429 Commits

Author SHA1 Message Date
brightmt 10461c1cf0 Replace with new image 2025-06-11 20:52:16 -04:00
brightmt 7a4fb195a3 Fixed duplicate object 2025-06-11 20:49:07 -04:00
brightmt 6933d9e896 Snake (#179)
* Update snake.md

Updated malware behaviors and descriptions.

* Update snake.md

Divided table to split out enhanced techniques

* Update software-packing.md

Added Snake

* Update self-deletion.md

Added Snake

* Update system-information-discovery.md

Added Snake

* Update keylogging.md

Added Snake

* Update screen-capture.md

* Update decode-data.md

Added Snake

* Update decrypt-data.md

Added Snake

* Update copy-file.md

Added Snake

* Update create-file.md

Added Snake

* Update delete-file.md

* Update crypto-library.md

Added Snake

* Update crypto-library.md

---------

Co-authored-by: Desiree Beck <dbeck@mitre.org>
2025-04-03 17:46:24 -04:00
brightmt 4649d1d522 Merge pull request #178 from MBCProject/match-methods
Match methods
2025-04-03 08:13:56 -04:00
brightmt f3b9e2a714 Merge pull request #177 from MBCProject/visualization
Behavior Visualization
2025-04-03 08:11:45 -04:00
Desiree Beck cb53612423 Update compress-data.md
fixed typo
2025-04-02 18:46:23 -04:00
brightmt 2dd31923a2 Update README.md 2025-04-02 09:01:21 -04:00
brightmt b0e971d43d Update README.md 2025-04-02 08:55:06 -04:00
brightmt f8c4eb4cb4 Update README.md 2025-04-02 08:47:19 -04:00
brightmt a2a42e6c96 Update README.md 2025-04-02 08:43:35 -04:00
brightmt b5e5331177 Update README.md 2025-03-31 12:13:15 -04:00
Maddie Bright 19ee71f6a2 added files for visualization work 2025-03-31 11:45:38 -04:00
Beck 03af076ad7 refine text 2025-03-29 13:17:53 -04:00
Beck 2739eed073 add visualization info 2025-03-29 12:05:55 -04:00
Beck 6344455b57 add visualization info 2025-03-29 12:03:27 -04:00
brightmt df40a05878 Update compress-data.md
Added aPLib
2025-01-07 09:13:24 -05:00
brightmt b906fe23f9 Merge pull request #175 from MBCProject/new-methods
Two New methods
2025-01-06 11:33:11 -05:00
brightmt cbc9bb78d4 Create revoked.md (#173)
* Create revoked.md

Added table for tracking revoked IDs.  Unsure of the reason for C0032.004's revocation, although my speculation based on google search is included.

* Update revoked.md

Fixed dates

* Update revoked.md

Added C0013
2025-01-03 13:52:23 -05:00
brightmt f88fdabdad Update references (#172)
* Update references_to_mbc.md

Updated references.

* Update references_to_mbc.md

* Update references_to_mbc.md

---------

Co-authored-by: Desiree Beck <dbeck@mitre.org>
2024-12-27 11:15:10 -05:00
Desiree Beck e1f422dc8b Update virtual-machine-detection.md 2024-12-27 11:04:03 -05:00
Desiree Beck ef18cf849d Update disassembler-evasion.md 2024-12-27 11:02:32 -05:00
Desiree Beck 04975dae43 Update virtual-machine-detection.md 2024-12-27 11:00:04 -05:00
brightmt 7f3bfe2c7d Update capa to v8.0.1 (#174)
* Update disable-or-evade-security-tools.md

Added overwrite DLL .text section to remove hooks rule released in 7.2

* Update socket-communication.md

Added rule "attach BPF to socket on Linux" released in v 7.2

* Update self-deletion.md

Updated for congruence with CAPA 7.2 changes

* Update hijack-execution-flow.md

Updated APIs for "execute shellcode via Windows callback function"

* Update software-packing.md

Added "packed with nmm-protect" from CAPA 7.4
2024-12-26 15:06:07 -05:00
Desiree Beck 0aa720aa31 add December Newsletter (#171)
* Create 09192024.md

newsletter for MBC v3.2

* Update 09192024.md

* Update README.md

* Update 09192024.md

* Update 09192024.md

* Update 09192024.md

* Rename 09192024.md to 09242024.md

* Rename 09242024.md to 09232024.md

* Update README.md

* Update 09232024.md

* Update and rename 09232024.md to 10212024.md

* Update and rename 10212024.md to 12092024.md

* Update README.md
2024-12-09 10:41:09 -05:00
Desiree Beck 0fab38218e Staging (#170)
* Update dns-communication.md

* Update dns-communication.md

* Update http-communication.md

* Update icmp-communication.md

* Update interprocess-communication.md

* Update socket-communication.md

* Update wininet.md

* Update encrypt-data.md

* Update encrypt-data.md

* Update encryption-key.md

* Update alter-file-extension.md

* Update create-directory.md

* Update create-file.md

* Update create-file.md

* Update delete-file.md

* Update registry.md

* Update wallpaper.md

* Update create-process.md

* Update check-mutex.md

* Update writes-file.md

* Update create-mutex.md

---------

Co-authored-by: brightmt <50853930+brightmt@users.noreply.github.com>
2024-11-18 15:03:18 -05:00
brightmt af8c8ea7ff Merge pull request #166 from MBCProject/add-new-matrix-image
uploaded table drafts
2024-10-21 07:37:37 -04:00
brightmt aa63470894 Merge pull request #167 from MBCProject/update_cape_classes
Update cape classes
2024-10-21 07:37:22 -04:00
brightmt 634e938b37 Added matrix images with alphabetic objectives 2024-10-17 12:49:58 -04:00
Maddie Bright 476b07385d removed old tables 2024-10-17 10:44:52 -04:00
brightmt 0468702b69 Added new matrix images for 3.2 2024-10-17 10:41:15 -04:00
brightmt 03571e42e7 Update modify-registry.md
Found and repaired last broken link
2024-10-02 11:48:36 -04:00
brightmt 9cdd933745 Update allocate-thread-local-storage.md
Changed allocate TLS detection to new CAPA link
2024-10-02 11:10:24 -04:00
brightmt 7321acd0a1 Update process-injection.md
New link for silent process exit
2024-10-02 11:06:59 -04:00
brightmt b9021def42 Update exploitation-for-client-execution.md
Updated link to Windows utilities
2024-10-02 11:01:10 -04:00
brightmt 95ff87565f Update set-thread-local-storage-value.md
Updated link to CAPA rule
2024-10-02 10:52:33 -04:00
brightmt 2ba3797884 Update registry.md
Updated neshta signature link
2024-10-02 10:49:09 -04:00
brightmt 8dd14afae3 Update create-mutex.md
Updated Zeus P2P link
2024-10-02 10:40:52 -04:00
brightmt e7a3dae7e6 Update move-file.md
Updated CAPE link and CAPE class
2024-10-02 10:28:36 -04:00
brightmt 44a35ab0d8 Update allocate-memory.md
Updated CAPE link and class
2024-10-02 10:26:32 -04:00
brightmt 2965436b62 Update allocate-memory.md
Fixed bad CAPA link
2024-10-02 10:17:55 -04:00
brightmt 91ec7133ff Update allocate-memory.md
Updated bad CAPA rule link
2024-10-02 10:06:44 -04:00
brightmt 4874fd4b35 Update terminate-process.md
Added new link and CAPE class for rule
2024-10-02 10:02:25 -04:00
brightmt 1317809f48 Update decompress-data.md 2024-09-27 12:08:35 -04:00
brightmt f3fbf1f51b Update decrypt-data.md
Added class to CAPE mapping
2024-09-27 11:58:19 -04:00
Maddie Bright d180c7bb60 uploaded table drafts 2024-09-27 08:55:53 -04:00
Desiree Beck 70f151ebe4 Update Process micro-objective (#164)
* Update create-mutex.md

* Update create-mutex.md

* Update README.md

* Update README.md

* Delete micro-behaviors/process/synchronization.md

* Update mbc_summary.md

---------

Co-authored-by: brightmt <50853930+brightmt@users.noreply.github.com>
2024-09-16 13:50:08 -04:00
Desiree Beck c3033e4061 Staging (#162)
* update staging (#158)

* update format/wording

* Capa 7.1 rule updates (#156)

* Update self-deletion.md

Added CAPA rule "self delete using alternate data streams" (https://github.com/mandiant/capa-rules/blob/v7.1.0/anti-analysis/anti-forensic/self-deletion/self-delete-using-alternate-data-streams.yml)

* Update obfuscated-files-or-information.md

added new CAPA rule "encrypt data using RC4 via SystemFunction033" https://github.com/mandiant/capa-rules/blob/v7.1.0/data-manipulation/encryption/rc4/encrypt-data-using-rc4-via-systemfunction033.yml

* Update disk-wipe.md

Added capa rule "https://github.com/mandiant/capa-rules/blob/v7.1.0/impact/wipe-disk/delete-drive-layout-via-ioctl.yml" https://github.com/mandiant/capa-rules/blob/v7.1.0/impact/wipe-disk/delete-drive-layout-via-ioctl.yml

* Update system-information-discovery.md

Added new CAPA rule "get disk information via IOCTL" https://github.com/mandiant/capa-rules/blob/v7.1.0/nursery/get-disk-information-via-ioctl.yml

* Update system-information-discovery.md

Added new CAPA rule "get volume information via IOCTL" https://github.com/mandiant/capa-rules/blob/v7.1.0/nursery/get-volume-information-via-ioctl.yml

* Update dns-communication.md

Removed duplication in APIs in "Resolve DNS" CAPA rule

* Update socket-communication.md

Updated APIs for "create raw socket" CAPA rule

* Update socket-communication.md

Updated APIs on CAPA rule "get socket status"

* Update socket-communication.md

Updated CAPA rule "initialize Winsock library"

* Update socket-communication.md

Updated API listing on CAPA rule "receive data on socket"

* Update socket-communication.md

Updated API listing for "send data on socket" CAPA rule

* Update socket-communication.md

Update APIs for CAPA rule "set socket configuration"

* Update socket-communication.md

Updated CAPA rule "connect tcp socket" to add APIs

* Update socket-communication.md

Added APIs to CAPA rule "create tcp socket"

* Update socket-communication.md

Added APIs to "create UDP socket" CAPA rule

* Update encrypt-data.md

Added new APIs to "encrypt data using DPAPI" CAPA rule

* Update install-driver.md

Added APIs to CAPA rule "install driver"

* Update set-file-attributes.md

Added APIs to CAPA rule "change file permissions on Linux"

* Update writes-file.md

Updated APIs for CAPA rule "write file on linux"

* Update system-information-discovery.md

Removed API from CAPA rule "get disk size" to align with published CAPA rule in v. 7.1

* Update create-process.md

Added API to "create process on linux" CAPA rule

* Update hijack-execution-flow.md

Added API calls to CAPA rule "execute shellcode via Windows callback function"

* Update self-deletion.md

Changed link to master

* Update obfuscated-files-or-information.md

Changed rule link to release to point to master

* Update system-information-discovery.md

Removed nursery rules

* Update disk-wipe.md

Updated link to master branch

* Update socket-communication.md

Checked for correct socket listings under the APIs

---------

Co-authored-by: brightmt <50853930+brightmt@users.noreply.github.com>

* New method (#159)

* update format/wording

* Update disassembler-evasion.md

* Update disassembler-evasion.md

* Corpus fix (#160)

* update format/wording

* fix tables

* Edits

---------

Co-authored-by: ryan <ryanxu@wustl.edu>

* New method (#161)

* update format/wording

* Update disassembler-evasion.md

* Update disassembler-evasion.md

---------

Co-authored-by: brightmt <50853930+brightmt@users.noreply.github.com>
Co-authored-by: ryan <ryanxu@wustl.edu>
2024-08-25 10:09:33 -04:00
brightmt 084ba830d3 Capa 7.1 rule updates (#156)
* Update self-deletion.md

Added CAPA rule "self delete using alternate data streams" (https://github.com/mandiant/capa-rules/blob/v7.1.0/anti-analysis/anti-forensic/self-deletion/self-delete-using-alternate-data-streams.yml)

* Update obfuscated-files-or-information.md

added new CAPA rule "encrypt data using RC4 via SystemFunction033" https://github.com/mandiant/capa-rules/blob/v7.1.0/data-manipulation/encryption/rc4/encrypt-data-using-rc4-via-systemfunction033.yml

* Update disk-wipe.md

Added capa rule "https://github.com/mandiant/capa-rules/blob/v7.1.0/impact/wipe-disk/delete-drive-layout-via-ioctl.yml" https://github.com/mandiant/capa-rules/blob/v7.1.0/impact/wipe-disk/delete-drive-layout-via-ioctl.yml

* Update system-information-discovery.md

Added new CAPA rule "get disk information via IOCTL" https://github.com/mandiant/capa-rules/blob/v7.1.0/nursery/get-disk-information-via-ioctl.yml

* Update system-information-discovery.md

Added new CAPA rule "get volume information via IOCTL" https://github.com/mandiant/capa-rules/blob/v7.1.0/nursery/get-volume-information-via-ioctl.yml

* Update dns-communication.md

Removed duplication in APIs in "Resolve DNS" CAPA rule

* Update socket-communication.md

Updated APIs for "create raw socket" CAPA rule

* Update socket-communication.md

Updated APIs on CAPA rule "get socket status"

* Update socket-communication.md

Updated CAPA rule "initialize Winsock library"

* Update socket-communication.md

Updated API listing on CAPA rule "receive data on socket"

* Update socket-communication.md

Updated API listing for "send data on socket" CAPA rule

* Update socket-communication.md

Update APIs for CAPA rule "set socket configuration"

* Update socket-communication.md

Updated CAPA rule "connect tcp socket" to add APIs

* Update socket-communication.md

Added APIs to CAPA rule "create tcp socket"

* Update socket-communication.md

Added APIs to "create UDP socket" CAPA rule

* Update encrypt-data.md

Added new APIs to "encrypt data using DPAPI" CAPA rule

* Update install-driver.md

Added APIs to CAPA rule "install driver"

* Update set-file-attributes.md

Added APIs to CAPA rule "change file permissions on Linux"

* Update writes-file.md

Updated APIs for CAPA rule "write file on linux"

* Update system-information-discovery.md

Removed API from CAPA rule "get disk size" to align with published CAPA rule in v. 7.1

* Update create-process.md

Added API to "create process on linux" CAPA rule

* Update hijack-execution-flow.md

Added API calls to CAPA rule "execute shellcode via Windows callback function"

* Update self-deletion.md

Changed link to master

* Update obfuscated-files-or-information.md

Changed rule link to release to point to master

* Update system-information-discovery.md

Removed nursery rules

* Update disk-wipe.md

Updated link to master branch

* Update socket-communication.md

Checked for correct socket listings under the APIs
2024-08-24 13:19:12 -04:00
Beck ad8e58255c update format/wording 2024-07-16 17:31:19 -04:00
Desiree Beck e1f6657ac0 Update README.md (#155)
see Issue #152
2024-06-30 16:24:18 -04:00
RazviOverflow 53771d2293 Updated MBC-CAPE signature mappings (#153)
* Deleted deprecated signatures

* Added new signature

* Updated table to match new CAPE signatures' format

* Added new signature mappings

* Fixed table header

* Deleted unspecified API

* Updated table to match new CAPE signature format. Fixed existing signatures.

* Deleted deprecated signatures

* Added missing class

* Added new signature mappings

* Deleted deprecated signatures

* Updated table to match new CAPE signature format

* Added new signature mappings

* Updated deprecated links

* Updated table to match new CAPE signature format

* Added new signature mapping

* Updated table format, signature, and link

* Fixed existing signatures' url

* Deleted deprecated signatures

* Updated existing signatures

* Added new signature mappings

* Deleted deprecated signature

* Updated table. Added new signature mappings.

* Deleted deprecated signatures

* Updated table to new CAPE signature format

* Added new signature mappings

* Deleted deprecated signatures

* Updated table. Added new signature mappings.

* Deleted deprecated signatures

* Updated table. Added new signature mappings

* Fixed broken url

* Updated table

* Deleted deprecated signatures

* Updated table format. Added new signature mapping.

* Deleted deprecated signatures

* Updated table. Fixed already existing signatures.

* Added new signature mappings

* Updated existing signatures

* Updated table format. Deleted deprecated signatures.

* Updated existing signatures

* Added new signature mappings

* Updated existing signatures

* Updated table and signatures

* Fixed existing signatures

* Deleted deprecated signatures

* Updated table

* Added new signature mappings

* Updated existing signatures

* Updating existing signatures

* Updating existing signatures

* Updating exiting signature

* Deleted deprecated signatures

* Updated existing signatures

* Updated existing signatures

* Added new signature mappings

* Deleted deprecated signature

* Updated table

* Added new signature mapping

* Deleted deprecated signatures

* Added new signature mappings

* Deleted deprecated signatures

* Added new signature mappings

* Updated table and existing signatures

* Deleted deprecated signatures

* Updated table and existing signatures

* Added new signature mappings

* Fixing typos

* Fixing typos II

* Fixing typos III
2024-06-30 15:08:20 -04:00
Desiree Beck bd31003a22 Staging (#151)
* Fixing links

* Code samples (#149)

* Update obfuscated-files-or-information.md

Added code sample with some proposed formatting incl. annotations explaining broad behavior patterns

* Update obfuscated-files-or-information.md

Added brief clarification to note

* Update obfuscated-files-or-information.md

Made requested changes to format

* Update system-information-discovery.md

Added code snippet from PoisonIvy RAT

* Update debugger-detection.md

Added code with example of PEB access

* Update system-information-discovery.md

Added new method based on code snippet

* Update registry.md

Added snippet for registry key query

* Update generate-pseudorandom-sequence.md

Added example of Mersenne Twister algorithm

* Update keylogging.md

Add Dark Comet keylogging code sample

* Update dns-communication.md

Added code sample from darkcomet

* Update socket-communication.md

Added DarkComet code snippet

* Update delete-file.md

Provided DarkComet sample

* Update file-and-directory-discovery.md

Added DarkComet snippet

* Update allocate-memory.md

Added DarkComet sample

* Update modulo.md

Added Hupigon snippet

* Update get-file-attributes.md

Added Hupigon sample

* Update application-window-discovery.md

Added Hupigon snippet

* Update create-process.md

Added Hupigon snippet.

