll-search-order-hijack.md)
|
||||
* **Execution Guardrails** [E1480](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/execution-guardrails.md)
|
||||
* **Exploitation for Defense Evasion** [T1211](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/exploit-for-defense.md)
|
||||
* **File Deletion** [E1107](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/file-deletion.md)
|
||||
* **File Permissions Modification** [T1222](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/file-permission-mod.md)
|
||||
* **File System Logical Offsets** [T1006](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/file-sys-logical-offset.md)
|
||||
* **Hidden Files and Directories** [E1158](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/hidden-files.md)
|
||||
* **Hidden Window** [T1143](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/hidden-window.md)
|
||||
* **HISTCONTROL** [T1148](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/histcontrol.md)
|
||||
* **Hooking** [E1179](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/hooking.md)
|
||||
* **Image File Execution Options Injection** [T1183](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/image-file-exe-opt-inj.md)
|
||||
* **Indicator Blocking** [E1054](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/indicator-blocking.md)
|
||||
* **Indicator Removal on Host** [T1070](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/indicator-remove-host.md)
|
||||
* **Indirect Command Execution** [T1202](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/indirect-command.md)
|
||||
* **Install Root Certificate** [T1130](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/install-root-cert.md)
|
||||
* **Masquerading** [T1036](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/masquerading.md)
|
||||
* **Modify Registry** [E1112](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/modify-reg.md)
|
||||
* **Modify Trusted Execution Environment** [T1399](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/mod-trust-exe-environ.md)
|
||||
* **NTFS File Attributes** [T1096](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/ntfs-file-attr.md)
|
||||
* **Obfuscated Files or Information** [E1027](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/obfuscate-files.md)
|
||||
* **Parent PID Spoofing** [T1502](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/parent-pid-spoof.md)
|
||||
* **Polymorphic Code** [M0029](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/polymorphic-code.md)
|
||||
* **Port Knocking** [T1205](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/port-knocking.md)
|
||||
* **Process Hollowing** [T1093](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/process-hollow.md)
|
||||
* **Process Injection** [E1055](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/process-inject.md)
|
||||
* **Redundant Access** [T1008](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/redundant-access.md)
|
||||
* **Regsvr32** [T1117](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/regsvr32.md)
|
||||
* **Rundll32** [T1085](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/rundll32.md)
|
||||
* **Rootkit Behavior** [E1014](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/rootkit-behavior.md)
|
||||
* **Scripting** [T1064](https://github.com/MBCProject/mbc-markdown/blob/master/execution/scripting.md)
|
||||
* **Software Packing** [E1045](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/software-packing.md)
|
||||
* **Timestomp** [T1099](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/timestomp.md)
|
||||
* **Virtualization/Sandbox Evasion** [T1497](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/virtualization-sandbox-evade.md)
|
||||
* **Web Service** [T1102](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/web-service.md)
|
||||
* **Alternative Installation Location** [B0027](../defense-evasion/alternative-installation-location.md)
|
||||
* **Bootkit** [F0013](../defense-evasion/bootkit.md)
|
||||
* **Bypass DEP** [B0037](../defense-evasion/bypass-data-execution-prevention.md)
|
||||
* **Component Firmware** [F0009](../persistence/component-firmware.md)
|
||||
* **Conditional Execution** [B0025](../execution/conditional-execution.md)
|
||||
* **Covert Location** [B0040](../defense-evasion/covert-location.md)
|
||||
* **Disable or Evade Security Tools** [F0004](../defense-evasion/disable-or-evade-security-tools.md)
|
||||
* **Hide Artifacts** [E1564](../defense-evasion/hide-artifacts.md)
|
||||
* **Hidden Files and Directories** [F0005](../defense-evasion/hidden-files-and-directories.md)
|
||||
* **Hijack Execution Flow** [F0015](../defense-evasion/hijack-execution-flow.md)
|
||||
* **Indicator Blocking** [F0006](../defense-evasion/indicator-blocking.md)
|
||||
* **Install Insecure or Malicious Configuration** [B0047](../defense-evasion/install-insecure-or-malicious-configuration.md)
|
||||
* **Modify Registry** [E1112](../defense-evasion/modify-registry.md)
|
||||
* **Obfuscated Files or Information** [E1027](../defense-evasion/obfuscated-files-or-information.md)
|
||||
* **Polymorphic Code** [B0029](../defense-evasion/polymorphic-code.md)
|
||||
* **Process Injection** [E1055](../defense-evasion/process-injection.md)
|
||||
* **Rootkit** [E1014](../defense-evasion/rootkit.md)
|
||||
* **Self Deletion** [F0007](../defense-evasion/self-deletion.md)
|
||||
* **Software Packing** [F0001](../anti-static-analysis/software-packing.md)
|
||||
|
||||
@@ -1,12 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1134**|
|
||||
|**Objective(s)**| [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion)|
|
||||
|**Related ATT&CK Technique**|[Access Token Manipulation](https://attack.mitre.org/techniques/T1134)|
|
||||
|
||||
|
||||
Access Token Manipulation
|
||||
=========================
|
||||
Malware manipulates access tokens to make a running process appear as thought it belongs to someone other than the user who started the process.