* Update conditional-execution.md

Added Hupigon snippet

* Update create-thread.md

Added Hupigon snippet

* Update resume-thread.md

Added Hupigon snippet

* Update command-and-scripting-interpreter.md

Added SmokeLoader sample

* Update change-memory-protection.md

Added SmokeLoader snippet

* Update console.md

Added snippet from SmokeLoader

* Update dynamic-analysis-evasion.md

Added Industroyer sample

* Update interprocess-communication.md

Added CobaltStrike sample

* Update read-file.md

Added Cobalt Strike snippet

* Update writes-file.md

Added cobalt strike snippet

* Update noncryptographic-hash.md

Added emotet snippet

* Update clipboard-modification.md

Added emotet snippet

* Update check-mutex.md

Added emotet sampler

* Update check-mutex.md

Fixed typo

* Update create-mutex.md

Added Emotet snippet

* Update allocate-thread-local-storage.md

Added emotet snippet

* Update registry-run-keys-startup-folder.md

Added emotet snippet

* Update wininet.md

Added EnvyScout snippet

* Update http-communication.md

Added EnvyScout snippet

* Update enumerate-threads.md

Added Envyscout snippet

* Update set-thread-local-storage-value.md

Added Envyscout sample

* Update create-directory.md

Added explosive snippet

* Update delete-directory.md

Added explosive code snippet (note: the malware is called "explosive")

* Update set-file-attributes.md

Added explosive sample

* Update terminate-process.md

Added explosive snippet

* Update terminate-thread.md

Added explosive sample

* Update move-file.md

Added Finfisher snippet

* Update screen-capture.md

Added ECCENTRICBANDWAGON snippet

* Fix links (#150)

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* update mod date

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* Update code-discovery.md

* Update taskbar-discovery.md

* Update conditional-execution.md

* Update memory-dump-evasion.md

* Update execution-dependency.md

* Update compromise-data-integrity.md

* Update dns-communication.md

* Update http-communication.md

* Update interprocess-communication.md

* Update socket-communication.md

* Update wininet.md

* Update generate-pseudorandom-sequence.md

* Update modulo.md

* Update noncryptographic-hash.md

* Update create-directory.md

* Update delete-directory.md

* Update delete-file.md

* Update get-file-attributes.md

* Update move-file.md

* Update read-file.md

* Update terminate-thread.md

* Update set-file-attributes.md

* Update writes-file.md

* Update allocate-memory.md

* Update change-memory-protection.md

* Update console.md

* Update registry.md

* Update allocate-thread-local-storage.md

* Update check-mutex.md

* Update terminate-process.md

* Update create-mutex.md

* Update create-process.md

* Update set-thread-local-storage-value.md

* Update resume-thread.md

* Update enumerate-threads.md

* Update create-thread.md

* update for 3.1 release

* update for 3.1 release

* update for 3.1 release

---------

Co-authored-by: ryan <ryanxu@wustl.edu>
Co-authored-by: brightmt <50853930+brightmt@users.noreply.github.com>
2024-05-01 16:09:33 -04:00
Desiree Beck 42dc41e00b update for attack v15 (#148)
* update for attack v15

* update modified date
2024-04-28 14:32:00 -04:00
Ryan Xu 009ae77217 3.1 Updates (#145)
* E/f updates (#143)

* E/F Update,  Update Install Cert ID

* Small fixes

* Update common objects link (#142)

* Update README.md

* Update 09152023.md

* Update README.md

* Update 12182023.md

* Adding descriptions to micro-behaviors

* Fixing dead links

* V3.1 updates (#144)

* minor fixes for v3.1

* correct id

---------

Co-authored-by: Desiree Beck <dbeck@mitre.org>
2024-02-14 09:27:20 -05:00
ryan ad05fb07ba Updating version and last modified 2024-01-02 12:58:56 -05:00
Desiree Beck 356d3dc416 Update bagle.md (#141)
* Update bagle.md

* Update malware-types.md

* Update redhip.md

* Update rombertik.md

* Update snake.md

* Update malware-types.md

* Update snake.md

* Update redhip.md

* Update rombertik.md
2023-12-21 09:18:21 -05:00
Desiree Beck 6ce7ebadf2 Malware types (#140)
* Create malware-types.md

* Update README.md

added link to malware type table.

* Update malware-types.md

* Update malware-types.md

* Update malware-types.md

* Update malware-types.md

* Update malware-types.md

* Update malware-types.md

* Update geneio.md

* Update geneio.md

* Update searchawesome.md

* Update chopstick.md

* Update cozycar.md

* Update gobotkr.md

* Update heriplor.md

* Update hupigon.md

* Update synful-knock.md

* Update mebromi.md

* Update blackenergy.md

* Update cozycar.md

* Update cozycar.md

* Update drovorub.md

* Update evilbunny.md

* Update gamut.md

* Update gobotkr.md

* Update cozycar.md

* Update kovter.md

* Update kraken.md

* Update mazarbot.md

* Update blackenergy.md

* Update matanbuchus.md

* Update yispecter.md

* Update cozycar.md

* Update up007.md

* Update teardrop.md

* Update redhip.md

* Update malware-types.md

* Update rombertik.md

* Update snake.md

* Update snake.md

* Update dark-comet.md

* Update badusb.md

* Update dyepack.md

* Update conti.md

* Update cryptolocker.md

* Update cryptowall.md

* Update locky-bart.md

* Update netwalker.md

* Update samsam.md

* Update wannacry.md

* Update adwind-jrat.md

* Update electrorat.md

* Update gravity-rat.md

* Update poison-ivy.md

* Update terminator.md

* Update clipminer.md

* Update webcobra.md

* Update drovorub.md

* Update dark-comet.md

* Update attor.md

* Update geneio.md

* Update malware-types.md

* Update trickbot.md

* Update dark-comet.md

* Update dnschanger.md

* Update emotet.md

* Update kovter.md

* Update heriplor.md

* Update trickbot.md

* Update ursnif.md

* Update mazarbot.md

* Update shamoon.md

* Update bagle.md

* Update conficker.md

* Update stuxnet.md

* Update vobfus.md

* Newsletter, editing E1510, E1560 (#137) (#138)

* Adding Newsletter

* Create 12182023.md

* Update README.md

---------



* Update e1510 (#134)

* Update clipboard-modification.md

Update to account for updates to T1115.

* Update data-encrypted-for-impact.md

fix parentheses

* Update clipboard-modification.md

* Update data-encrypted-for-impact.md

* Update clipboard-modification.md

* Moving Archive Collected Data to collection, some description updates

* Updating Last Modified

---------

Co-authored-by: Ryan Xu <ryanxu@wustl.edu>

* Newsletter, editing E1510, E1560 (#137) (#139)

* Adding Newsletter

* Create 12182023.md

* Update README.md

---------



* Update e1510 (#134)

* Update clipboard-modification.md

Update to account for updates to T1115.

* Update data-encrypted-for-impact.md

fix parentheses

* Update clipboard-modification.md

* Update data-encrypted-for-impact.md

* Update clipboard-modification.md

* Moving Archive Collected Data to collection, some description updates

* Updating Last Modified

---------

Co-authored-by: Ryan Xu <ryanxu@wustl.edu>

---------

Co-authored-by: Ryan Xu <ryanxu@wustl.edu>
2023-12-20 21:54:25 -05:00
Ryan Xu a92e8ffdfd Newsletter, editing E1510, E1560 (#137)
* Adding Newsletter

* Create 12182023.md

* Update README.md

---------

Co-authored-by: Desiree Beck <dbeck@mitre.org>

* Update e1510 (#134)

* Update clipboard-modification.md

Update to account for updates to T1115.

* Update data-encrypted-for-impact.md

fix parentheses

* Update clipboard-modification.md

* Update data-encrypted-for-impact.md

* Update clipboard-modification.md

* Moving Archive Collected Data to collection, some description updates

* Updating Last Modified

---------

Co-authored-by: Desiree Beck <dbeck@mitre.org>
2023-12-18 13:40:56 -05:00
Ryan Xu d423b5a5fa Adding CAPE mappings to detection section (#132)
* Making spacing between sections consistent

* Adding cape mappings
2023-12-05 14:19:50 -05:00
Ryan Xu 463eef29c1 Updating Summary and Minor Fixes (#131)
* Updating Summary

* Minor fixes (#130)

* How to cite (#127)

* Added citation-related files

* Modified type to misc. Commented out the license

* Modified main README to match output produced by CITATION.cff

* Update CITATION.cff

* Update README.md

---------

Co-authored-by: Desiree Beck <dbeck@mitre.org>

* Update dynamic-analysis-evasion.md

remove duplicated text and fix link

* Update sandbox-detection.md

Corrected technique name

* Update README.md

* Update mbc_summary.md

---------

Co-authored-by: RazviOverflow <41084837+RazviOverflow@users.noreply.github.com>

* fixes to summary

* ordering change

---------

Co-authored-by: Desiree Beck <dbeck@mitre.org>
Co-authored-by: RazviOverflow <41084837+RazviOverflow@users.noreply.github.com>
2023-11-16 09:38:32 -05:00
RazviOverflow 30d610503e How to cite (#127)
* Added citation-related files

* Modified type to misc. Commented out the license

* Modified main README to match output produced by CITATION.cff

* Update CITATION.cff

* Update README.md

---------

Co-authored-by: Desiree Beck <dbeck@mitre.org>
2023-10-30 09:37:19 -04:00
Ryan Xu 74d28a9ef9 small malware fixes (#129) 2023-10-26 11:33:17 -04:00
Desiree Beck c2df3d4e10 Staging (#126)
* Changing conti name

* Mbc 3 (#125)

* update version number

* update links

* update version number

* update version number

* update version number

* 2.3 to main in matrix

* link fix

* v3 faq update

---------

Co-authored-by: ryan <ryanxu@wustl.edu>

---------

Co-authored-by: ryan <ryanxu@wustl.edu>
2023-10-03 11:36:05 -04:00
Ryan Xu f7d92d59fa Staging (#124)
- Updating capa detection in behaviors
- Newsletter
- Conti malware
- pafish faq
2023-09-20 15:57:32 -04:00
Ryan Xu 7223fa76d6 Aug 23 update (#118) (#119)
* update faq

* update faq

* update corpus doc

* update corpus doc

* update FAQ

* update FAQ

* update FAQ

* update FAQ

* update FAQ

* update what's new

* Cleaning ref links, etc (#115) (#116)

* Cleanup

---------



* Revert "Cleaning ref links, etc (#115) (#116)" (#117)

This reverts commit 57d470ab4c.

* reorder questions

* reorder questions

* reorder questions

* reorder questions

* update faq

* update faq

* update faq

* update faq

---------

Co-authored-by: Desiree Beck <dbeck@mitre.org>
2023-08-23 14:05:31 -04:00
Ryan Xu c9b0396e0e Cleaning ref links, etc (#115)
* Cleanup

---------

Co-authored-by: Desiree Beck <dbeck@mitre.org>
2023-08-17 14:08:55 -04:00
Ryan Xu 94eed133d7 Syntax change (#109) 2023-06-29 12:57:34 -04:00
Ryan Xu 1a009c8077 attack flow and cacao patch (#107) (#108)
* Update README.md

fix link

* Update README.md

* add Attack Flow content for two corpus malware

* add info about attack flow and cacao

* add info about attack flow and cacao

* info about cacao playbook

* update readme for cacao and attack flow

* add text for cacao

* update readme for cacao and attack flow

Co-authored-by: Desiree Beck <dbeck@mitre.org>
2023-06-28 10:09:08 -04:00
Desiree Beck ddbb2caa46 June newsletter (#106)
* june newsletter

* June newsletter

* June newsletter

* June newsletter

* June newsletter

* June newsletter

* June newsletter

* June newsletter
2023-06-20 23:16:01 -04:00
Ryan Xu 275c8feec3 New Malware Examples + Editing References (#105)
* New malware examples (#103)

* fix typos

* add new Use in Malware entries to behaviors

* new corpus entries

* remove extraneous ref

* restore original IDs

* fix typos

* Update registry.md (#101)

Update C0036.001 per "Registry micro-behavior" Discussion.

* Update registry.md (#102)

Update C0036.001 per "Registry micro-behavior" Discussion.

* correct modified date

* fix PR comments on formatting

* Editing references (#104)

---------

Co-authored-by: Desiree Beck <dbeck@mitre.org>
2023-06-12 11:10:47 -04:00
Desiree Beck 39a49dca38 Update registry.md
Update C0036.001 per "Registry micro-behavior" Discussion.
2023-05-24 22:52:05 -04:00
Ryan Xu 17663f17f6 minor fixes (#99) 2023-05-22 10:18:37 -04:00
Ryan Xu 0400889da4 Update sandbox-detection.md (#97) 2023-05-09 13:16:38 -04:00
Ryan Xu 0238c12f6e Enhancing behavior descriptions, formatting + citation updates (#96)
* formatting and citation updates

* Adding Janet's work on behavior descriptions
2023-05-08 10:32:10 -04:00
Ryan Xu b43365cb18 New methods (#93) (#94)
* two new methods

* two new methods

* two new methods

Co-authored-by: Desiree Beck <dbeck@mitre.org>
2023-04-26 15:37:32 -04:00
Ryan Xu 337d99e890 Typo fixes in xample-malware (#92) 2023-04-03 15:09:07 -04:00
Ryan Xu 6509b3dedb Added clarification to malware corpus description (#89) 2023-03-20 13:32:34 -04:00
Ryan Xu f3a6002ab4 Adding references page (#88)
* Adding references_to_mbc page

* Adding refs
2023-03-20 09:46:42 -04:00
Ryan Xu 3dafbebc69 disk-wipe fix (#87) 2023-03-16 10:40:33 -04:00
Desiree Beck 92b76bde3d March newsletter (#86)
* march 2023 newsletter
2023-03-15 13:10:04 -04:00
Ryan Xu e1b22023c5 Staging (#85)
* Janet mbc updates (#84)

* Added Unprotect techniques to respective behaviors and or methods.

* Unprotect updates MBC

* Unprotect techniques mapped in MBC

---------

Co-authored-by: Ryan Xu <ryanxu@wustl.edu>

* Fixing redundant Detection sec in sandbox detect

---------

Co-authored-by: quant23va <105243450+quant23va@users.noreply.github.com>
2023-03-15 10:20:48 -04:00
Ryan Xu 9e30d80c19 Staging (#83)
* Adding script files

* Scripting overhaul

* Adding capa analysis from MITRE into corpus

* Adding capa analysis from MITRE into corpus

* Backtracing capa mappings to behavior pages

* Other fixes

* merge dev into staging

* Fixing capa mappings

* merge dev into staging

* fix writes file typo

* merge dev into staging

* Fix method column + cape analysis

* Updates to snippets and descriptions
2023-03-14 09:28:34 -04:00
Desiree Beck 46d44c90c6 fix link typo 2023-03-11 11:15:10 -05:00
Stephen Battista c36a5217b4 Fixed dead links moved http to https (#82)
* Fixed dead links moved http to https

* Updated Joesecurity link to not use web archive
2023-03-04 13:54:02 -05:00
Desiree Beck 573b932926 Update poison-ivy.md 2023-03-01 03:17:02 -05:00
Desiree Beck bfbe6defaa Update kovter.md 2023-03-01 03:15:42 -05:00
Lauren Parker 94fa3c86b8 Lauren malware corpus (#81)
* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated info

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* updated ID number

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos

* fixed typos
2023-03-01 03:12:22 -05:00
Desiree Beck 4c418892ee Update process-injection.md
corrected link
2023-02-20 04:03:23 -05:00
Desiree Beck d6dae1437c Update cape.md
update formatting
2023-02-14 05:38:05 -05:00
Desiree Beck 2d7229c8ef Update capa.md
update formatting
2023-02-14 05:37:02 -05:00
Desiree Beck 35ea70d679 Update cape.md
Further explain histogram contents.
2023-02-14 05:27:29 -05:00
Desiree Beck 699c4f94a6 Update capa.md
update text to more clearly explain content
2023-02-14 05:20:46 -05:00
Ryan Xu 1917b816ca Adding capa analysis to corpus and improved backtrace to behavior pages (#80)
* Adding script files

* Scripting overhaul

* Adding capa analysis from MITRE into corpus

* Adding capa analysis from MITRE into corpus

* Backtracing capa mappings to behavior pages

* Other fixes

* merge dev into staging

* Fixing capa mappings

* merge dev into staging

* fix writes file typo

* merge dev into staging

* Fix method column + cape analysis
2023-02-01 10:28:30 -05:00
Desiree Beck da00a07f6b Update README.md 2022-12-29 12:56:48 -05:00
Desiree Beck 4222adac4a Update README.md
update copyright
2022-12-29 12:55:22 -05:00
Desiree Beck c84e8062aa Update 12152022.md
minor corrections
2022-12-15 23:55:52 -05:00
Desiree Beck 3c094648be Merge pull request #78 from MBCProject/dec-newsletter
Dec newsletter
2022-12-15 23:47:37 -05:00
Desiree Beck 962ff10437 Merge pull request #77 from MBCProject/obj-list
Obj list
2022-12-14 16:09:56 -05:00
Dez Beck 5b52f47491 draft dec newsletter 2022-12-14 10:41:50 -05:00
Dez Beck 0845e52f71 draft dec newsletter 2022-12-14 10:39:26 -05:00
Dez Beck 5df6d33896 draft dec newsletter 2022-12-12 13:21:15 -05:00
Dez Beck 3d754d97e9 draft dec newsletter 2022-12-12 13:17:20 -05:00
Dez Beck 04d9933540 draft dec newsletter 2022-12-12 13:05:27 -05:00
Dez Beck 31b9e73fd8 draft dec newsletter 2022-12-12 13:03:46 -05:00
Dez Beck fab70e0a04 correct typo 2022-12-12 12:58:18 -05:00
Dez Beck b478f86e3a draft dec newsletter 2022-12-12 12:57:29 -05:00
Dez Beck 85d13ea6c8 add missing data 2022-12-12 09:58:54 -05:00
Dez Beck 925207b992 fix incorrect link 2022-12-11 19:16:25 -05:00
Dez Beck 18f8fded32 add framework for cape signatures 2022-12-11 18:57:25 -05:00
Dez Beck d8f6471a23 add framework for cape signatures 2022-12-11 17:05:53 -05:00
Dez Beck 5adac81159 add framework for cape signatures 2022-12-11 16:58:29 -05:00
Dez Beck 0ef2b8a7fb add framework for cape signatures 2022-12-11 16:53:59 -05:00
Dez Beck 106ab71ebf add framework for cape signatures 2022-12-11 16:50:00 -05:00
Ryan Xu cc516db545 Merge pull request #76 from ryantxu1/master
Removing zscript from master branch
2022-12-06 11:21:32 -05:00
ryan 0a710c1ec5 Removing zscript from master branch 2022-12-06 11:18:29 -05:00
Ryan Xu 57f88fb611 Merge pull request #75 from MBCProject/mbc-addfields
Mbc addfields
2022-11-30 10:07:44 -05:00
Ryan Xu a2c1bb740b Merge branch 'master' into mbc-addfields 2022-11-30 10:07:21 -05:00
Desiree Beck a1f4be4d08 Merge pull request #74 from ryantxu1/mbc-addfields
Completed syntax migration and typo fixes
2022-11-29 15:32:50 -05:00
Ryan Xu 6eca508a1b Merge pull request #73 from MBCProject/mbc-utkonos
updates to disassembler evasion and executable code obfuscation
2022-11-29 10:00:11 -05:00
ryan 12b8422a5f Completed syntax migration and typo fixes 2022-11-29 09:19:21 -05:00
Dez Beck a59ccac398 move methods between behaviors 2022-11-22 09:58:17 -05:00
Dez Beck 78694e454f move methods between behaviors 2022-11-21 22:21:30 -05:00
Desiree Beck 0ee560d941 Merge pull request #72 from ryantxu1/mbc-addfields
Adding Method column to 'Use in Malware' section
2022-11-21 14:05:04 -05:00
ryan 8806c483f9 Adding Method column to 'Use in Malware' section 2022-11-21 10:55:51 -05:00
Dez Beck cc57a06faf address issue #68 2022-11-20 15:54:01 -05:00
Dez Beck 1eb1d399d6 update text for issues #63 and #65 2022-11-20 15:40:03 -05:00
Dez Beck ba0c30cda2 address issue #67 2022-11-20 15:08:42 -05:00
Dez Beck a2f7da94ed address issues 63 and 65 2022-11-20 14:54:26 -05:00
Desiree Beck d55c5c092b Merge pull request #69 from utkonos/issue61
Update navigator links from tag v2.2 to v2.3. Fixes #61
2022-11-19 10:17:51 -05:00
Desiree Beck de885058f6 Merge pull request #66 from ryantxu1/mbc-addfields
Adding new malware to corpus, some typo fixes
2022-11-19 10:01:49 -05:00
Malware Utkonos 0cad98fb1f Update navigator links from tag v2.2 to v2.3. Fixes #61 2022-11-19 01:53:22 -05:00
ryan 8bb7c5e3df Adding new malware to corpus, some typo fixes 2022-11-18 12:36:44 -05:00
Desiree Beck 24d2ee2bba Merge pull request #62 from ryantxu1/mbc-addfields
Changed Markdown headers to atx-style
2022-11-11 03:59:29 -05:00
ryan 236f706f30 Changed Markdown headers to atx-style pt2 2022-11-10 13:28:52 -05:00
Ryan Xu d51417f94e Merge branch 'MBCProject:mbc-addfields' into mbc-addfields 2022-11-10 13:28:34 -05:00
ryan 9c69facf0f Changed Markdown headers to atx-style 2022-11-10 12:02:12 -05:00
Desiree Beck 85febd7c94 Merge pull request #60 from ryantxu1/mbc-addfields
Added Anti-Analysis/Impact Tags
2022-11-09 03:09:50 -05:00
Ryan Xu acf14afd3c Merge branch 'MBCProject:mbc-addfields' into mbc-addfields 2022-11-08 15:23:07 -05:00
ryan 6201858f10 Added Anti-Analysis/Impact Tags 2022-11-08 15:22:36 -05:00
Dez Beck c7901b96fe fix typo 2022-11-01 07:28:05 -04:00
Desiree Beck 5635b9b5a4 Merge pull request #59 from ryantxu1/mbc-addfields
Modified header fields + code snippet dropdown
2022-11-01 07:05:45 -04:00
ryan 779142fb8f Added new header fields 2022-10-31 15:49:13 -04:00
Dez Beck ba4ebcb04b add full table of content 2022-10-31 03:35:17 -04:00
ryan f749cb82fb anti-behavioral-analysis header changes 2022-10-28 15:15:07 -04:00
ryan 56220fb732 Code snippet changes 2022-10-22 17:59:01 -04:00
ryan 86594f12a2 Link 2022-10-20 13:51:21 -04:00
ryan 0930da07d0 Dropdown prototype 2022-10-19 10:52:34 -04:00
Dez Beck e9b9982497 adding add'l fields 2022-10-09 15:23:32 -04:00
Dez Beck 939b5ffa8d adding add'l fields 2022-10-09 15:13:04 -04:00
Dez Beck 2d13f77362 Merge branch 'master' of https://github.com/MBCProject/mbc-markdown into mbc-addfields 2022-10-01 13:17:49 -04:00
Dez Beck e7777b8e63 fix objective ID 2022-10-01 13:16:43 -04:00
Dez Beck cf7cc73047 adding add'l fields 2022-09-29 14:09:52 -04:00
Dez Beck 9337f1a275 adding add'l fields 2022-09-29 14:05:09 -04:00
Dez Beck a396670ba1 adding add'l fields 2022-09-29 14:02:06 -04:00
Dez Beck 1a77b41a26 adding add'l fields 2022-09-29 13:56:45 -04:00
Dez Beck 066d3728d5 adding add'l fields 2022-09-29 13:55:08 -04:00
Dez Beck 843e9527f0 adding add'l fields 2022-09-29 13:53:29 -04:00
Dez Beck 4f0dafbfaa adding add'l fields 2022-09-29 13:50:29 -04:00
Dez Beck b9a18a1f41 adding add'l fields 2022-09-29 13:22:29 -04:00
Desiree Beck ffcce48eee Merge pull request #58 from ryantxu1/html-changes
Updating Hashes to SHA256 + typo fixes
2022-09-16 11:02:41 -04:00
ryan 322fb1248d Updating Hashes to SHA256 + typo fixes 2022-09-16 09:44:47 -04:00
Ryan Xu 200f302b01 Update README to reflect 2.3 release 2022-09-14 12:49:56 -04:00
Desiree Beck e5b31bdd5b Merge pull request #57 from MBCProject/mbc-newsletter
Mbc newsletter
2022-09-09 15:52:26 -04:00
Dez Beck 949209d597 newsletter update 2022-09-09 13:52:09 -04:00
Dez Beck 1e42433220 newsletter update 2022-09-09 13:46:19 -04:00
Dez Beck 00afb1d6b0 newsletter update 2022-09-09 10:57:45 -04:00
Desiree Beck 344da4eaea Merge pull request #56 from ryantxu1/html-changes
FAQ readme anchor fix
2022-09-08 15:14:06 -04:00
Ryan Xu 9937ebd631 Update 09092022.md 2022-09-08 15:09:06 -04:00
ryan fa9f508370 faq readme anchor fix 2022-09-08 15:01:30 -04:00
Dez Beck d5791ce5fe newsletter update 2022-09-08 13:15:21 -04:00
Dez Beck a6096cb8df newsletter update 2022-09-08 13:05:24 -04:00
Dez Beck 2f6093b0b9 newsletter update 2022-09-08 13:00:59 -04:00
Dez Beck 503105dcd0 add newsletters 2022-09-08 12:51:51 -04:00
Dez Beck dbf98ecfb7 add newsletters 2022-09-08 12:42:21 -04:00
Desiree Beck 5fc453ab53 Merge pull request #55 from ryantxu1/html-changes
xample malware link fixes
2022-09-08 10:20:37 -04:00
ryan 9d267f438a xample malware link fixes 2022-09-08 09:57:40 -04:00
Desiree Beck 389c9023ef Merge pull request #54 from MBCProject/mbc-faq
Mbc faq
2022-09-07 19:44:11 -04:00
Desiree Beck 99e472ad90 Merge pull request #53 from MBCProject/master
Merge pull request #52 from MBCProject/mbc-faq
2022-09-07 19:43:14 -04:00
Dez Beck 69055744bf add link 2022-09-07 19:41:46 -04:00
Desiree Beck b3096ed9f2 Merge pull request #52 from MBCProject/mbc-faq
updated for v2.3
2022-09-07 19:37:53 -04:00
Dez Beck a1f14b90a8 updated for v2.3 2022-09-07 19:33:26 -04:00
Desiree Beck d107a3d89e Merge pull request #51 from MBCProject/mbc-FP-update
Mbc fp update
2022-09-07 10:48:27 -04:00
Dez Beck e677acfe93 address F.P. feedback 2022-08-26 10:11:45 -04:00
Dez Beck 5392791edc address F.P. feedback 2022-08-26 10:10:10 -04:00
Dez Beck 4c3cc0125f address F.P. feedback 2022-08-26 10:05:44 -04:00
Dez Beck 999696ad26 updates navigator view text 2022-08-22 15:28:52 -04:00
Dez Beck 3f897ca2bb updates navigator view text 2022-08-22 15:27:21 -04:00
Dez Beck 01df10e1cb updates navigator view text 2022-08-22 15:25:19 -04:00
Dez Beck 580fadedcf updates navigator view text 2022-08-22 14:51:28 -04:00
Dez Beck b3a7a36a27 updates navigator view text 2022-08-22 14:49:07 -04:00
Desiree Beck 9b8672cfe4 Merge pull request #50 from ryantxu1/html-changes
Objective Header Format
2022-08-22 12:18:08 -04:00
Ryan Xu 7dd6670274 Merge branch 'MBCProject:master' into html-changes 2022-08-22 12:08:11 -04:00
ryan da26628e86 Objective Header format 2022-08-22 12:07:27 -04:00
Desiree Beck 1410cd6076 Merge pull request #49 from ryantxu1/html-changes
ATT&CK/MBC reference formatting + typos
2022-08-22 12:00:51 -04:00
ryan 22ac38a876 Merge branch 'html-changes' of https://github.com/ryantxu1/mbc-markdown into html-changes 2022-08-22 11:12:44 -04:00
Ryan Xu 643fefd7b3 Merge branch 'MBCProject:master' into html-changes 2022-08-22 11:12:46 -04:00
ryan 7168b1040a Typo/formatting fixes 2022-08-22 11:12:16 -04:00
ryan 9d2dc7d065 ATT&CK + MBC reference consistent formatting 2022-08-22 10:59:49 -04:00
Dez Beck ff05de6422 fix typos 2022-08-21 13:12:04 -04:00
Desiree Beck 804b913cb4 Merge pull request #48 from ryantxu1/html-changes
HTML tables inside Markdown
2022-08-19 10:29:22 -04:00
ryan d9e84725bf HTML tables inside Markdown 2022-08-18 15:15:00 -04:00
Desiree Beck 7c70e41d7b Merge pull request #46 from MBCProject/example-readme
Example readme
2022-08-15 12:13:57 -04:00
Dez Beck a2b581728a add example IDs 2022-08-15 12:12:17 -04:00
Desiree Beck 7c769c8e3c Merge pull request #47 from MBCProject/capa-rule-page
Capa rule page
2022-08-15 12:03:04 -04:00
Dez Beck e5b8278174 add capa rule distribution info 2022-08-15 12:01:32 -04:00
Dez Beck 61b5dfb051 add capa rule distribution info 2022-08-15 11:58:58 -04:00
Dez Beck 950cfca2cc add capa rule distribution info 2022-08-15 11:54:21 -04:00
Dez Beck 4d7c7f6dad add capa rule distribution info 2022-08-15 11:50:22 -04:00
Dez Beck 79b42cba12 add capa rule distribution info 2022-08-15 11:49:32 -04:00
Dez Beck 2a9bcd3ab5 add capa rule distribution info 2022-08-15 11:48:36 -04:00
Dez Beck 1ed65e2692 add capa rule distribution info 2022-08-15 11:39:43 -04:00
Dez Beck ddfc129ba1 add capa rule distribution info 2022-08-15 11:36:36 -04:00
Dez Beck 40db622ee7 add capa rule distribution info 2022-08-15 11:33:43 -04:00
Dez Beck 017d263ebb add capa rule distribution info 2022-08-15 11:16:56 -04:00
Dez Beck 3e16f10c35 add capa rule distribution info 2022-08-15 11:12:42 -04:00
Dez Beck 6d560ed105 add capa rule distribution info 2022-08-15 11:06:02 -04:00
Dez Beck ac3e8b6859 update corpus overview text 2022-08-14 13:20:07 -04:00
Dez Beck c2500c8f3f update corpus overview text 2022-08-14 13:17:55 -04:00
Dez Beck 9932beb512 update corpus overview text 2022-08-14 13:15:27 -04:00
Dez Beck 0ed931a0d8 update corpus overview text 2022-08-14 13:12:43 -04:00
Dez Beck 34c87921d5 update corpus overview text 2022-08-14 13:08:54 -04:00
Dez Beck f0f0235353 update corpus overview text 2022-08-12 19:06:05 -04:00
Dez Beck 5e3a5cedf7 update corpus overview text 2022-08-12 18:58:55 -04:00
Dez Beck a5a31f2f63 update corpus overview text 2022-08-12 18:52:39 -04:00
Desiree Beck ff57a87f7f Merge pull request #45 from ryantxu1/corpus2
Added 'Enhanced ATT&CK Techniques' section
2022-08-10 16:46:56 -04:00
Ryan Xu 24dca9d9c9 Merge branch 'MBCProject:master' into corpus2 2022-08-10 16:42:20 -04:00
Desiree Beck 30f31bd245 Merge pull request #40 from ryantxu1/corpus
Enhanced malware corpus & update file names to match behaviors
2022-08-10 16:22:26 -04:00
ryan 7fe9a48518 Added 'Enhanced ATT&CK Techniques' section 2022-08-10 15:40:57 -04:00
ryan d8ba02ab00 bagle typo 2022-08-10 11:26:25 -04:00
ryan cd7b66d5b9 Adding PR feedback 2022-08-09 14:34:00 -04:00
ryan c544962577 Merge remote-tracking branch 'origin/master' into corpus 2022-08-09 14:14:11 -04:00
Desiree Beck a13dceeb1d Merge pull request #43 from MBCProject/mbc-table
Added table of MBC behaviors.
2022-08-09 14:13:23 -04:00
ryan 19be37cdd4 Merge remote-tracking branch 'origin/master' into corpus 2022-08-09 14:13:15 -04:00
Dez Beck 95b1f2e854 mbc table and faq update 2022-08-09 14:11:10 -04:00
Dez Beck 42520d3108 add MBC table 2022-08-09 14:05:51 -04:00
Dez Beck a1efa1509c add MBC table 2022-08-09 14:02:51 -04:00
Dez Beck 98b2fe9c8a add MBC table 2022-08-09 13:57:16 -04:00
Dez Beck a7fe0c17eb add MBC table 2022-08-09 13:55:28 -04:00
Dez Beck a6624a0eef add MBC table 2022-08-09 13:52:55 -04:00
Dez Beck 10d4eaf12d add MBC table 2022-08-09 13:50:24 -04:00
Dez Beck c5b4a95793 add MBC table 2022-08-09 13:38:26 -04:00
Desiree Beck 3e49062c21 Merge pull request #42 from MBCProject/mbc-predef
made text consistent for att&ck techniques defined after mbc behaviors were defined.
2022-08-09 11:37:54 -04:00
Dez Beck b2502e69eb mbc behavior related techniques 2022-08-09 11:36:10 -04:00
Dez Beck bf7da3f24f mbc behavior related techniques 2022-08-09 11:34:45 -04:00
Dez Beck b934db3501 mbc behavior related techniques 2022-08-09 11:29:30 -04:00
Dez Beck ff5678fddd mbc behavior related techniques 2022-08-09 11:08:18 -04:00
Dez Beck a9b6502475 typo fix 2022-08-07 13:13:20 -04:00
Dez Beck b921f533e3 fix typo 2022-08-07 12:35:52 -04:00
Desiree Beck 64864b7c86 Merge pull request #41 from MBCProject/mbc-objectives
Mbc objectives
2022-08-06 11:27:45 -04:00
Dez Beck e0b0e039c7 update objective descriptions 2022-08-06 11:25:09 -04:00
Dez Beck c8114ef336 fix formatting 2022-08-06 11:21:15 -04:00
Dez Beck 486c764c1b fix formatting 2022-08-06 10:59:06 -04:00
Dez Beck a4e9e9ec12 update objective descriptions 2022-08-06 10:51:27 -04:00
Dez Beck a040511b06 update copyright 2022-08-04 19:58:17 -04:00
Dez Beck 9a4629884f update objective descriptions 2022-08-04 19:56:19 -04:00
ryan 9463964215 Merge branch 'MBCProject-master' into corpus 2022-08-02 11:14:55 -04:00
ryan 34e355110a Merge branch into MBCProject-master 2022-08-02 11:14:27 -04:00
ryan e07e00f4d4 Enhanced malware corpus & update file names to match behaviors 2022-08-02 10:32:52 -04:00
Desiree Beck 48a1f3615d Merge pull request #38 from MBCProject/mbc-mobv11
Mobile v11-beta updates
2022-08-01 14:26:16 -04:00
Dez Beck 52b3e23281 changes for Mobile v11-beta techniques 2022-08-01 13:55:27 -04:00
Dez Beck 2a6cb7a397 changes for Mobile v11-beta techniques 2022-08-01 13:54:45 -04:00
Dez Beck cbceef7c44 changes for Mobile v11-beta techniques 2022-08-01 13:44:33 -04:00
Dez Beck 0966565798 changes for Mobile v11-beta techniques 2022-08-01 13:43:30 -04:00
Dez Beck f71ff004fa changes for Mobile v11-beta techniques 2022-08-01 13:36:18 -04:00
Dez Beck 9e473ed965 changes for Mobile v11-beta techniques 2022-08-01 13:25:18 -04:00
Dez Beck 0db4607e2f changes for Mobile v11-beta techniques 2022-08-01 13:17:13 -04:00
Dez Beck 286c0106c4 mobile v11 updates 2022-07-26 22:25:43 -04:00
Dez Beck 7287afb877 mobile v11 updates 2022-07-25 22:05:04 -04:00
Dez Beck f6d2f58b7c mobile v11 updates 2022-07-25 22:03:10 -04:00
Desiree Beck fb9882c0b9 Merge pull request #37 from MBCProject/mbc-entv11
Enterprise v11 updates
2022-07-25 17:20:54 -04:00
Dez Beck b6b1a12db1 changes for Enterprise v11 techniques 2022-07-25 17:16:09 -04:00
Dez Beck 9791a68096 changes for Enterprise v11 techniques 2022-07-25 17:07:51 -04:00
Dez Beck 975c21c7bc fix ID 2022-06-11 19:29:27 -04:00
Dez Beck 5a57d01e4e Merge branch 'master' of https://github.com/MBCProject/mbc-markdown 2022-06-10 11:58:41 -04:00
Dez Beck 8092d86ae3 fix typo 2022-06-10 11:58:21 -04:00
Desiree Beck ff62030726 Merge pull request #36 from djhaynes/master
Various updates to align with ATT&CK v11 - looks great!
2022-06-09 11:02:58 -04:00
Danny Haynes e1b1756c93 Update hijack-execution-flow.md
Fixed reference identifier.
2022-06-03 14:22:40 -04:00
Danny Haynes 4e6d8a44aa Update hijack-execution-flow.md
Unbolded text to be consistent with other text.
2022-06-03 14:21:56 -04:00
Danny Haynes ce6453a692 Update hijack-execution-flow.md
Merged Hooking behavior content into Hijack Execution Flow behavior.
2022-06-03 14:20:38 -04:00
Danny Haynes c648c032a3 Update self-deletion.md
Adding space between techniques.
2022-06-03 14:17:05 -04:00
Danny Haynes cb553d3681 Update self-deletion.md
Updating behavior to also reference Indicator Removal on Host: Uninstall Malicious Application (T1630.001).
2022-06-03 14:16:35 -04:00
Danny Haynes 40ddc39e3c Update README.md
Removing Hooking behavior as material was moved into Hijack Execution Flow behavior.
2022-06-03 14:12:41 -04:00
Danny Haynes 556c01f636 Delete hooking.md
Deleting Hooking behavior as the content will be merged Hijack Execution Flow behavior.
2022-06-03 14:11:58 -04:00
Danny Haynes 67c9b4d30c Update data-destruction.md
Removing "Delete Device Data / Indicator Removal on Host: File Deletion" since that is covered under Self Deletion.
2022-06-03 10:53:10 -04:00
Danny Haynes 08b41c057f Update config-mod.md
Updated to be its own behavior because the ATT&CK v11 technique (Subvert Trust Controls: Code Signing Policy Modification) is too narrowly scoped for what malware can do.
2022-06-03 10:25:05 -04:00
Danny Haynes 2524861df3 Update README.md
Updated "Generate Fraudulent Revenue" to "Generate Network Traffic from Victim".
2022-06-03 08:12:53 -04:00
Danny Haynes 2f87c60a47 Delete generate-fraud-rev.md
Removing in favor of adding new behavior for "Generate Traffic from Victim" technique.
2022-06-03 08:05:42 -04:00
Danny Haynes dcdc71c325 Create generate-traffic-from-victim.md
Created a new behavior for generating traffic from the victim system to encompass generating fraudulent ad revenue.
2022-06-03 05:24:27 -04:00
Danny Haynes 7375cf16c6 Update exploit-kit-behavior.md
Changing title from "Exploit Kit Behavior" to "Exploit Kit" since none of the other behaviors have "Behavior" in the title.
2022-06-02 16:47:39 -04:00
Danny Haynes 8b97ca31cd Update hide-artifacts.md
Changed behavior name from "Hidden Artifacts" to "Hide Artifacts" to align with ATT&CK technique.
2022-06-02 15:01:05 -04:00
Danny Haynes af0350ec08 Update component-firmware.md
Updated behavior description to align with ATT&CK technique.
2022-06-02 14:56:37 -04:00
Danny Haynes f97bfd8794 Update remote-copy.md
Updated behavior name from "Remote File Copy" to "Ingress Tool Transfer" to align with ATT&CK technique (T1105).
2022-06-02 12:49:08 -04:00
Dez Beck af8df39833 fix typos 2022-05-27 16:50:26 -04:00
Dez Beck ee207f35a3 test fix 2022-05-26 19:56:11 -04:00
Desiree Beck 6449769ac2 Update README.md
fix identifier typo
2022-05-01 22:17:14 -04:00
Desiree Beck 077d21c73c remove duplicate list item 2022-03-10 10:26:32 -05:00
Emmanuelle Vargas-Gonzalez 813557e591 Update README.md 2022-02-05 20:16:52 -05:00
Emmanuelle Vargas-Gonzalez ed5892d24b update text for v2.2 2022-02-05 19:58:09 -05:00
Emmanuelle Vargas-Gonzalez 2facfec1a5 update svg files for v2.2 2022-02-05 19:32:12 -05:00
Emmanuelle Vargas-Gonzalez 6908afc46c Update README.md 2022-01-31 19:37:16 -05:00
Emmanuelle Vargas-Gonzalez 610f5987e8 Update README.md 2022-01-31 19:36:51 -05:00
Emmanuelle Vargas-Gonzalez ba705ca09e Update decompress.md 2022-01-31 10:03:10 -05:00
Desiree Beck 1129ca7fb8 correct ids 2021-12-14 15:26:19 -05:00
Desiree Beck bf1dfa48ab update methods 2021-12-14 15:22:23 -05:00
Desiree Beck c00fc1ffa9 add two methods 2021-12-14 14:56:39 -05:00
Desiree Beck 7827b3aae4 expand description 2021-12-14 14:55:17 -05:00
Desiree Beck bb1fac5043 improve text 2021-12-14 14:54:36 -05:00
Desiree Beck a57e9877bf update for capa 2.0 mappings 2021-11-10 09:47:26 -05:00
Desiree Beck b0c11f1d27 add rootkit-related methods 2021-11-08 12:18:21 -05:00
Desiree Beck 5973e9ed53 add rootkit-related methods 2021-11-08 12:09:17 -05:00
Desiree Beck 77fcac8a7b fix typo 2021-09-30 09:22:28 -04:00
Desiree Beck 71ca24ac1e typo fix 2021-09-08 21:20:16 -04:00