|
||||
|
||||
See ATT&CK: [**Access Token Manipulation**](https://attack.mitre.org/techniques/T1134).
|
||||
@@ -1,25 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**M0027**|
|
||||
|**Objective(s)**| [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
|
||||
Alternative Installation Location
|
||||
=================================
|
||||
Malware may install itself not as a file on the hard drive. [[1]](#1)
|
||||
|
||||
Methods
|
||||
-------
|
||||
* **Fileless Malware**: Stores itself in memory.
|
||||
* **Registry Install**: Stores itself in the Windows registry.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|--------|-----------------------------|
|
||||
|[**Kovter**](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/kovter.md)|2016|Stores malware files in the Registry instead of the hard drive. [[1]](#1)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.bleepingcomputer.com/virus-removal/remove-kovter-trojan
|
||||
@@ -0,0 +1,40 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0027</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../defense-evasion">Defense Evasion</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Alternative Installation Location
|
||||
=================================
|
||||
Malware may install itself not as a file on the hard drive. [[1]](#1)
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Fileless Malware**|B0027.001|Stores itself in memory.|
|
||||
|**Registry Install**|B0027.002|Stores itself in the Windows registry.|
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Kovter**](../xample-malware/kovter.md)|2016|Stores malware files in the Registry instead of the hard drive. [[1]](#1)|
|
||||
|[**SYNfulKnock**](../xample-malware/synful-knock.md)|2015|100 memory-resident modules can be installed [[2]](#2)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.bleepingcomputer.com/virus-removal/remove-kovter-trojan
|
||||
|
||||
<a name="2">[2]</a> https://www.mandiant.com/resources/synful-knock-acis
|
||||
@@ -1,12 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1009**|
|
||||
|**Objective(s)**| [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion)|
|
||||
|**Related ATT&CK Technique**|[Binary Padding](https://attack.mitre.org/techniques/T1009)|
|
||||
|
||||
|
||||
Binary Padding
|
||||
==============
|
||||
Malware is padded to increase its size beyond what security tools can handle or to change its hash.
|
||||
|
||||
See ATT&CK: [**Binary Padding**](https://attack.mitre.org/techniques/T1009).
|
||||
@@ -1,12 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1197**|
|
||||
|**Objective(s)**| [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion), [Persistence](https://github.com/MBCProject/mbc-markdown/tree/master/persistence)|
|
||||
|**Related ATT&CK Technique**|[BITS Jobs](https://attack.mitre.org/techniques/T1197)|
|
||||
|
||||
|
||||
BITS Jobs
|
||||
=========
|
||||
Malware may abuse Windows Background Intelligent Transfer Service (BITS) to download and/or execute malicious code.
|
||||
|
||||
See ATT&CK: [**BITS Jobs**](https://attack.mitre.org/techniques/T1197).
|
||||
@@ -1,22 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**M0028**|
|
||||
|**Objective(s)**|[Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion), [Persistence](https://github.com/MBCProject/mbc-markdown/tree/master/persistence)|
|
||||
|**Related ATT&CK Technique**|[Bootkit](https://attack.mitre.org/techniques/T1067/)|
|
||||
|
||||
Boot Sector Modification
|
||||
========================
|
||||
The boot sectors of a hard drive are modified (e.g., Master Boot Record (MBR)). ATT&CK associates bootkits with the Persistence. See ATT&CK: [**Bootkit**](https://attack.mitre.org/techniques/T1067/).
|
||||
|
||||
The MBC also associates the Bootkit behavior with Defense Evasion because the malware may execute before or external to the system's kernel or hypervisor (e.g., through the BIOS), making it more difficult to detect.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|-----------|-----------------------------|
|
||||
|[**Mebromi**](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/mebromi.md)|2011|An MBR bootkit and a BIOS bootkit targeting Award BIOS. [[1]](#1)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.webroot.com/blog/2011/09/13/mebromi-the-first-bios-rootkit-in-the-wild/
|
||||
|
||||
@@ -0,0 +1,35 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>F0013</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../defense-evasion">Defense Evasion</a>, <a href="../persistence">Persistence</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Pre-OS Boot: Bootkit (<a href="https://attack.mitre.org/techniques/T1542/003">T1542.003</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Bootkit
|
||||
=======
|
||||
The boot sectors of a hard drive are modified (e.g., Master Boot Record (MBR)). ATT&CK associates bootkits with the Persistence. See ATT&CK: **Pre-OS Boot: Bootkit ([T1067](https://attack.mitre.org/techniques/T1067/))**.
|
||||
|
||||
The MBC also associates the Bootkit behavior with Defense Evasion because the malware may execute before or external to the system's kernel or hypervisor (e.g., through the BIOS), making it more difficult to detect. (As of 2020, ATT&CK also associates the technique with Persistence.)