Desiree Beck 1a7004b446 Merge pull request #34 from ryantxu1/capa2.0-changes
Capa2.0 changes
2021-09-08 21:14:30 -04:00
Ryan Xu 81d5cfcc3e Update move-file.md 2021-08-31 11:37:40 -05:00
Ryan Xu 9b7f830ea5 Update enumerate-threads.md 2021-08-31 11:37:21 -05:00
Ryan Xu d4be3586f3 Update process-inject.md 2021-08-31 11:34:19 -05:00
Ryan Xu 41868fd892 Added new mappings for capa2 2021-08-30 09:40:09 -05:00
Desiree Beck 457b3ffc5e update hooking methods 2021-07-12 15:59:33 -04:00
Desiree Beck ce075ef813 new technique, issue #32 2021-06-26 23:08:39 -04:00
Desiree Beck d90c97259c Merge pull request #33 from boot2generic/anti-behavioral-analysis
Adding findings from Manual V.S. Automated analysis review
2021-06-25 12:28:13 -04:00
Desiree Beck 4b21e889ef fix typos 2021-06-25 12:25:49 -04:00
boot2generic 2da03d54cf Adding findings from Manual V.S. Automated analysis review 2021-06-24 14:40:28 -04:00
Emmanuelle Vargas-Gonzalez cd945062f1 Update detect-sandbox.md
add asm code syntax highlighting
2021-05-12 14:31:38 -04:00
Desiree Beck 41d63c6ba0 update ID number 2021-04-21 22:46:41 -04:00
Desiree Beck f1b45c1d0e Merge pull request #31 from malwarefrank/exec-depend
add Execution Dependency
2021-04-21 22:42:54 -04:00
Desiree Beck 6828164c2d Merge pull request #30 from malwarefrank/c2-methods
Add several Methods to Command and Control.
2021-04-21 10:48:20 -04:00
malwarefrank a9870c628a add Execution Dependency 2021-04-20 02:58:03 +00:00
malwarefrank 9d4cf70b4d Add several Methods to Command and Control.
- Authenticate
- Directory listing
- Execute file
- Execute shell command
- File search
- Start interactive shell
2021-04-20 02:34:12 +00:00
Emmanuelle Vargas-Gonzalez 115d7f39d7 update svg graphics 2021-04-15 18:32:39 -04:00
Desiree Beck 1e34931072 update content per issue 27 2021-04-15 11:58:50 -04:00
Desiree Beck f4a3a74727 Merge pull request #29 from malwarefrank/cnc-implant
Use less ambiguous implant/controller terms
2021-04-14 11:36:44 -04:00
malwarefrank 5c3147ff60 change command and control (cnc) wording to use less ambiguous implant/controller 2021-04-12 21:46:40 -04:00
Desiree Beck d7c814302b formatting 2021-04-11 13:52:53 -04:00
Desiree Beck 49038fa484 remove redundancy of behaviors 2021-04-11 13:49:07 -04:00
Desiree Beck 968b94e64b fix formatting 2021-04-11 11:51:49 -04:00
Desiree Beck 2e0245bf9a add method 2021-04-11 11:42:20 -04:00
Desiree Beck 0bf66d6231 formatting 2021-03-15 13:23:45 -04:00
Desiree Beck 974f8c212a formatting 2021-03-15 13:18:45 -04:00
Desiree Beck 6ad2921191 formatting 2021-03-15 13:17:50 -04:00
Desiree Beck 35d73c5606 formatting 2021-03-15 13:16:43 -04:00
Desiree Beck 66dc492f9e tou content 2021-03-15 13:13:42 -04:00
Emmanuelle Vargas-Gonzalez 248207bd4b minor link issue in SVG 2021-02-10 14:41:55 -05:00
Emmanuelle Vargas-Gonzalez 14e747fc1f minor link issue in SVG 2021-02-10 10:15:35 -05:00
Emmanuelle Vargas-Gonzalez 052ad8283c update SVGs for MBC v2.1 2021-02-10 02:18:37 -05:00
Emmanuelle Vargas-Gonzalez e0fffe4d5c update internal links 2021-02-09 19:26:58 -05:00
Desiree Beck 859544e548 update text for v2.1 2021-02-09 13:42:54 -05:00
Desiree Beck e966d8aed7 Merge branch 'master' of https://github.com/MBCProject/mbc-markdown 2021-02-08 12:32:27 -05:00
Desiree Beck f109dc51e0 update text 2021-02-08 12:31:47 -05:00
Emmanuelle Vargas-Gonzalez b03c99f6f5 Merge pull request #22 from MBCProject/mbc-updates-p5
mbc 2.1 updates p5
2021-01-20 16:36:13 -05:00
Desiree Beck 42028462cd alphabetize methods 2021-01-17 19:52:15 -05:00
Desiree Beck 7557f6e586 add methods for capa mapping 2021-01-17 19:48:28 -05:00
Desiree Beck 0f6be9ff0c update readme lists 2021-01-17 19:47:44 -05:00
Desiree Beck bd95692b9e add behs for capa mapping 2021-01-17 19:47:01 -05:00
Desiree Beck ed7ca2a97e expand disable security tool to include evasion 2021-01-17 19:44:24 -05:00
Desiree Beck 271092a6a9 add micro behs per 0x534a comment 2021-01-14 13:30:11 -05:00
Desiree Beck c688df3c0c add micro behs per 0x534a comment 2021-01-14 13:28:54 -05:00
Emmanuelle Vargas-Gonzalez cc1b649e77 update main README to include MBC Matrix 2021-01-11 14:19:50 -05:00
Desiree Beck a29e07bee2 update faq 2021-01-04 15:36:01 -05:00
Desiree Beck b87371ce86 Merge branch 'master' of https://github.com/MBCProject/mbc-markdown 2021-01-04 15:32:34 -05:00
Desiree Beck f60855e3b0 update faq 2021-01-04 15:30:45 -05:00
Desiree Beck efcea74ba0 Update README.md
add tool mapping info
2021-01-04 13:57:24 -05:00
Desiree Beck f6335e7ca5 add method 2020-12-29 15:40:46 -05:00
Desiree Beck d17c52f4c4 missing beh 2020-12-29 14:54:58 -05:00
Desiree Beck 28daf463db missing beh 2020-12-29 14:54:22 -05:00
Desiree Beck 083d599a80 formatting change 2020-12-23 14:45:37 -05:00
Desiree Beck d202803387 update formatting 2020-12-23 14:15:57 -05:00
Desiree Beck bf008e50af expand description 2020-12-23 14:12:46 -05:00
Desiree Beck 03d47b6132 add snippet 2020-12-23 14:11:32 -05:00
Desiree Beck 24c6946732 add method 2020-12-23 14:11:08 -05:00
Desiree Beck 7ea2aaee05 fix formatting 2020-12-12 12:28:52 -05:00
Emmanuelle Vargas-Gonzalez fe28548c49 Merge pull request #20 from MBCProject/mbc-2.1-updates-p4
update content to support capa mapping
2020-12-07 13:51:38 -05:00
Desiree Beck e89098ec73 associating shadow drive with disk content wipe instead of data destruction 2020-12-04 15:45:59 -05:00
Desiree Beck 0a6c7dede6 update content to support capa mapping 2020-12-04 12:30:07 -05:00
Emmanuelle Vargas-Gonzalez 9a177f67b5 add content for new MBC Matrix 2020-11-12 17:09:19 -05:00
Desiree Beck e72f620fec add snippet 2020-11-12 11:23:34 -05:00
Desiree Beck a3b719feac add snippet 2020-11-12 11:13:54 -05:00
Desiree Beck 93c17e23bb add snippet 2020-11-12 11:13:03 -05:00
Desiree Beck 7c505a8d54 add snippet 2020-11-12 11:11:01 -05:00
Desiree Beck f33b64450f Merge branch 'master' of https://github.com/MBCProject/mbc-markdown 2020-10-29 11:56:24 -04:00
Desiree Beck dd9f1a49c2 remove old link 2020-10-29 11:55:50 -04:00
Emmanuelle Vargas-Gonzalez ee203c560f Merge pull request #19 from MBCProject/mbc-2.1-updates-p3
mbc 2.1 updates p3
2020-10-19 14:21:14 -04:00
Emmanuelle Vargas-Gonzalez da38b519c8 minor formatting... 2020-10-19 14:19:59 -04:00
Desiree Beck 376dedeb7b fix method descriptions 2020-10-16 12:49:09 -04:00
Desiree Beck 6ca7ab1abe update readme file table format 2020-10-15 11:08:18 -04:00
Desiree Beck 29b9bcb718 update readme format 2020-10-14 19:21:27 -04:00
Desiree Beck 2ac0ab1dc9 update methods 2020-10-14 15:05:18 -04:00
Desiree Beck 258a0f9505 update text 2020-10-14 13:45:05 -04:00
Desiree Beck fdfeb243d6 update text 2020-10-14 13:31:34 -04:00
Desiree Beck c1582b2154 add microbehaviors 2020-10-14 13:30:29 -04:00
Desiree Beck 19e07cc26f update method text 2020-10-14 13:29:52 -04:00
Desiree Beck 46cfb30300 updates for capa mapping 2020-10-13 18:38:44 -04:00
Desiree Beck 7ff8aa8713 add method 2020-10-11 12:27:35 -04:00
Desiree Beck c4dddba7d9 Merge branch 'master' of https://github.com/MBCProject/mbc-markdown into master 2020-10-11 12:17:06 -04:00
Desiree Beck c9aee04283 add method 2020-10-11 12:16:19 -04:00
Desiree Beck f175b7e0be Update README.md 2020-10-05 10:24:51 -04:00
Desiree Beck d9af0e5834 Update README.md
update VB2020 link
2020-10-05 10:24:23 -04:00
Emmanuelle Vargas-Gonzalez a828f02795 Merge pull request #17 from MBCProject/mbc-2.1-updates
Updates to MBC communication micro-behaviors
2020-09-30 11:48:57 -04:00
Emmanuelle Vargas-Gonzalez 536f884758 final changes to PR 2020-09-30 11:40:57 -04:00
Desiree Beck 6d7cc638d4 added text about method ordering 2020-09-30 09:46:38 -04:00
Desiree Beck a3edfa54e8 Merge pull request #16 from fr0gger/master
Updating link to Unprotect Project (Malware Evasion Techniques DB). 
@fr0gger Thanks!
2020-09-25 14:50:48 -04:00
Desiree Beck 8841eb32d4 updated based on capa mapping 2020-09-25 14:25:18 -04:00
Thomas Roccia e47cf276f7 Update README.md 2020-09-24 17:00:35 +02:00
Thomas Roccia e02767caef Update evade-debugger.md 2020-09-24 16:59:46 +02:00
Thomas Roccia 716aff8bd2 Update detect-vm.md 2020-09-24 16:59:05 +02:00
Thomas Roccia 73dd104efa Update detect-emulator.md 2020-09-24 16:58:31 +02:00
Thomas Roccia 8307ba5c4e Update README.md 2020-09-24 16:57:42 +02:00
Desiree Beck a9db388317 add method 2020-09-13 12:05:58 -04:00
Emmanuelle Vargas-Gonzalez 060d2fcba8 resolve ID clash conflict 2020-08-26 22:21:18 -04:00
Desiree Beck f89cbccdd7 Update README.md 2020-08-26 11:14:24 -04:00
Desiree Beck c7af1687ad Update README.md 2020-08-26 11:12:03 -04:00
Emmanuelle Vargas-Gonzalez 78a84c74b4 small fixes on reference urls 2020-08-25 20:05:56 -04:00
Desiree Beck a2e78f2ea4 Merge pull request #14 from malwarefrank/minortyops
fix small typos in FAQ
2020-08-23 09:27:24 -04:00
malwarefrank ade5b26988 fix small typos in FAQ 2020-08-22 22:37:26 -04:00
Desiree Beck 7bca9d6a64 Merge pull request #13 from MBCProject/minor-fixes-in-content-normalizing-text
Content Normalization & Overall Improvements
2020-08-22 01:28:52 -04:00
Emmanuelle Vargas-Gonzalez 01a7d974d8 Update README.md 2020-08-21 19:17:55 -04:00
Emmanuelle Vargas-Gonzalez 6d29b37130 Update README.md 2020-08-21 19:15:06 -04:00
Emmanuelle Vargas-Gonzalez a265c73431 couple of relative path fixes for micro-behaviors 2020-08-21 18:06:30 -04:00
Emmanuelle Vargas-Gonzalez b7197c785d make all internal references relative 2020-08-21 17:49:32 -04:00
Emmanuelle Vargas-Gonzalez 59b66b0844 same procedure for micro-behaviors 2020-08-21 16:31:12 -04:00
Emmanuelle Vargas-Gonzalez 28028ce5c6 shift Methods columns, sort alphabetically 2020-08-21 16:00:03 -04:00
Emmanuelle Vargas-Gonzalez 1c4eef4c69 consistency changes for behaviors than had more dependencies 2020-08-21 15:50:22 -04:00
Emmanuelle Vargas-Gonzalez f4af7f5769 updates to tables, wrong ids 2020-08-21 11:34:24 -04:00
Emmanuelle Vargas-Gonzalez 76d72bf9fc Merge branch 'master' of github.com:MBCProject/mbc-markdown into minor-fixes-in-content-normalizing-text 2020-08-20 16:23:47 -04:00
Emmanuelle Vargas-Gonzalez c0a7760da9 Remove MBC-beta mention from FAQ 2020-08-20 16:08:50 -04:00
Emmanuelle Vargas-Gonzalez 3e5d257030 Normalizing tables, dividers, style layout, minor content typos 2020-08-20 16:05:08 -04:00
Desiree Beck 4f381c5ae4 update info on objectives 2020-08-19 11:11:00 -04:00
Desiree Beck ed2a32e60b Merge pull request #11 from emmanvg/move-to-v2.0
Move changes for MBC v2.0
2020-08-17 14:28:07 -04:00
Emmanuelle Vargas-Gonzalez 74d816deb1 update mbc-beta hyperlinks to mbc-markdown equivalents 2020-08-14 14:54:01 -04:00
Emmanuelle Vargas-Gonzalez 2207d845ae move and replace MBCProject/mbc-markdown with contents from MBCProject/mbc-beta 2020-08-14 14:37:45 -04:00
452 changed files with 27257 additions and 4584 deletions
+15
View File
@@ -0,0 +1,15 @@
cff-version: 1.2.0
message: "If you use the Malware Behavior Catalog, please cite it as below."
authors:
- name: MITRE
title: "Malware Behavior Catalog"
version: 3.0
url: "https://github.com/MBCProject/mbc-markdown"
type: dataset
abstract: The Malware Behavior Catalog (MBC) is a catalog of malware objectives and behaviors, created to support malware analysis-oriented use cases, such as labeling, similarity analysis, and standardized reporting.
keywords:
- malware behavior
- malware objective
- malware analysis
- malware behavior catalog
- mbc
+136 -23
View File
@@ -1,38 +1,151 @@
# <a name="mbc"></a>Malware Behavior Catalog #
The Malware Behavior Catalog (MBC) is a catalog of malware objectives and behaviors, created to support malware analysis-oriented use cases, such as labeling, similarity analysis, and standardized reporting. Please see the [FAQ](https://github.com/MBCProject/mbc-markdown/blob/master/yfaq/README.md) page for answers to common questions.
# <a name="mbc"></a>Malware Behavior Catalog v3.1 #
The Malware Behavior Catalog (MBC) is a catalog of malware objectives and behaviors, created to support malware analysis-oriented use cases, such as labeling, similarity analysis, and standardized reporting. Please see the [FAQ](./yfaq/README.md) page for answers to common questions, and read the [newsletters](./ynewsletters/README.md) for information on the most recent MBC updates and activity.
Check out the [MBC presentation](https://www.youtube.com/watch?v=KY8Ty-0sdVU) given at BSides DC (October 2019).
Open-source malware analysis tools map their output to MBC and ATT&CK:
* [capa](https://github.com/fireeye/capa-rules) - see the [capa rule mapping distribution](./capa.md)
* [CAPE](https://github.com/kevoreilly/community/tree/master/modules/signatures) - see the [CAPE signature mapping distribution](./cape.md)
MBC supports other community efforts:
* [CACAO](https://www.oasis-open.org/committees/tc_home.php?wg_abbrev=cacao) - a [playbook](https://github.com/oasis-tcs/cacao/tree/master/Examples/CACAO-2.0) for the MBC corpus malware [Locky Bart](./xample-malware/locky-bart.md) shows how CACAO can reference MBC behaviors.
* [Attack Flow](https://github.com/center-for-threat-informed-defense/attack-flow/tree/main/corpus) - flow diagrams for the MBC corpus malware [Shamoon](./xample-malware/shamoon.md) and [SearchAwesome](./xample-malware/searchawesome.md) illustrate how Attack Flow can reference MBC behaviors.
Check out MBC presentations:
* [Standardized Reporting with the Malware Behavior Catalog](https://youtu.be/qZef-SoREdY), VB2020 localhost (October 2020)
* [Malware Behavior Catalog](https://youtu.be/KY8Ty-0sdVU), BSides DC (October 2019)
To join the **MBC mailing list**, please send a request to mbc@mitre.org.
### Objectives ###
As shown below, thirteen objectives are defined. Two are specific to malware analysis and are not defined in ATT&CK: ANTI-BEHAVIORAL ANALYSIS and ANTI-STATIC ANALYSIS. Eleven are based on ATT&CK tactics and are tailored for malware analysis use cases.
As shown below, malware objectives are based on [ATT&CK tactics](https://attack.mitre.org/tactics/enterprise/), and are tailored for the malware analysis use case of characterizing malware based on known objectives and behaviors. Two malware analysis-specific objectives not in ATT&CK are also defined (ANTI-BEHAVIORAL ANALYSIS and ANTI-STATIC ANALYSIS).
### Behaviors ###
Under each objective, MBC captures all behaviors and code characteristics discovered during malware analysis, with links to [ATT&CK Techniques](https://attack.mitre.org/techniques/enterprise/) as appropriate. Names of MBC behaviors may or may not match related ATT&CK techniques. Any content provided on behavior pages is *supplemental* to ATT&CK content. In other words, ATT&CK content is not duplicated in MBC, and MBC users will want to reference ATT&CK while capturing malware behaviors.
Under each objective, MBC captures all behaviors and code characteristics discovered during malware analysis, with links to [ATT&CK techniques](https://attack.mitre.org/techniques/enterprise/) as appropriate. Names of MBC behaviors may or may not match related ATT&CK techniques. Any content provided on behavior pages is *supplemental* to ATT&CK content. In other words, ATT&CK content is not duplicated in MBC, and MBC users will reference ATT&CK while capturing malware behaviors.
### Methods ###
Methods are associated with behaviors and serve different roles, depending on the behavior. In some cases, a method further refines a behavior (i.e., sub-behavior); in other cases, a method is an implementation of a behavior. Previously, methods had no ATT&CK counterpart, but beginning in April 2020, ATT&CK defines sub-techniques, which are similar to methods.
Note that a method cannot be used without a behavior.
### Micro-objectives / Micro-behaviors ###
Some malware behaviors are low-level, support many objectives and other behaviors, and aren't necessarily malicious. For example, a TCP socket may be created, or a string may be checked for some condition. Because such behaviors are often noted in malware analysis, they are captured in MBC. See [Micro-behaviors](./micro-behaviors/README.md) for details.
### <a name="ids"></a>Identifiers ###
The first letter of a behavior identifier indicates whether the behavior is a stub referencing an ATT&CK technique ("T", matching the ATT&CK identifier; e.g. T1234), whether it enhances an ATT&CK technique with malware-specific details ("E"; e.g. E1234), or whether it is a newly defined behavior in MBC ("M"; e.g. M1234). When two or more MBC behaviors refine the same ATT&CK technique, each is given an MBC identifier and each references the ATT&CK identifier. When a new ATT&CK technique is defined *after* an MBC behavior has been defined, the preexisting MBC identifier is preserved and the new ATT&CK identifier is referenced.
As shown below, the letter of an identifier relays information about a behavior. Note that letters used in MBC v2 and v3 are changed from MBC v1.
### Example Malware ###
The MBC also contains a collection of [example malware](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/) that are characterized with malware behaviors.
|**Letter**|**Example**|**Description**|
|---|---|---|
|**B**|*B0040*|An MBC behavior.|
|**C**|*C0015*|An MBC micro-behavior.|
|**T**|*T1234*|An ATT&CK technique.|
|**E**|*E1234*|An ATT&CK technique that has been enhanced with malware-specific details. The numerical portion of the identifier will match the ATT&CK ID (e.g., E1234 enhances T1234).|
|**F**|*F0004*|An ATT&CK sub-technique that has been enhanced with malware-specific details.|
Two letters of an identifier relay information about an objective.
|**Letter**|**Example**|**Description**|
|---|---|---|
|**OB**|*OB0001*|An MBC objective.|
|**OC**|*OC0003*|An MBC micro-objective.|
Identifiers of methods are formatted in the same way as ATT&CK sub-techniques. If MBC defines a new method for an existing ATT&CK technique, the identifier is changed from "T" to "E" and an "m" identifier is added (e.g., a method added to T1234 would be denoted *E1234.m01* and is different than *T1234.001*, although both refer to the T1234 ATT&CK technique). Method identifiers of "B", "C", and "F" behaviors are defined without the "m" (e.g., *B0008.009*; *C0005.002*; *F0001.005*).
When two or more MBC behaviors refine the same ATT&CK technique, each is given an MBC identifier and each references the ATT&CK identifier. When a new ATT&CK technique is defined *after* an MBC behavior has been defined, the preexisting MBC identifier is preserved and the new ATT&CK identifier is referenced.
In cases where an MBC behavior enhances a technique/sub-technique that is defined in both ATT&CK Mobile and Enterprise, the "E" identifier used in MBC corresponds to the Enterprise identifier. For example, the Obfuscated Files or Information technique has identifier <a href="https://attack.mitre.org/techniques/T1027/">T1027</a> in Enterprise, identifier <a href="https://attack.mitre.org/techniques/T1406/">T1406</a> in Mobile, and identifier <a href="./defense-evasion/obfuscated-files-or-information.md">E1027</a> in MBC.
### Canonical Representation ###
The canonical representation for MBC content is **OBJECTIVE::Behavior::Method**. For example, *ANTI-BEHAVIORAL ANALYSIS::Debugger Detection::Process Environment Block*.
Objectives and behaviors can be used alone, but a method *must* be associated with a behavior.
### STIX 2.1 Representation ###
A STIX 2.1 representation for MBC v3.1 is available in the [mbc-stix2.1](https://github.com/MBCProject/mbc-stix2.1) repository. It's based on a refined STIX 2.1 [Malware Behavior Extension](https://github.com/oasis-open/cti-stix-common-objects/tree/main/extension-definition-specifications/malware-behavior-8e9) that includes new STIX domain objects for MBC objectives, behaviors, and methods.
### Navigator View ###
This visual representation of the MBC Matrix is based on the ATT&CK Navigator. Two views are available:
* <a href="https://raw.githubusercontent.com/MBCProject/mbc-markdown/master/yfaq/mbc_matrix_with_ids.svg" target="_blank">Matrix with identifiers</a>
* <a href="https://raw.githubusercontent.com/MBCProject/mbc-markdown/master/yfaq/mbc_matrix_without_ids.svg" target="_blank">Matrix without identifiers</a>
### Malware Corpus ###
The MBC contains a [malware corpus](./xample-malware/README.md) where each malware entry is decomposed into behaviors that are mapped to ATT&CK and MBC. The mappings are based on open source malware analysis reports. Note that some malware types are also present in the ATT&CK software page. We refer readers to the corresponding ATT&CK page for a list of identified ATT&CK techniques. However, we will list any newly identified ATT&CK techniques in the MBC malware page.
## Malware Objective Descriptions ##
Malware objectives are defined below. Follow the links to view associated behaviors. Please see the [MBC Matrix](http://maecproject.github.io/ema/index.html) to view all behaviors.
Malware objectives are defined in the table below. Follow the links to view associated behaviors.
|**Objective**|**Description**|
|------------------------------------------------------------------|----------------------------|
|[**Anti-Behavioral Analysis**](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/README.md) |Malware aims to prevent, obstruct, or evade behavioral analysis done in a sandbox, debugger, etc.|
|[**Anti-Static Analysis**](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/README.md)| Malware aims to prevent static analysis or make it more difficult. Simpler static analysis identifies features such as embedded strings, executable header information, hash values, and file metadata. More involved static analysis involves the disassembly of the binary code.|
|[**Collection**](https://github.com/MBCProject/mbc-markdown/blob/master/collection/README.md) | Malware aims to identify and gather information, such as sensitive files, from a target network prior to exfiltration. This objective includes locations on a system or network where the malware may look for information to exfiltrate.|
|[**Command and Control**](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/README.md) |Malware aims to communicate (receive and/or execute remotely submitted commands) with controlling or controlled systems within a target network (C2 servers, bots, etc.).|
|[**Credential Access**](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/README.md)|Malware aims to obtain credential access, allowing it or its underlying threat actor to assume control of an account, with the associated system and network permissions.|
|[**Defense Evasion**](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/README.md)|Malware aims to evade detection or avoid other cybersecurity defenses.|
|[**Discovery**](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/README.md)|Malware aims to gain knowledge about the system and internal network.|
|[**Execution**](https://github.com/MBCProject/mbc-markdown/blob/master/execution/README.md)| Malware aims to execute its code on a system to achieve a variety of goals.|
|[**Exfiltration**](https://github.com/MBCProject/mbc-markdown/blob/master/exfiltration/README.md)| Malware aims to steal data from the system on which it executes. This includes stored data (e.g., files) as well as data input into applications (e.g., web browser).|
|[**Impact**](https://github.com/MBCProject/mbc-markdown/blob/master/impact/README.md)| Malware aims to achieve its mission of manipulating, interrupting, or destroying systems and data.|
|[**Lateral Movement**](https://github.com/MBCProject/mbc-markdown/blob/master/lateral-movement/README.md)|Malware aims to propagate through the infection of a system or is able to infect a file after executing on a system. The malware may infect actively (e.g., gain access to a machine directly) or passively (e.g., send malicious email).|
|[**Persistence**](https://github.com/MBCProject/mbc-markdown/blob/master/persistence/README.md)|Malware aims to remain on a system regardless of system events.|
|[**Privilege Escalation**](https://github.com/MBCProject/mbc-markdown/blob/master/privilege-escalation/README.md)|Malware aims to obtain a higher level of privilege for execution.|
|---|---|
|[**Anti-Behavioral Analysis**](./anti-behavioral-analysis/README.md)|Malware aims to prevent, obstruct, or evade behavioral analysis, such as analysis done using a sandbox or debugger.|
|[**Anti-Static Analysis**](./anti-static-analysis/README.md)|Malware aims to prevent static analysis or make it more difficult.|
|[**Collection**](./collection/README.md)|Malware aims to identify and gather information from a machine or network.|
|[**Command and Control**](./command-and-control/README.md)|Malware aims to communicate with compromised systems to control them.|
|[**Credential Access**](./credential-access/README.md)|Malware aims to steal account names and passwords.|
|[**Defense Evasion**](./defense-evasion/README.md)|Malware aims to evade detection.|
|[**Discovery**](./discovery/README.md)|Malware aims to gain knowledge about the environment.|
|[**Execution**](./execution/README.md)|Malware aims to execute code on a system.|
|[**Exfiltration**](./exfiltration/README.md)|Malware aims to steal data.|
|[**Impact**](./impact/README.md)|Malware aims to manipulate, interrupt, or destroy systems or data.|
|[**Lateral Movement**](./lateral-movement/README.md)|Malware aims to propagate or otherwise move through an environment. Lateral movement may be active, happening via direct machine access, or may be passive (for example, done via malicious email).|
|[**Persistence**](./persistence/README.md)|Malware aims to remain on a system.|
|[**Privilege Escalation**](./privilege-escalation/README.md)|Malware aims to obtain higher level permissions.|
## MBC Behaviors ##
The table below lists MBC behaviors and related ATT&CK techniques. In most cases, related ATT&CK techniques were defined *after* the MBC behavior was defined. Please see the [MBC Summary](./mbc_summary.md) for a listing of all MBC content.
|**ID**|**Objective(s)**|**Behavior**|**Related ATT&CK Technique**|
|---|---|---|---|
|**B0001**|ANTI-BEHAVIORAL ANALYSIS|**Debugger Detection**|*none*|
|**B0002**|ANTI-BEHAVIORAL ANALYSIS|**Debugger Evasion**|Debugger Evasion ([T1622](https://attack.mitre.org/techniques/T1622))|
|**B0003**|ANTI-BEHAVIORAL ANALYSIS|**Dynamic Analysis Evasion**|Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/techniques/T1497),[T1633](https://attack.mitre.org/techniques/T1633))|
|**B0004**|ANTI-BEHAVIORAL|**Emulator Detection**|*none*|
|**B0005**|ANTI-BEHAVIORAL|**Emulator Evasion**|*none*|
|**B0006**|ANTI-BEHAVIORAL|**Memory Dump Evasion**|*none*|
|**B0007**|ANTI-BEHAVIORAL|**Sandbox Detection**|Virtualization/Sandbox Evasion: System Checks ([T1497.001](https://attack.mitre.org/techniques/T1497/001),[T1633.001](https://attack.mitre.org/techniques/T1633/001)); Virtualization/Sandbox Evasion: User Activity Based Checks ([T1497.002](https://attack.mitre.org/techniques/T1497/002))|
|**B0008**|ANTI-BEHAVIORAL ANALYSIS, ANTI-STATIC ANALYSIS|**Executable Code Virtualization**|*none*|
|**B0009**|ANTI-BEHAVIORAL ANALYSIS|**Virtual Machine Detection**|Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/techniques/T1497),[T1633](https://attack.mitre.org/techniques/T1633))|
|**B0010**|ANTI-STATIC ANALYSIS|**Call Graph Generation Evasion**|*none*|
|**B0011**|EXECUTION|**Remote Commands**|*none*|
|**B0012**|ANTI-STATIC ANALYSIS|**Disassembler Evasion**|*none*|
|**B0013**|DISCOVERY|**Analysis Tool Discovery**|*none*|
|**B0014**|DISCOVERY|**SMTP Connection Discovery**|*none*|
|**B0015**|*not defined*|---|---|
|**B0016**|IMPACT|**Compromise Data Integrity**|Data Manipulation: Stored Data Manipulation ([T1565.001](https://attack.mitre.org/techniques/T1565/001))|
|**B0017**|IMPACT|**Destroy Hardware**|*none*|
|**B0018**|IMPACT|**Resource Hijacking**|Resource Hijacking ([T1496](https://attack.mitre.org/techniques/T1496))|
|**B0019**|IMPACT|**Manipulate Network Traffic**|Data Manipulation: Transmitted Data Manipulation ([T1565.002](https://attack.mitre.org/techniques/T1565/002))|
|**B0020**|EXECUTION, LATERAL MOVEMENT|**Send Email**|Phishing ([T1566](https://attack.mitre.org/techniques/T1566))|
|**B0021**|EXECUTION, LATERAL MOVEMENT|**Send Poisoned Email**|*none*|
|**B0022**|IMPACT, PERSISTENCE|**Remote Access**|*none*|
|**B0023**|EXECUTION|**Install Additional Program**|*none*|
|**B0024**|EXECUTION|**Prevent Concurrent Execution**|*none*|
|**B0025**|ANTI-BEHAVIORAL ANALYSIS//EXECUTION|**Conditional Execution**|Execution Guardrails ([T1480](https://attack.mitre.org/techniques/T1480))|
|**B0026**|LATERAL MOVEMENT, PERSISTENCE|**Malicious Network Driver**|*none*|
|**B0027**|DEFENSE EVASION|**Alternative Installation Location**|*none*|
|**B0028**|CREDENTIAL ACCESS|**Cryptocurrency**|*none*|
|**B0029**|DEFENSE EVASION|**Polymorphic Code**|*none*|
|**B0030**|COMMAND AND CONTROL|**Command and Control Communication**|*none*|
|**B0031**|COMMAND AND CONTROL|**Domain Name Generation**|Dynamic Resolution: Domain Name Generation ([T1568.002](https://attack.mitre.org/techniques/T1568/002))|
|**B0032**|ANTI-STATIC ANALYSIS|**Executable Code Obfuscation**|*none*|
|**B0033**|IMPACT|**Denial of Service**|Network Denial of Service ([T1498](https://attack.mitre.org/techniques/T1498))|
|**B0034**|ANTI-STATIC ANALYSIS|**Executable Code Optimization**|*none*|
|**B0035**|PERSISTENCE|**Shutdown Event**|*none*|
|**B0036**|ANTI-BEHAVIORAL ANALYSIS|**Capture Evasion**|*none*|
|**B0037**|DEFENSE EVASION|**Bypass Data Execution Prevention**|*none*|
|**B0038**|DISCOVERY|**Self Discovery**|*none*|
|**B0039**|IMPACT|**Spamming**|*none*|
|**B0040**|DEFENSE EVASION|**Covert Location**|*none*|
|**B0041**|*not defined*|---|---|
|**B0042**|IMPACT|**Modify Hardware**|*none*|
|**B0043**|DISCOVERY|**Taskbar Discovery**|*none*|
|**B0044**|EXECUTION|**Execution Dependency**|*none*|
|**B0045**|ANTI-STATIC ANALYSIS|**Data Flow Analysis Evasion**|*none*|
|**B0046**|DISCOVERY|**Code Discovery**|*none*|
|**B0047**|DEFENSE EVASION, PERSISTENCE|**Install Insecure or Malicious Code**|*none*|
## Citing MBC ##
If you use MBC, please cite it as specified in the [CITATION](./CITATION.cff) file or by using GitHub's sidebar citation widget, which provides both APA and BibTeX formats.
**Copyright © 2021-2023, The MITRE Corporation. [Terms of Use.](./tou.md)**
+30 -23
View File
@@ -1,30 +1,37 @@
|||
|--|-----|
|**ID**|**M9001**|
<table>
<tr>
<td><b>ID</b></td>
<td><b>OB0001</b></td>
</tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>12 June 2023</b></td>
</tr>
</table>
# Anti-Behavioral Analysis
Behaviors that prevent, obstruct, or evade behavioral analysis (sandbox, debugger, etc). Because the underlying methods differ, separate "detection" and "evasion" behaviors are defined for some anti-behavioral analysis areas (e.g., anti-debugger).
Two primary resources for anti-behavioral analysis behaviors are [[1]](#1) and [[2]](#2).
Behaviors that prevent, obstruct, or evade behavioral analysis of malware--for example, analysis done using a sandbox or debugger. Because the underlying methods differ, separate "detection" and "evasion" behaviors are defined for some anti-behavioral analysis areas.
* **Capture Evasion** [M0036](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/evade-capture.md)
* **Debugger Detection** [M0001](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/detect-debugger.md)
* **Debugger Evasion** [M0002](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/evade-debugger.md)
* **Dynamic Analysis Evasion** [M0003](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/evade-dynamic-analysis.md)
* **Emulator Detection** [M0004](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/detect-emulator.md)
* **Emulator Evasion** [M0005](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/evade-emulator.md)
* **Executable Code Virtualization** [M0008](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/exe-code-virtualize.md)
* **Execution Guardrails** [E1480](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/execution-guardrails.md)
* **Hooking** [E1179](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/hooking.md)
* **Memory Dump Evasion** [M0006](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/evade-memory-dump.md)
* **Sandbox Detection** [M0007](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/detect-sandbox.md)
* **Software Packing** [E1045](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/software-packing.md)
* **Virtual Machine Detection** [M0009](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/detect-vm.md)
* **Capture Evasion** [B0036](../anti-behavioral-analysis/capture-evasion.md)
* **Conditional Execution** [B0025](../execution/conditional-execution.md)
* **Debugger Detection** [B0001](../anti-behavioral-analysis/debugger-detection.md)
* **Debugger Evasion** [B0002](../anti-behavioral-analysis/debugger-evasion.md)
* **Dynamic Analysis Evasion** [B0003](../anti-behavioral-analysis/dynamic-analysis-evasion.md)
* **Emulator Detection** [B0004](../anti-behavioral-analysis/emulator-detection.md)
* **Emulator Evasion** [B0005](../anti-behavioral-analysis/emulator-evasion.md)
* **Executable Code Virtualization** [B0008](../anti-static-analysis/executable-code-virtualization.md)
* **Hijack Execution Flow** [F0015](../defense-evasion/hijack-execution-flow.md)
* **Memory Dump Evasion** [B0006](../anti-behavioral-analysis/memory-dump-evasion.md)
* **Sandbox Detection** [B0007](../anti-behavioral-analysis/sandbox-detection.md)
* **Software Packing** [F0001](../anti-static-analysis/software-packing.md)
* **Virtual Machine Detection** [B0009](../anti-behavioral-analysis/virtual-machine-detection.md)
References
----------
<a name="1">[1]</a> Unprotect Project, a database about malware self-defense and protection. http://unprotect.tdgt.org/index.php/Unprotect_Project
## References
<a name="1">[1]</a> https://search.unprotect.it/map/
<a name="2">[2]</a> InDepthUnpacking, course content for teaching malware anti-analysis techniques and mitigations, with emphasis on packers. https://github.com/knowmalware/InDepthUnpacking
@@ -0,0 +1,62 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>B0036</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>None</b></td>
</tr>
<tr>
<td><b>Anti-Analysis Type</b></td>
<td><b>Evasion</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.0</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>18 November 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>1 March 2023</b></td>
</tr>
</table>
# Capture Evasion
Malware has characteristics enabling it to evade capture from the infected system.
## Methods
|Name|ID|Description|
|---|---|---|
|**Encrypted Payloads**|B0036.002|The decryption key is stored external to the executable or never touches the disk.|
|**Memory-only Payload**|B0036.001|Malware is never written to disk (e.g., RAT plugins received from the controller are never written to disk).|
|**Multiple Stages of Loaders**|B0036.003|Multiple stages of loaders are used with an encoded payload.|
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**Vobfus**](../xample-malware/vobfus.md)|2016|B0036.002|Vobfus is downloaded in an encrypted form then decrypted. [[1]](#1)|
|[**TEARDROP**](../xample-malware/teardrop.md)|2018|B0036.001|TEARDROP loads its payload only into memory. [[2]](#2)|
|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0036.001|The malware downloads multiple payloads (as files and DLLs) that are stored in a memory buffer. [[4]](#4)|
|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0036.003|Matanbuchus consists of 2 loaders. [[3]](#3) [[4]](#4)|
## References
<a name="1">[1]</a> https://securitynews.sonicwall.com/xmlpost/revisiting-vobfus-worm-mar-8-2013/
<a name="2">[2]</a> https://www.cisa.gov/uscert/ncas/analysis-reports/ar21-039b
<a name="3">[3]</a> https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/
<a name="4">[4]</a> https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader
@@ -0,0 +1,188 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>B0001</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>None</b></td>
</tr>
<tr>
<td><b>Anti-Analysis Type</b></td>
<td><b>Detection</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.3</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>27 April 2024</b></td>
</tr>
</table>
# Debugger Detection
Malware detects whether it's being executed inside a debugger by checking for artifacts such as DLLs, processes, and registry keys [[1]](#1). If malware detects a debugger, it may change its execution path or change its code to initiate a crash [[2]](#2).
While many methods are listed in the table below, among the most commonly used are:
- Using APIs such as IsDebuggerPresent, CheckRemoteDebuggerPresent, and OutputDebugString
- Reading the BeingDebugged bit (is it a 1 or 0) in the Process Environment Block (PEB)
- Checking whether a software breakpoint instruction is used (INT3; 0xCC opcode)
Details on detecting debuggers can be found in the references.
## Methods
|Name|ID|Description|
|---|---|---|
|**API Hook Detection**|B0001.001|Module bounds based [[7]](#7).|
|**Anti-debugging Instructions**|B0001.034|Malware code contains mnemonics related to anti-debugging (e.g., rdtsc, icebp).|
|**CheckRemoteDebuggerPresent**|B0001.002|The kernel32!CheckRemoteDebuggerPresent function calls NtQueryInformationProcess with ProcessInformationClass parameter set to 7 (ProcessDebugPort constant).This method is related to Unprotect technique U0121.|
|**Check Processes**|B0001.038|The malware may check running processes for specific strings such as "malw" to detect a analysis environment.|
|**CloseHandle**|B0001.003|(NtClose); If an invalid handle is passed to the CloseHandle function and a debugger is present, then an EXCEPTION_INVALID_HANDLE (0xC0000008) exception will be raised. [[7]](#7) This method is related to Unprotect technique U0114.|
|**Debugger Artifacts**|B0001.004|Malware may detect a debugger by its artifact (window title, device driver, exports, etc.).|
|**Hardware Breakpoints**|B0001.005|(SEH/GetThreadContext); Debug registers will indicate the presence of a debugger. See [[7]](#7) for details. This method is related to Unprotect technique U0127.|
|**Interruption**|B0001.006|If an interruption is mishandled by the debugger, it can cause a single-byte instruction to be inadvertently skipped, which can be detected by malware. Examples include Interrupt 0x2d and Interrupt 1 [[7]](#7). This method is related to Unprotect technique U0129.|
|**IsDebuggerPresent**|B0001.008|The kernel32!IsDebuggerPresent API function call checks the PEB BeingDebugged flag to see if the calling process is being debugged. It returns 1 if the process is being debugged, 0 otherwise. This is one of the most common ways of debugger detection.This method is related to Unprotect technique U0122.|
|**Memory Breakpoints**|B0001.009|(PAGE_GUARD); Guard pages trigger an exception the first time they are accessed and can be used to detect a debugger. See [[7]](#7) for details. This method is related to Unprotect technique U0102.|
|**Memory Write Watching**|B0001.010|[[7]](#7)|
|**Monitoring Thread**|B0001.011|Malware may spawn a monitoring thread to detect tampering, breakpoints, etc.|
|**NtQueryInformationProcess**|B0001.012|Calling NtQueryInformationProcess with its ProcessInformationClass parameter set to 0x07 (ProcessDebugPort constant) will cause the system to set ProcessInformation to -1 if the process is being debugged. Calling with ProcessInformationClass set to 0x0E (ProcessDebugFlags) or 0x11 (ProcessDebugObject) are used similarly. Testing "ProcessDebugPort" is equivalent to using the kernel32!CheckRemoteDebuggerPresent API call (see next method). This method is related to Unprotect technique U0120.|
|**NtQueryObject**|B0001.013|The ObjectTypeInformation and ObjectAllTypesInformation flags are checked for debugger detection. This method is related to Unprotect technique U0118.|
|**NtSetInformationThread**|B0001.014|Calling this API with a fake class length or thread handle can indicate whether it is hooked. After calling NtSetInformationThread properly, the HideThreadFromDebugger flag is checked with the NtQueryInformationThread API. [[7]](#7)This method is related to Unprotect technique U0119.|
|**NtYieldExecution/SwitchToThread**|B0001.015|[[7]](#7)|
|**OutputDebugString**|B0001.016|(GetLastError); The OutputDebugString function will demonstrate different behavior depending whether or not a debugger is present. See [[7]](#7) for details. This method is related to Unprotect technique U0117.|