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Mebromi**](../xample-malware/mebromi.md)|2011|An MBR bootkit and a BIOS bootkit targeting Award BIOS. [[1]](#1)|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Can implement malicious code into firmware, allowing read, write, and/or erasure of the UEFI/BIOS firmware [[2]](#24)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.webroot.com/blog/2011/09/13/mebromi-the-first-bios-rootkit-in-the-wild/
|
||||
|
||||
<a name="2">[2]</a> https://eclypsium.com/wp-content/uploads/2020/12/TrickBot-Now-Offers-TrickBoot-Persist-Brick-Profit.pdf
|
||||
@@ -0,0 +1,38 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0037</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../defense-evasion">Defense Evasion</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Bypass Data Execution Prevention
|
||||
================================
|
||||
Malware may bypass Data Execution Prevention (DEP).
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**ROP Chains**|B0037.001|Return-Oriented Programming can be used to bypass DEP. It can also be used to bypass code signing. [[1]](#1)|
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|TrickBot has come with a signed downloader component [[2]](#2)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://medium.com/cybersecurityservices/dep-bypass-using-rop-chains-garima-chopra-e8b3361e50ce
|
||||
|
||||
<a name="2">[2]</a> https://www.cybereason.com/blog/research/dropping-anchor-from-a-trickbot-infection-to-the-discovery-of-the-anchor-malware
|
||||
@@ -1,12 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1088**|
|
||||
|**Objective(s)**| [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion), [Privilege Escalation](https://github.com/MBCProject/mbc-markdown/tree/master/privilege-escalation)|
|
||||
|**Related ATT&CK Technique**|[Bypass User Account Control](https://attack.mitre.org/techniques/T1088)|
|
||||
|
||||
|
||||
Bypass User Account Control
|
||||
===========================
|
||||
Malware bypasses Windows User Account Control.
|
||||
|
||||
See ATT&CK: [**Bypass User Account Control**](https://attack.mitre.org/techniques/T1088).
|
||||
@@ -1,12 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1116**|
|
||||
|**Objective(s)**| [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion)|
|
||||
|**Related ATT&CK Technique**|[Code Signing](https://attack.mitre.org/techniques/T1116)|
|
||||
|
||||
|
||||
Code Signing
|
||||
============
|
||||
Malware code is digitally signed to appear as legitimate software.
|
||||
|
||||
See ATT&CK: [**Code Signing**](https://attack.mitre.org/techniques/T1116).
|
||||
@@ -1,12 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1122**|
|
||||
|**Objective(s)**| [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion), [Persistence](https://github.com/MBCProject/mbc-markdown/tree/master/persistence)|
|
||||
|**Related ATT&CK Technique**|[Component Object Model Hijacking](https://attack.mitre.org/techniques/T1122)|
|
||||
|
||||
|
||||
Component Object Model Hijacking
|
||||
=================================
|
||||
Malware hijacks a component object model (COM) object to execute itself or other malicious code.
|
||||
|
||||
See ATT&CK: [**Component Object Model Hijacking**](https://attack.mitre.org/techniques/T1122).
|
||||
@@ -1,12 +0,0 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**E1478**|
|
||||
|**Objective(s)**| [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion), [Persistence](https://github.com/MBCProject/mbc-markdown/tree/master/persistence)|
|
||||
|**Related ATT&CK Technique**|[Install Insecure or Malicious Configuration](https://attack.mitre.org/techniques/T1478)|
|
||||
|
||||
|
||||
Configuration Modification
|
||||
==========================
|
||||
Malware may install malicious configuration settings or may modify existing configuration settings. This MBC behavior extends the related ATT&CK technique to all platforms and to the Persistence objective.
|
||||
|
||||
See ATT&CK: [**Install Insecure or Malicious Configuration**](https://attack.mitre.org/techniques/T1478).
|
||||
@@ -0,0 +1,27 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0040</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../defense-evasion">Defense Evasion</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Covert Location
|
||||
===============
|
||||
Malware may hide data or binary files within other files, the registry, etc.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Hide Data in Registry**|B0040.001|Malware may use a registry key to store a long sequence of bytes.|
|
||||
|**Steganography**|B0040.002|Malware may store information in an image. See related ATT&CK techniques: Data Obfuscation: Steganography [T1001.002](https://attack.mitre.org/techniques/T1001/002), Obfuscated Files or Information: Steganography ([T1027.003](https://attack.mitre.org/techniques/T1027/003), [T1406.001](https://attack.mitre.org/techniques/T1406/001)).|
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user