|**Page Exception Breakpoint Detection**|B0001.017|[[7]](#7)|
|**Parent Process**|B0001.018|(Explorer.exe); Executing an application by a debugger will result in the parent process being the debugger process rather than the shell process (Explorer.exe) or the command line. Malware checks its parent process; if it's not explorer.exe, it's assumed to be a debugger. [[7]](#7)|
|**Process Environment Block**|B0001.019|The Process Environment Block (PEB) is a Windows data structure associated with each process that contains several fields, such as "BeingDebugged," "NtGlobalFlag," and "IsDebugged". Testing the value of this PEB field of a particular process can indicate whether the process is being debugged. Testing "BeingDebugged" is equivalent to using the kernel32!IsDebuggerPresent API call (see separate method). This method is related to Unprotect technique U0113.|
|**Process Environment Block BeingDebugged**|B0001.035|The BeingDebugged field is tested to determine whether the process is being debugged.|
|**Process Environment Block IsDebugged**|B0001.037|The IsDebugged field is tested to determine whether the process is being debugged.|
|**Process Environment Block NtGlobalFlag**|B0001.036|The NtGlobalFlag field is tested to determine whether the process is being debugged. This method is related to Unprotect technique U0111.|
|**Process Jobs**|B0001.020|[[7]](#7)|
|**ProcessHeap**|B0001.021|Process heaps are affected by debuggers. Malware can detect a debugger by checking heap header fields such as Flags (debugger present if value greater than 2) or ForceFlags (debugger present if value greater than 0).This method is related to Unprotect technique U0112.|
|**RtlAdjustPrivilege**|B0001.022|Malware may call RtlAdjustPrivilege to detect if a debugger is attached (or to prevent a debugger from attaching).|
|**SeDebugPrivilege**|B0001.023|(Csrss.exe); Using the OpenProcess function on the csrss.exe process can detect a debugger. [[7]](#7)|
|**SetHandleInformation**|B0001.024|(Protected Handle)|
|**Software Breakpoints**|B0001.025|(INT3/0xCC) This method is related to Unprotect technique U0105.|
|**Stack Canary**|B0001.026|Similar to the anti-exploitation method of the same name, malware may try to detect mucking with values on the stack.|
|**TIB Aware**|B0001.027|Malware may access information in the Thread Information Block (TIB) for debug detection or process obfuscation detection. The TIB can be accessed as an offset of the segment register (e.g., fs:[20h]).|
|**TLS Callbacks**|B0001.029|[[7]](#7)|
|**Timing/Delay Check**|B0001.028|Malware may compare time between two points to detect unusual execution, such as the (relative) massive delays introduced by debugging. This method is related to Unprotect techniques U110 and U1308.|
|**Timing/Delay Check GetTickCount**|B0001.032|Malware uses GetTickCount function in a timing/delay check. This method is related to Unprotect technique U0125.|
|**Timing/Delay Check QueryPerformanceCounter**|B0001.033|Malware uses QueryPerformanceCounter in a timing/delay check. This method is related to Unprotect techniques U110 and U1309.|
|**UnhandledExceptionFilter**|B0001.030|The UnhandledExceptionFilter function is called if no registered exception handlers exist, but it will not be reached if a debugger is present. See [[7]](#7) for details. Row 11 This method is related to Unprotect technique U0108.|
|**WudfIsAnyDebuggerPresent**|B0001.031|Includes use of WudfIsAnyDebuggerPresent, WudfIsKernelDebuggerPresent, WudfIsUserDebuggerPresent.|
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**Redhip**](../xample-malware/redhip.md)|2011|--|Redhip uses general approaches to detecting user level debuggers (e.g., Process Environment Block 'Being Debugged' field), as well as specific checks for kernel level debuggers like SOFTICE. [[4]](#4)|
|[**Redhip**](../xample-malware/redhip.md)|2011|B0001.032|Redhip checks for a time delay using GetTickCount. [[15]](#15)|
|[**Redhip**](../xample-malware/redhip.md)|2011|B0001.035|Redhip checks for PEB BeingDebugged flag. [[15]](#15)|
|[**Gamut**](../xample-malware/gamut.md)|2014|B0001.006|The malware detects debuggers using an INT 03h trap. [[8]](#8)|
|[**Gamut**](../xample-malware/gamut.md)|2014|B0001.008|The malware detects debuggers using IsDebuggerPresent. [[8]](#8)|
|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0001.016|The malware calls the Windows API OutputDebugString function 335,000 times. [[9]](#9)|
|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0001.032|The malware checks for a time delay via GetTickCount. [[15]](#15)|
|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0001.038|An anti-analysis function within the packer is called to check the username and filename of the executing process for strings like “malwar”, “sampl”, “viru”, and “sandb”. [[9]](#9)|
|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|B0001.005|Poison Ivy Variant checks for breakpoints and exits immediately if found. [[13]](#13)|
|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|B0001.008|Poison Ivy uses the IsDebuggerPresent API function call to check if the process is running in a debugger. [[13]](#13)|
|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0001.032|The malware calls GetTickCount64 to retrieve timestamp. Malware executes Sleep and Beep in a repeated loop for 10 times. [[11]](#11) [[12]](#12)|
|[**Ursnif**](../xample-malware/ursnif.md)|2016|B0001.028|The malware manipulates TLS Callbacks while injecting to a child process. [[12]](#12)|
|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|B0001.032|The malware checks for a time delay via GetTickCount. [[15]](#15)|
|[**Hupigon**](../xample-malware/hupigon.md)|2013|B0001.025|The malware checks for software breakpoints. [[15]](#15)|
|[**Hupigon**](../xample-malware/hupigon.md)|2013|B0001.032|The malware checks for a time delay via GetTickCount. [[15]](#15)|
|[**Hupigon**](../xample-malware/hupigon.md)|2013|B0001.034|The malware executes anti-debugging instructions. [[15]](#15)|
|[**UP007**](../xample-malware/up007.md)|2016|B0001.032|The malware checks for a time delay via GetTickCount. [[15]](#15)|
## Detection
|Tool: capa|Mapping|APIs|
|---|---|---|
|[check for trap flag exception](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-debugging/debugger-detection/check-for-trap-flag-exception.yml)|Debugger Detection (B0001)|--|
|[check for software breakpoints](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-debugging/debugger-detection/check-for-software-breakpoints.yml)|Debugger Detection::Software Breakpoints (B0001.025)|--|
|[check process job object](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-debugging/debugger-detection/check-process-job-object.yml)|Debugger Detection (B0001)|kernel32.QueryInformationJobObject, kernel32.OpenProcess|
|[check for PEB BeingDebugged flag](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-debugging/debugger-detection/check-for-peb-beingdebugged-flag.yml)|Debugger Detection::Process Environment Block BeingDebugged (B0001.035)|--|
|[check for time delay via GetTickCount](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-gettickcount.yml)|Debugger Detection::Timing/Delay Check GetTickCount (B0001.032)|--|
|[check for protected handle exception](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-debugging/debugger-detection/check-for-protected-handle-exception.yml)|Debugger Detection::SetHandleInformation (B0001.024)|SetHandleInformation, CloseHandle|
|[check for OutputDebugString error](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-debugging/debugger-detection/check-for-outputdebugstring-error.yml)|Debugger Detection::OutputDebugString (B0001.016)|kernel32.SetLastError, kernel32.GetLastError, kernel32.OutputDebugString|
|[check for unexpected memory writes](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-debugging/debugger-detection/check-for-unexpected-memory-writes.yml)|Debugger Detection::Memory Write Watching (B0001.010)|kernel32.GetWriteWatch|
|[check for kernel debugger via shared user data structure](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-debugging/debugger-detection/check-for-kernel-debugger-via-shared-user-data-structure.yml)|Debugger Detection (B0001)|--|
|[check for time delay via QueryPerformanceCounter](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-debugging/debugger-detection/check-for-time-delay-via-queryperformancecounter.yml)|Debugger Detection::Timing/Delay Check QueryPerformanceCounter (B0001.033)|--|
|[check for hardware breakpoints](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-debugging/debugger-detection/check-for-hardware-breakpoints.yml)|Debugger Detection::Hardware Breakpoints (B0001.005)|kernel32.GetThreadContext|
|[check ProcessDebugPort](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-debugging/debugger-detection/check-processdebugport.yml)|Debugger Detection::NtQueryInformationProcess (B0001.012)|NtQueryInformationProcess|
|[check for debugger via API](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-debugging/debugger-detection/check-for-debugger-via-api.yml)|Debugger Detection::CheckRemoteDebuggerPresent (B0001.002)|kernel32.CheckRemoteDebuggerPresent, WUDFPlatform.WudfIsAnyDebuggerPresent, WUDFPlatform.WudfIsKernelDebuggerPresent, WUDFPlatform.WudfIsUserDebuggerPresent|
|[check for debugger via API](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-debugging/debugger-detection/check-for-debugger-via-api.yml)|Debugger Detection::WudfIsAnyDebuggerPresent (B0001.031)|kernel32.CheckRemoteDebuggerPresent, WUDFPlatform.WudfIsAnyDebuggerPresent, WUDFPlatform.WudfIsKernelDebuggerPresent, WUDFPlatform.WudfIsUserDebuggerPresent|
|[check for PEB NtGlobalFlag flag](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-debugging/debugger-detection/check-for-peb-ntglobalflag-flag.yml)|Debugger Detection::Process Environment Block NtGlobalFlag (B0001.036)|--|
|[execute anti-debugging instructions](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-debugging/debugger-detection/execute-anti-debugging-instructions.yml)|Debugger Detection::Anti-debugging Instructions (B0001.034)|--|
|[PEB access](https://github.com/mandiant/capa-rules/blob/master/lib/peb-access.yml)|Debugger Detection::Process Environment Block (B0001.019)|--|
|Tool: CAPE|Mapping|APIs|
|---|---|---|
|[antidebug_checkremotedebuggerpresent](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antidebug_checkremotedebuggerpresent.py)|Debugger Detection (B0001)|CheckRemoteDebuggerPresent, NtQueryInformationProcess|
|[antiav_nthookengine_libs](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antidebug_nthookengine_libs.py)|Debugger Detection (B0001)|LdrGetDllHandle, LdrLoadDll|
|[antiav_nthookengine_libs](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antidebug_nthookengine_libs.py)|Debugger Detection::API Hook Detection (B0001.001)|LdrGetDllHandle, LdrLoadDll|
|[antidebug_setunhandledexceptionfilter](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antidebug_setunhandledexceptionfilter.py)|Debugger Detection (B0001)|SetUnhandledExceptionFilter|
|[antidebug_setunhandledexceptionfilter](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antidebug_setunhandledexceptionfilter.py)|Debugger Detection::UnhandledExceptionFilter (B0001.030)|SetUnhandledExceptionFilter|
|[antidebug_addvectoredexceptionhandler](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antidebug_addvectoredexceptionhandler.py)|Debugger Detection (B0001)|AddVectoredExceptionHandler|
|[antidebug_outputdebugstring](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antidebug_outputdebugstring.py)|Debugger Detection (B0001)|GetLastError, SetLastError, OutputDebugStringW, OutputDebugStringA|
|[antidebug_outputdebugstring](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antidebug_outputdebugstring.py)|Debugger Detection::OutputDebugString (B0001.016)|GetLastError, SetLastError, OutputDebugStringW, OutputDebugStringA|
|[antidebug_gettickcount](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antidebug_gettickcount.py)|Debugger Detection (B0001)|GetTickCount|
|[antidebug_gettickcount](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antidebug_gettickcount.py)|Debugger Detection::Timing/Delay Check GetTickCount (B0001.032)|GetTickCount|
|[antidebug_guardpages](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antidebug_guardpages.py)|Debugger Detection (B0001)|VirtualProtectEx, NtAllocateVirtualMemory, NtProtectVirtualMemory|
|[antidebug_guardpages](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antidebug_guardpages.py)|Debugger Detection::Memory Breakpoints (B0001.009)|VirtualProtectEx, NtAllocateVirtualMemory, NtProtectVirtualMemory|
|[antidebug_ntsetinformationthread](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antidebug_ntsetinformationthread.py)|Debugger Detection (B0001)|NtSetInformationThread|
|[antidebug_ntsetinformationthread](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antidebug_ntsetinformationthread.py)|Debugger Detection::NtSetInformationThread (B0001.014)|NtSetInformationThread|
|[antidebug_debugactiveprocess](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antidebug_debugactiveprocess.py)|Debugger Detection (B0001)|DebugActiveProcess|
### B0001.019 Snippet
<details>
<summary> Anti-Behavioral Analysis::Debugger Detection::Process Environment Block </summary>
SHA256: e33a713b96b45e2b2e0da350c0fdaaf865139607066aadff3b67b0ced82ca8bc
Location: 0x1800270A2
<pre>
mov rax, qword ptr GS:[0x60] ; GS:[0x60] contains a pointer to the Windows Process Environment Block on 64-bit versions of Windows. This command is copying that pointer into the rax register.
</pre>
</details>
## References
<a name="1">[1]</a> S. Yosef,"RASPBERRY ROBIN: ANTI-EVASION HOW-TO & EXPLOIT ANALYSIS," https://research.checkpoint.com/, 18 Apr 2023. [Online]. Available: https://research.checkpoint.com/2023/raspberry-robin-anti-evasion-how-to-exploit-analysis/.
<a name="2">[2]</a> M. Sikorski and A. Honig, Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software, No Starch Press, 2012.
<a name="3">[3]</a> Peter Ferrie, "The 'Ultimate' Anti-Debugging Reference," 4 May 2011. https://anti-reversing.com/Downloads/Anti-Reversing/The_Ultimate_Anti-Reversing_Reference.pdf.
<a name="4">[4]</a> https://web.archive.org/web/20200815134441/https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
<a name="5">[5]</a> Ayoub Faouzi (LordNoteworthy), Al-Khaser v0.79. https://github.com/LordNoteworthy/al-khaser
<a name="6">[6]</a> Nicolas Falliere, Symantec, "Windows Anti-Debug Reference," 11 September 2007. https://www.symantec.com/connect/articles/windows-anti-debug-reference.
<a name="7">[7]</a> Anti Debugging Tricks, Al-Khaser. https://github.com/LordNoteworthy/al-khaser/wiki/Anti-Debugging-Tricks
<a name="8">[8]</a> https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/gamut-spambot-analysis/
<a name="9">[9]</a> https://blogs.cisco.com/security/talos/rombertik
<a name="10">[10]</a> https://www.mandiant.com/sites/default/files/2021-09/rpt-poison-ivy.pdf
<a name="11">[11]</a> https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/
<a name="12">[12]</a> https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader
<a name="13">[13]</a> https://www.fortinet.com/blog/threat-research/deep-analysis-of-new-poison-ivy-variant
<a name="14">[14]</a> https://www.fireeye.com/blog/threat-research/2017/11/ursnif-variant-malicious-tls-callback-technique.html
<a name="15">[15]</a> capa v4.0, analyzed at MITRE on 10/12/2022
@@ -0,0 +1,108 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>B0002</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>Debugger Evasion (<a href="https://attack.mitre.org/techniques/T1622/">T1622</a>)</b></td>
</tr>
<tr>
<td><b>Anti-Analysis Type</b></td>
<td><b>Evasion</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.3</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>27 April 2024</b></td>
</tr>
</table>
# Debugger Evasion
Debugger evasion is employed by malware to foil a debugger and avoid analysis. For example, to hinder the malware analyst and debugger, malware may use exception handling to execute non-obvious execution paths (exception misdirection method) or may use several parallel threads (parallel threads method). Additional debugger evasion methods are described below.
A thorough reference for anti-debugging, both detection and evasion, is given in [[1]](#1).
The related **Debugger Evasion ([T1622](https://attack.mitre.org/techniques/T1622/))** ATT&CK technique was defined subsequent to this MBC behavior.
## Methods
|Name|ID|Description|
|---|---|---|
|**Block Interrupts**|B0002.001|Block interrupt (via hooking) 1 and/or 3 to prevent debuggers from working.|
|**Break Point Clearing**|B0002.002|Intentionally clearing software or hardware breakpoints.|
|**Byte Stealing**|B0002.003|Move or copy the first bytes / instructions of the original code elsewhere. AKA stolen bytes or code splicing. For example, a packer may incorporate the first few instructions of the original EntryPoint (EP) into its unpacking stub before the tail transition in order to confuse automated unpackers and novice analysts. This can make it harder for rebuilding and may bypass breakpoints if set prematurely.|
|**Change SizeOfImage**|B0002.004|Changing this value during run time can prevent some debuggers from attaching and also confuses some unpackers and dumpers.|
|**Code Integrity Check**|B0002.005|Check that the unpacking code is unmodified. Variation exists where unpacking code is part of the "key" used to unpack, therefore any Software Breakpoints during debugging causes unpacking to completely fail or result in malformed unpacked code.|
|**Exception Misdirection**|B0002.006|Using exception handling (SEH) to cause flow of program to non-obvious paths.|
|**Get Base Indirectly**|B0002.007|CALL to a POP; finds base of code or data, often the packed version of the code; also used often in obfuscated/packed shellcode.|
|**Guard Pages**|B0002.008|Encrypt blocks of code individually and decrypt temporarily only upon execution. This method is related to Unprotect technique U0102.|
|**Hook Interrupt**|B0002.009|Modification of interrupt vector or descriptor tables.|
|**Import Obfuscation**|B0002.010|Add obfuscation between imports calls and APIs.|
|**Inlining**|B0002.011|Variation of static linking where full API code inserted everywhere it would have been called.|
|**Loop Escapes**|B0002.012|Use SEH or other methods to break out of a loop instead of a conditional jump.|
|**Malloc Use**|B0002.013|Instead of unpacking into a pre-defined section/segment (ex: .text) of the binary, use malloc() / VirtualAlloc() to create a new segment. This makes keeping track of memory locations across different runs more difficult, as there is no guarantee that malloc/VirtualAlloc will assign the same address range each time.|
|**Modify PE Header**|B0002.014|Any part of the header is changed or erased.|
|**Nanomites**|B0002.015|int3 with code replacement table; debugs itself.|
|**Obfuscate Library Use**|B0002.016|LoadLibrary API calls or direct access of kernel32 via PEB (fs[0]) pointers, used to rebuild IAT or just obfuscate library use.|
|**Parallel Threads**|B0002.017|Use several parallel threads to make analysis harder.|
|**Pipeline Misdirection**|B0002.018|Take advantage of pipelining in modern processors to misdirect debugging, emulation, or static analysis tools. An unpacker can assume a certain number of opcodes will be cached and then proceed to overwrite them in memory, causing a debugger/emulator/analyzer to follow different code than is normally executed.|
|**Pre-Debug**|B0002.019|Prevents debugger from attaching to process or to break until after the code of interest has been executed.|
|**Relocate API Code**|B0002.020|Relocate API code in separate buffer (calls dont lead to imported DLLs).|
|**Return Obfuscation**|B0002.021|Overwrite the RET address on the stack or the code at the RET address. Variation seen that writes to the start-up code or main module that called the malware's WinMain or DllMain.|
|**RtlAdjustPrivilege**|B0002.022|Calling RtlAdjustPrivilege to either prevent a debugger from attaching or to detect if a debugger is attached.|
|**Section Misalignment**|B0002.023|Some analysis tools cannot handle binaries with misaligned sections.|
|**Self-Debugging**|B0002.024|Debug itself to prevent another debugger to be attached.|
|**Self-Unmapping**|B0002.025|UnmapViewOfFile() on itself.|
|**Static Linking**|B0002.026|Copy locally the whole content of API code.|
|**Stolen API Code**|B0002.027|A variation of "byte stealing" where the first few instructions or bytes of an API are executed in user code, allowing the IAT to point into the middle of an API function. This confuses IAT rebuilders such as ImpRec and Scylla and may bypass breakpoints.|
|**Tampering**|B0002.028|Erase or corrupt specific file parts to prevent rebuilding (header, packer stub, etc.).|
|**Thread Timeout**|B0002.029|Setting dwMilliseconds in WaitForSingleObject to a small number will timeout the thread before the analyst can step through and analyze the code executing in the thread. Modifying this via patch, register, or stack to the value `0xFFFFFFFF`, the **INFINITE** constant circumvents this anti-debugging technique.|
|**Use Interrupts**|B0002.030|The unpacking code relies on use of int 1 or int 3, or it uses the interrupt vector table as part of the decryption "key".|
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|**Fake Adobe Flash Update OS X**|2016|--|Malware contains code that manually detects a debugger. [[2]](#2)|
|**Dridex**|2015|--|[[3]](#3)|
|[**Redhip**](../xample-malware/redhip.md)|2011|--|Redhip uses general approaches to detecting user level debuggers (e.g., Process Environment Block 'Being Debugged' field), as well as specific checks for kernel level debuggers like SOFTICE. [[3]](#3)|
|[**Vobfus**](../xample-malware/vobfus.md)|2016|--|Vobfus uses GetModuleHandle API to check for the presence of a debugger. [[4]](#4)|
## Detection
|Tool: capa|Mapping|APIs|
|---|---|---|
|[hide thread from debugger](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-debugging/debugger-evasion/hide-thread-from-debugger.yml)|Debugger Evasion (B0002)|NtSetInformationThread, ZwSetInformationThread, GetCurrentThread|
|[switch active desktop](https://github.com/mandiant/capa-rules/blob/master/host-interaction/gui/switch-active-desktop.yml)|Debugger Evasion (B0002)|user32.CreateDesktop, user32.SwitchDesktop|
|Tool: CAPE|Mapping|APIs|
|---|---|---|
|[antidebug_guardpages](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antidebug_guardpages.py)|Debugger Evasion (B0002)|VirtualProtectEx, NtAllocateVirtualMemory, NtProtectVirtualMemory|
|[antidebug_guardpages](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antidebug_guardpages.py)|Debugger Evasion::Guard Pages (B0002.008)|VirtualProtectEx, NtAllocateVirtualMemory, NtProtectVirtualMemory|
|[antidebug_ntcreatethreadex](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antidebug_ntcreatethreadex.py)|Debugger Evasion (B0002)|NtCreateThreadEx|
|[debugs_self](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/debugs_self.py)|Debugger Evasion (B0002)|CreateProcessInternalW|
|[debugs_self](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/debugs_self.py)|Debugger Evasion::Self-Debugging (B0002.024)|CreateProcessInternalW|
## References
<a name="1">[1]</a> https://anti-reversing.com/Downloads/Anti-Reversing/The_Ultimate_Anti-Reversing_Reference.pdf
<a name="2">[2]</a> https://web.archive.org/web/20210225195315/https://www.synack.com/blog/analyzing-the-anti-analysis-logic-of-an-adware-installer/
<a name="3">[3]</a> https://web.archive.org/web/20200815134441/https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
<a name="4">[4]</a> https://securitynews.sonicwall.com/xmlpost/revisiting-vobfus-worm-mar-8-2013/
@@ -1,69 +0,0 @@
|||
|---------|------------------------|
|**ID**|**M0001**|
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis)|
|**Related ATT&CK Technique**|None|
Debugger Detection
==================
Malware detects whether it's being executed inside a debugger. If so, conditional execution selects a benign execution path. [[1]](#1), [[2]](#2)
Details on methods of detecting debuggers are given in the references; many are listed below.
Methods
-------
* **API Hook Detection**: module bounds based [[7]](#7)
* **CheckRemoteDebuggerPresent**: The kernel32!CheckRemoteDebuggerPresent function calls NtQueryInformationProcess with ProcessInformationClass parameter set to 7 (ProcessDebugPort constant).
* **CloseHandle**: (NtClose); If an invalid handle is passed to the CloseHandle function and a debugger is present, then an EXCEPTION_INVALID_HANDLE (0xC0000008) exception will be raised. [[7]](#7)
* **Debugger Artifacts**: Malware may detect a debugger by its artifact (window title, device driver, exports, etc.).
* **Hardware Breakpoints**: (SEH/GetThreadContext); Debug registers will indicate the presence of a debugger. See [[7]](#7) for details.
* **Interrupt 0x2d**: If int 0x2d is mishandled by the debugger, it can cause a single-byte instruction to be inadvertently skipped, which can be detected by malware.
* **Interrupt 1**: [[7]](#7)
* **IsDebuggerPresent**: The kernel32!IsDebuggerPresent API function call checks the PEB BeingDebugged flag to see if the calling process is being debugged. It returns 1 if the process is being debugged, 0 otherwise. This is one of the most common ways of debugger detection.
* **Memory Breakpoints**: (PAGE_GUARD); Guard pages trigger an exception the first time they are accessed and can be used to detect a debugger. See [[7]](#7) for details.
* **Memory Write Watching**: [[7]](#7)
* **Monitoring Thread**: Malware may spawn a monitoring thread to detect tampering, breakpoints, etc.
* **NtQueryInformationProcess**: Calling NtQueryInformationProcess with its ProcessInformationClass parameter set to 0x07 (ProcessDebugPort constant) will cause the system to set ProcessInformation to -1 if the process is being debugged. Calling with ProcessInformationClass set to 0x0E (ProcessDebugFlags) or 0x11 (ProcessDebugObject) are used similarly. Testing "ProcessDebugPort" is equivalent to using the kernel32!CheckRemoteDebuggerPresent API call (see next method).
* **NtQueryObject**: The ObjectTypeInformation and ObjectAllTypesInformation flags are checked for debugger detection.
* **NtSetInformationThread**: Calling this API with a fake class length or thread handle can indicate whether it is hooked. After calling NtSetInformationThread properly, the HideThreadFromDebugger flag is checked with the NtQueryInformationThread API. [[7]](#7)
* **NtYieldExecution/SwitchToThread**: [[7]](#7)
* **OutputDebugString**: (GetLastError); The OutputDebugString function will demonstrate different behavior depending whether or not a debugger is present. See [[7]](#7) for details.
* **Page Exception Breakpoint Detection**: [[7]](#7)
* **Parent Process**: (Explorer.exe); Executing an application by a debugger will result in the parent process being the debugger process rather than the shell process (Explorer.exe) or the command line. Malware checks its parent process; if it's not explorer.exe, it's assumed to be a debugger. [[7]](#7)
* **Process Environment Block**: The Process Environment Block (PEB) is a Windows data structure associated with each process that contains several fields, such as "BeingDebugged," "NtGlobalFlag," and "IsDebugged". Testing the value of this PEB field of a particular process can indicate whether the process is being debugged. Testing "BeingDebugged" is equivalent to using the kernel32!IsDebuggerPresent API call (see next method).
* **Process Jobs**: [[7]](#7)
* **ProcessHeap**: Process heaps are affected by debuggers. Malware can detect a debugger by checking heap header fields such as Flags (debugger present if value greater than 2) or ForceFlags (debugger present if value greater than 0).
* **RtlAdjustPrivilege**: Malware may call RtlAdjustPrivilege to detect if a debugger is attached (or to prevent a debugger from attaching).
* **SeDebugPrivilege**: (Csrss.exe); Using the OpenProcess function on the csrss.exe process can detect a debugger. [[7]](#7)
* **SetHandleInformation**: (Protected Handle);
* **Software Breakpoints**: (INT3/0xCC)
* **Stack Canary**: Similar to the anti-exploitation method of the same name, malware may try to detect mucking with values on the stack.
* **TIB Aware**: Malware may access information in the Thread Information Block (TIB) for debug detection or process obfuscation detection. The TIB can be accessed as an offset of the segment register (e.g., fs:[20h]).
* **Timing/Delay Checks**: Malware may compare time between two points to detect unusual execution, such as the (relative) massive delays introduced by debugging.
* **TLS Callbacks**: [[7]](#7)
* **UnhandledExceptionFilter**: The UnhandledExceptionFilter function is called if no registered exception handlers exist, but it will not be reached if a debugger is present. See [[7]](#7) for details.
* **WudfIsAnyDebuggerPresent**: WudfIsAnyDebuggerPresent, WudfIsKernelDebuggerPresent, WudfIsUserDebuggerPresent
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|--------|-----------------------------|
|[**Redhip**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/redhip.md)|January 2011|Redhip uses general approaches to detecting user level debuggers (e.g., Process Environment Block 'Being Debugged' field), as well as specific checks for kernel level debuggers like SOFICE. [[4]](#4)|
References
----------
<a name="1">[1]</a> Alexander Antukh, "Anti-debugging Techniques Cheat Sheet," 19 January 2015. http://antukh.com/blog/2015/01/19/malware-techniques-cheat-sheet.
<a name="2">[2]</a> Joshua Cannell, Malwarebytes Labs, "Five Anti-Analysis Tricks that sometimes Fool Analysts," 31 March 2016. https://blog.malwarebytes.com/threat-analysis/2014/09/five-anti-debugging-tricks-that-sometimes-fool-analysts.
<a name="3">[3]</a> Peter Ferrie, "The 'Ultimate' Anti-Debugging Reference," 4 May 2011. https://anti-reversing.com/Downloads/Anti-Reversing/The_Ultimate_Anti-Reversing_Reference.pdf.
<a name="4">[4]</a> Atif Mushtaq, FireEye, "The Dead Giveaways of VM-Aware Malware," 27 January 2011. https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html.
<a name="5">[5]</a> Ayoub Faouzi (LordNoteworthy), Al-Khaser v0.79. https://github.com/LordNoteworthy/al-khaser
<a name="6">[6]</a> Nicolas Falliere, Symantec, "Windows Anti-Debug Reference," 11 September 2007. https://www.symantec.com/connect/articles/windows-anti-debug-reference.
<a name="7">[7]</a> Anti Debugging Tricks, Al-Khaser. https://github.com/LordNoteworthy/al-khaser/wiki/Anti-Debugging-Tricks
@@ -1,29 +0,0 @@
|||
|---------|------------------------|
|**ID**|**M0004**|
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis)|
|**Related ATT&CK Technique**|None|
Emulator Detection
==================
Detects whether the malware instance is being executed inside an emulator. If so, conditional execution selects a benign execution path.
Methods
-------
* **Check for Emulator-related Files**: Checks whether particular files (e.g., QEMU files) exist.
* **Check for WINE Version**: Checks for WINE via the `get_wine_version` function from WINE's `ntdll.dll`.
* **Check Emulator-related Registry Keys**: Emulators register artifacts in the registry, which can be detected by malware. For example, installation of QEMU results in the registry key: *HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 0\Target Id 0\Logical Unit Id 0* with value=*Identifier* and data=*QEMU*, or registry key: *HARDWARE\Description\System* with value=*SystemBiosVersion* and data=*QEMU*. [[1]](#1)
* **Failed Network Connections**: Some emulated systems fail to handle some network communications; such failures will indicate the emulated environment.
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|--------|-----------------------------|
References
----------
<a name="1">[1]</a> http://unprotect.tdgt.org/index.php/Sandbox_Evasion
@@ -1,39 +0,0 @@
|||
|---------|------------------------|
|**ID**|**M0007**|
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis)|
|**Related ATT&CK Technique**|None|
Sandbox Detection
=================
Detects whether the malware instance is being executed inside an instrumented sandbox environment (e.g., Cuckoo Sandbox). If so, conditional execution selects a benign execution path.
The Sandbox Detection behavior relates to anti-analysis, whereas a related ATT&CK technique relates to [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion): for details, see the ATT&CK: [**Virtualization/Sandbox Evasion**](https://attack.mitre.org/techniques/T1497/).
Methods
-------
* **Check Clipboard Data**: Checks clipboard data which can be used to detect whether execution is inside a sandbox.
* **Check Files**: Sandboxes create files on the file system. Malware can check the different folders to find sandbox artifacts.
* **Human User Check**: Detects whether there is any "user" activity on the machine, such as the movement of the mouse cursor, non-default wallpaper, or recently opened Office files. If there is no human activity, the machine is suspected to be a virtualized machine and/or sandbox. Other items used to detect a user: mouse clicks (single/double), DialogBox, scrolling, color of background pixel [[3]](#3).
* **Injected DLL Testing**: Testing for the name of a particular DLL that is known to be injected by a sandbox for API hooking is a common way of detecting sandbox environments. This can be achieved through the kernel32!GetModuleHandle API call and other means.
* **Product Key/ID Testing**: Checking for a particular product key/ID associated with a sandbox environment (commonly associated with the Windows host OS used in the environment) can be used to detect whether a malware instance is being executed in a particular sandbox. This can be achieved through several means, including testing for the Key/ID in the Windows registry.
* **Screen Resolution Testing**: Sandboxes aren't used in the same manner as a typical user environment, so most of the time the screen resolution stays at the minimum 800x600 or lower. No one is actually working on a such small screen. Malware could potentially detect the screen resolution to determine if it's a user machine or a sandbox.
* **Self Check**: Malware may check its own characteristics to determine whether it's running in a sandbox. For example, a malicious Office document might check its file name or VB project name.
* **Timing/Date Check**: Calling GetSystemTime or equiv and only executing code if the current date/hour/minute/second passes some check. Often this is for running only after or only until a specific date. This behavior can be mitigated in non-automated analysis environments.
* **Timing/Uptime Check**: Comparing single GetTickCount with some value to see if system has been started at least *X* amount ago. This behavior can be mitigated in non-automated analysis environments.
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|--------|-----------------------------|
|[**Redhip**](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/redhip.md)|January 2011|Redhip detects publicly available automated analysis workbenches (e.g., Joe Box) by considering OS product keys and special DLLs. [[1]](#1)|
|**Rombertik**|May 2015|[[2]](#2)|
References
----------
<a name="1">[1]</a> https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
<a name="2">[2]</a> http://labs.lastline.com/exposing-rombertik-turning-the-tables-on-evasive-malware
<a name="3">[3]</a> https://github.com/LordNoteworthy/al-khaser
-72
View File
@@ -1,72 +0,0 @@
|||
|---------|------------------------|
|**ID**|**M0009**|
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis)|
|**Related ATT&CK Technique**|[Virtualization/Sandbox Evasion](https://attack.mitre.org/techniques/T1497/)|
Virtual Machine Detection
=========================
Detects whether the malware instance is being executed in a virtual machine (VM), such as VMWare. If so, conditional execution selects a benign execution path. [[1]](#1)
The Virtual Machine Detection behavior relates to anti-analysis, whereas a related ATT&CK technique relates to [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion): for details, see the ATT&CK: [**Virtualization/Sandbox Evasion**](https://attack.mitre.org/techniques/T1497/).
Methods
-------
* **Check File and Directory Artifacts**: Virtual machines create files on the file system (e.g., VMware creates files in the installation directory C:\Program Files\VMware\VMware Tools). Malware can check the different folders to find virtual machine artifacts (e.g., Virtualbox has the artifact VBoxMouse.sys). [[2]](#2)
* **Check Memory Artifacts**: VMware leaves many artifacts in memory. Some are critical processor structures, which, because they are either moved or changed on a virtual machine, leave recognizable footprints. Malware can search through physical memory for the strings VMware, commonly used to detect memory artifacts. [[2]](#2)
* **Check Named System Objects**: Virtual machines often include specific named system objects by default, such as Windows device drivers, which can be detected by testing for specific strings, whether found in the Windows registry or other places.
* **Check Processes**: The VMware Tools use processes like VMwareServices.exe or VMwareTray.exe, to perform actions on the virtual environment. Malware can list the process and searches for the VMware string. Process related to Virtualbox can be detected by malware by query the process list. [[2]](#2)
* **Check Registry Keys**: Virtual machines register artifacts in the registry, which can be detected by malware. For example, a search for "VMware" or "VBOX" in the registry might reveal keys that include information about a virtual hard drive, adapters, running services, or virtual mouse. [[2]](#2) Example registry key value artifacts include "HARDWARE\Description\System (SystemBiosVersion) (VBOX)" and "SYSTEM\ControlSet001\Control\SystemInformation (SystemManufacturer) (VMWARE)"; example registry key artifacts include "SOFTWARE\VMware, Inc.\VMware Tools (VMWARE)" and "SOFTWARE\Oracle\VirtualBox Guest Additions (VBOX)". [[5]](#5)
* **Check Running Services**: VMwareService.exe runs the VMware Tools Service as a child of services.exe. It can be identified by listing services. [[2]](#2)
* **Check Software**: Malware may check whether software is relatively current.
* **Check Virtual Devices**: The presence of virtual devices can indicate a virtualized environment (e.g., "\\.\VBoxTrayIPC"). [[5]](#5)
* **Check Windows**: Malware may check windows for VM-related characteristics such as:
* *Window size*: tiny window size may indicate a VM.
* *Unique windows*: may check for the presence of known windows from analysis tools running in a VM.
* *Title bars*: may inject malicious code to svchost.exe to check all open window title bar text to a list of strings indicating virtualized environment.
* **Guest Process Testing**: Virtual machines offer guest additions that can be installed to add functionality such as clipboard sharing. Detecting the process responsible for these tasks, via its name or other methods, is a technique employed by malware for detecting whether it is being executed in a virtual machine.
* **HTML5 Performance Object Check**: In three browser families, it is possible to extract the frequency of the Windows performance counter frequency, using standard HTML and Javascript. This value can then be used to detect whether the code is being executed in a virtual machine, by detecting two specific frequencies commonly used in virtual but not physical machines.
* **Human User Check**: Detects whether there is any "user" activity on the machine, such as the movement of the mouse cursor, non-default wallpaper, or recently opened Office files. If there is no human activity, the machine is suspected to be a virtualized machine and/or sandbox. Other items used to detect a user: mouse clicks (single/double), DialogBox, scrolling, color of background pixel, change in foreground window [[5]](#5).
* **Modern Specs Check**: Different aspects of the hardware are inspected to determine whether the machine has modern characteristics. A machine with substandard specifications indicates a virtual environment:
* *Total physical memory*: most modern machines have at leave 4 GB of memory. (GlobalMemoryStatusEx) [[5]](#5).
* *Drive size*: most modern machines have at least 80 GB disks. May use DeviceloControl (IOCTL_DISK_GET_LENGTH_INFO) or GetDiskFreeSpaceEx (TotalNumberOfBytes) [[5]](#5).
* *USB drive*: checks whether there is a potential USB drive; if not a virtual environment is suspected.
* *Printer*: checks whether there is a potential connected printer or default Windows printers; if not a virtual environment is suspected.
* *Processor count*: checks number of processors; single CPU machines are suspect.
* *Keyboard layout*
* **Unique Hardware/Firmware Check**: Malware may check for hardware characteristics unique to being virtualized, allowing the malware to detect the virtual environment. Items checked include:
* *BIOS*: characteristics of the BIOS, such as version, can indicate virtualization.
* *I/O Communication Port*: VMware uses virtual I/O ports for communication between the virtual machine and the host operating system to support functionality like copy and paste between the two systems. The port can be queried and compared with a magic number VMXh to identify the use of VMware.
* *CPU Name*
* *CPU Location*: When an Operating System is virtualized, the CPU is relocated. [[2]](#2)
* *MAC Address*: VMware uses specific virtual MAC address that can be detected. The usual MAC address used started with the following numbers: "00:0C:29", "00:1C:14", "00:50:56", "00:05:69". Virtualbox uses specific virtual MAC address that can be detected by Malware. The usual MAC address used started with the following numbers: 08:00:27. [[2]](#2)
* **Instruction Testing**: The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2)
* *SIDT (red pill)*: Red Pill is an anti-VM technique that executes the SIDT instruction to grab the value of the IDTR register. The virtual machine monitor must relocate the guest's IDTR to avoid conflict with the host's IDTR. Since the virtual machine monitor is not notified when the virtual machine runs the SIDT instruction, the IDTR for the virtual machine is returned.
* *SGDT/SLDT (no pill)*: The No Pill technique relies on the fact that the LDT structure is assigned to a processor not an Operating System. The LDT location on a host machine will be zero and on a virtual machine will be non-zero.
* *SMSW*
* *STR*
* *CPUID*: Checking the CPU ID found within the registry can provide information to system type.
* *IN*
* *RDTSC*
* *VMCPUID*
* *VPCEXT*
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|**GravityRAT**|May 2018|GravityRAT checks system temperature by recording thermal readings for detecting VMs. Heat levels indicate whether the system is a VM. [[3]](#3)|
|[**WebCobra**](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/webcobra.md)|2018|WebCobra injects malicious code to svchost.exe and uses an infinite loop to check all open windows and to compare each windows title bar text with a set of strings to determine whether it is running in an isolated, malware analysis environment [[4]](#4)|
References
----------
<a name="1">[1]</a> https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
<a name="2">[2]</a> http://unprotect.tdgt.org/index.php/Sandbox_Evasion
<a name="3">[3]>/a> https://www.hackread.com/gravityrat-malware-evades-detection-targets-india/
<a name="4">[4]</a> https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/webcobra-malware-uses-victims-computers-to-mine-cryptocurrency/
<a name="5">[5]</a> https://github.com/LordNoteworthy/al-khaser
@@ -0,0 +1,112 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>B0003</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>Virtualization/Sandbox Evasion (<a href="https://attack.mitre.org/techniques/T1497/">T1497</a>, <a href="https://attack.mitre.org/techniques/T1633/">T1633</a>)</b></td>
</tr>
<tr>
<td><b>Anti-Analysis Type</b></td>
<td><b>Evasion</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>27 April 2024</b></td>
</tr>
</table>
# Dynamic Analysis Evasion
Malware may obstruct dynamic analysis in a sandbox or virtual machine. An analyst detonates the specimen in these controlled environments to understand the malware's behavior. However, the code may exhibit a variety of anti-analysis methods, including delayed execution and code integrity checks. Additional methods are listed in the table below.
See **Emulator Evasion ([B0004](../anti-behavioral-analysis/emulator-evasion.md))** for an emulator-specific evasion behavior, and see **Conditional Execution ([B0025](../execution/conditional-execution.md))** for a behavior that constrains dynamic execution based on environmental conditions.
The related **Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/techniques/T1497/), [T1633](https://attack.mitre.org/techniques/T1633/))** ATT&CK techniques were defined subsequent to this MBC behavior.
## Methods
|Name|ID|Description|
|---|---|---|
|**Alternative ntdll.dll**|B0003.001|A copy of ntdll.dll is dropped to the filesystem and then loaded. This alternative DLL is used to execute function calls to evade sandboxes which use hooking in the operating system's ntdll.dll.|
|**API Hammering**|B0003.012|Uses of a huge number of calls to Windows APIs as a form of extended sleep to evade analysis in sandbox environments. This method is related to Unprotect technique U1305.|
|**Code Integrity Check**|B0003.011|Compares memory-based and disk-based versions of itself. If differences are detected, the malware alters its execution, possibly acting destructively.|
|**Data Flood**|B0003.002|Overloads a sandbox by generating a flood of meaningless behavioral data. [[1]](#1)|
|**Delayed Execution**|B0003.003|Stalling code is typically executed before any malicious behavior. The malware's aim is to delay the execution of the malicious activity long enough so that an automated dynamic analysis system fails to extract the interesting malicious behavior. This method is very similar to ATT&CK's [Virtualization/Sandbox Evasion: Time Based Evasion](https://attack.mitre.org/techniques/T1497/003/) sub-technique. This method is related to Unprotect technique U1318.|
|**Demo Mode**|B0003.004|Inclusion of a demo binary/mode that is executed when token is absent or not privileged enough.|
|**Drop Code**|B0003.005|Original file is written to disk then executed. May confuse some sandboxes, especially if the dropped executable must be provided specific arguments and the original dropper is not associated with the drop file(s).|
|**Encode File**|B0003.006|Encode a file on disk, such as an implant's config file.|
|**Hook File System**|B0003.007|Execution happens when a particular file or directory is accessed, often through hooking certain API calls such as CreateFileA and CreateFileW.|
|**Hook Interrupt**|B0003.008|Modification of interrupt vector or descriptor tables.|
|**Illusion**|B0003.009|Creates an illusion; makes the analyst think something happened when it didn't.|
|**Restart**|B0003.010|Restarts or shuts down system to bypass sandboxing.|
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**Terminator**](../xample-malware/terminator.md)|2013|B0003.003|The Terminator RAT evades a sandbox by not executing until after a reboot. Most sandboxes don't reboot during an analysis. [[3]](#3)|
|**Nap**|2013|--|Trojan Nap (tied to the Kelihos Botnet) uses extended sleep calls to evade sandbox analysis. [[3]](#3)|
|**Smokeloader**|2019|--|Smokeloader drops a copy of ntdll.dll to %APPDATA%\Local\Temp\ [[4]](#4)|
|[**WebCobra**](../xample-malware/webcobra.md)|2018|B0003.001|The malware loads ntdll.dll and user32.dll as data files and overwrites the first 8 bytes of those functions to avoid API hooking by security products. [[7]](#7)|
|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0003.002|The malware stalls by writing a byte of random data to memory 960 million times which complicates analysis. It also calls specific Windows API functions. [[5]](#5)|
|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0003.011|The malware computes a 32-bit hash of a resource in memory, and compares it to the PE Compile Timestamp of the unpacked sample. If the resource or compile time has been altered, the malware acts destructively. [[5]](#5)|
|[**TrickBot**](../xample-malware/trickbot.md)|2016|B0003.012|The malware uses numerous printf loops to delay the execution process and overload the sandbox with junk data (API Hammering). [[6]](#6)|
## Detection
|Tool: capa|Mapping|APIs|
|---|---|---|
|[delay execution](https://github.com/mandiant/capa-rules/blob/master/lib/delay-execution.yml)|Dynamic Analysis Evasion::Delayed Execution (B0003.003)|kernel32.Sleep, kernel32.SleepEx, kernel32.WaitForSingleObject, kernel32.SignalObjectAndWait, kernel32.WaitForSingleObjectEx, kernel32.WaitForMultipleObjects, kernel32.WaitForMultipleObjectsEx, kernel32.RegisterWaitForSingleObject, WaitOnAddress, user32.MsgWaitForMultipleObjects, user32.MsgWaitForMultipleObjectsEx, NtDelayExecution, KeWaitForSingleObject, KeDelayExecutionThread, sleep, usleep|
|Tool: CAPE|Mapping|APIs|
|---|---|---|
|[api_spamming](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/api_spamming.py)|Dynamic Analysis Evasion (B0003)|--|
|[api_spamming](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/api_spamming.py)|Dynamic Analysis Evasion::Data Flood (B0003.002)|--|
|[api_spamming](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/api_spamming.py)|Dynamic Analysis Evasion::Delayed Execution (B0003.003)|--|
|[antisandbox_suspend](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_suspend.py)|Dynamic Analysis Evasion (B0003)|NtSuspendThread|
|[antisandbox_restart](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_restart.py)|Dynamic Analysis Evasion (B0003)|ExitWindowsEx, InitiateSystemShutdownExW, NtSetSystemPowerState, InitiateSystemShutdownW, InitiateShutdownW, NtRaiseHardError, NtShutdownSystem|
|[antisandbox_restart](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_restart.py)|Dynamic Analysis Evasion::Restart (B0003.010)|ExitWindowsEx, InitiateSystemShutdownExW, NtSetSystemPowerState, InitiateSystemShutdownW, InitiateShutdownW, NtRaiseHardError, NtShutdownSystem|
|[stealth_timeout](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/stealth_timelimit.py)|Dynamic Analysis Evasion (B0003)|NtWaitForSingleObject, NtQuerySystemTime, NtTerminateProcess, GetLocalTime, NtDelayExecution, GetSystemTime, GetSystemTimeAsFileTime|
|[stealth_timeout](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/stealth_timelimit.py)|Dynamic Analysis Evasion::Delayed Execution (B0003.003)|NtWaitForSingleObject, NtQuerySystemTime, NtTerminateProcess, GetLocalTime, NtDelayExecution, GetSystemTime, GetSystemTimeAsFileTime|
|[antisandbox_unhook](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_unhook.py)|Dynamic Analysis Evasion (B0003)|--|
### B0003.003 Snippet
<details>
<summary> Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed Execution </summary>
SHA256: 21c1fdd6cfd8ec3ffe3e922f944424b543643dbdab99fa731556f8805b0d5561
Location: 0x40103B
<pre>
push 0x36ee80 ; sleep duration: 3600000 milliseconds (1 hour)
call dword ptr [->KERNEL32.DLL::Sleep] ; Windows API call instructing thread to sleep for the time period specified above
</pre>
</details>
## References
<a name="1">[1]</a> https://www.joesecurity.org/blog/4310408827727907098
<a name="2">[2]</a> https://www.mcafee.com/blogs/other-blogs/mcafee-labs/webcobra-malware-uses-victims-computers-to-mine-cryptocurrency/
<a name="3">[3]</a> https://www.fireeye.com/content/dam/fireeye-www/current-threats/pdfs/pf/file/fireeye-hot-knives-through-butter.pdf
<a name="4">[4]</a> https://research.checkpoint.com/2019-resurgence-of-smokeloader/
<a name="5">[5]</a> https://blogs.cisco.com/security/talos/rombertik
<a name="6">[6]</a> https://www.joesecurity.org/blog/498839998833561473
@@ -0,0 +1,71 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>B0004</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>None</b></td>
</tr>
<tr>
<td><b>Anti-Analysis Type</b></td>
<td><b>Detection</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>27 April 2024</b></td>
</tr>
</table>
# Emulator Detection
Detects whether the malware instance is being executed inside an emulator. If so, conditional execution selects a benign execution path.
## Methods
|Name|ID|Description|
|---|---|---|
|**Check Emulator-related Registry Keys**|B0004.003|Emulators register artifacts in the registry, which can be detected by malware. For example, installation of QEMU results in the registry key: *HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 0\Target Id 0\Logical Unit Id 0* with value=*Identifier* and data=*QEMU*, or registry key: *HARDWARE\Description\System* with value=*SystemBiosVersion* and data=*QEMU*. [[1]](#1)|
|**Check for Emulator-related Files**|B0004.001|Checks whether particular files (e.g., QEMU files) exist.|
|**Check for WINE Version**|B0004.002|Checks for WINE via the `get_wine_version` function from WINE's `ntdll.dll`.|
|**Failed Network Connections**|B0004.004|Some emulated systems fail to handle some network communications; such failures will indicate the emulated environment.|
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|--|Stuxnet checks for specific operating systems on 32-bit machines, registry keys, and dates to profile a potential target machine before execution. If the conditions are not met to be considered a viable target, it will exit execution. [[2]](#2)|
## Detection
|Tool: capa|Mapping|APIs|
|---|---|---|
|[check if process is running under wine](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-emulation/wine/check-if-process-is-running-under-wine.yml)|Emulator Detection (B0004)|GetModuleHandle, GetProcAddress|
|Tool: CAPE|Mapping|APIs|
|---|---|---|
|[antiemu_windefend](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antiemu_windefend.py)|Emulator Detection (B0004)|--|
|[antivm_bochs_keys](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_bochs_keys.py)|Emulator Detection (B0004)|--|
|[antivm_bochs_keys](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_bochs_keys.py)|Emulator Detection::Check Emulator-related Registry Keys (B0004.003)|--|
|[antiemu_wine_func](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antiemu_wine_func.py)|Emulator Detection (B0004)|LdrGetProcedureAddress|
|[antiemu_wine_reg](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antiemu_wine.py)|Emulator Detection (B0004)|--|
|[antiemu_wine_reg](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antiemu_wine.py)|Emulator Detection::Check Emulator-related Registry Keys (B0004.003)|--|
## References
<a name="1">[1]</a> https://search.unprotect.it/category/sandbox-evasion/
<a name="2">[2]</a> https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en
@@ -0,0 +1,51 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>B0005</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>None</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.0</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>4 March 2023</b></td>
</tr>
</table>
# Emulator Evasion
Behaviors that obstruct analysis in an emulator.
## Methods
|Name|ID|Description|
|---|---|---|
|**Different Opcode Sets**|B0005.001|Use different opcodes sets (ex: FPU, MMX, SSE) to block emulators.|
|**Extra Loops/Time Locks**|B0005.004|Add extra loops to make time-constraint emulators give up.|
|**Undocumented/Unimplemented Opcodes**|B0005.002|Use rare, undocumented, or unimplemented opcodes to block non-exhaustive emulators.|
|**Unusual/Undocumented API Calls**|B0005.003|Call unusual APIs to block non-exhaustive emulators (particularly anti-virus).|
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**WebCobra**](../xample-malware/webcobra.md)|2018|B0005.004|The malware evades emulator-based analysis by using an infinite loop to check all open windows and compare each window's title bar to a list of strings. [[1]](#1)|
## References
<a name="1">[1]</a> https://www.mcafee.com/blogs/other-blogs/mcafee-labs/webcobra-malware-uses-victims-computers-to-mine-cryptocurrency/
-27
View File
@@ -1,27 +0,0 @@
|||
|---------|------------------------|
|**ID**|**M0036**|
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis)|
|**Related ATT&CK Technique**|None|
Capture Evasion
===============
Malware has characteristics enabling it to evade capture from the infected system.
Methods
-------
* **Memory-only Payload**: Malware is never written to disk (e.g., RAT plugins received from the controller are never written to disk).
* **Encrypted Payloads**: Decryption key is stored external to the executable or never touches the disk.
* **Multiple Stages of Loaders**: Multiple stages of loaders are used with an encoded payload.
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
| | | |
References
----------
@@ -1,65 +0,0 @@
|||
|---------|------------------------|
|**ID**|**M0002**|
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis)|
|**Related ATT&CK Technique**|None|
Debugger Evasion
================
Behaviors that make debugging difficult.
A thorough reference for anti-debugging, both detection and evasion, is given in [[1]](#1).
Methods
-------
* **Block Interrupts**: Block interrupt (via hooking) 1 and/or 3 to prevent debuggers from working.
* **Break Point Clearing**: Intentionally clearing software or hardware breakpoints.
* **Byte Stealing**: Move or copy the first bytes / instructions of the original code elsewhere. AKA stolen bytes or code splicing. For example, a packer may incorporate the first few instructions of the original EntryPoint (EP) into its unpacking stub before the tail transition in order to confuse automated unpackers and novice analysts. This can make it harder for rebuilding and may bypass breakpoints if set prematurely.
* **Change SizeOfImage**: Changinging this value during run time can prevent some debuggers from attaching. Also confuses some unpackers and dumpers.
* **Code Integrity Check**: Check that the unpacking code is unmodified. Variation exists where unpacking code is part of the "key" used to unpack, therefore any Software Breakpoints during debugging causes unpacking to completely fail or result in malformed unpacked code.
* **Exception Misdirection**: Using exception handling (SEH) to cause flow of program to non-obvious paths.
* **Get Base Indirectly**: CALL to a POP; finds base of code or data, often the packed version of the code; also used often in obfuscated/packed shellcode.
* **Guard Pages**: Encrypt blocks of code individually and decrypt temporarily only upon execution.
* **Hook Interrupt**: modification of interrupt vector or descriptor tables.
* **Import Obfuscation**: Add obfuscation between imports calls and APIs.
* **Inlining**: variation of static linking where full API code inserted everywhere it would have been called.
* **Loop Escapes**: Use SEH or other methods to break out of a loop instead of a conditional jump.
* **Malloc Use**: Instead of unpacking into a pre-defined section/segment (ex: .text) of the binary, use malloc() / VirtualAlloc() to create a new segment. This makes keeping track of memory locations across different runs more difficult, as there is no guarantee that malloc/VirtualAlloc will assign the same address range each time.
* **Modify PE Header**: Any part of the header is changed or erased.
* **Nanomites**: int3 with code replacement table; debugs itself.
* **Obfuscate Library Use**: LoadLibrary API calls or direct access of kernel32 via PEB (fs[0]) pointers, used to rebuild IAT or just obfuscate library use.
* **Parallel Threads**: Use several parallel threads to make analysis harder.
* **Pipeline Misdirection**: Take advantage of pipelining in modern processors to misdirect debugging, emulation, or static analysis tools. An unpacker can assume a certain number of opcodes will be cached and then proceed to overwrite them in memory, causing a debugger/emulator/analyzer to follow different code than is normally executed.
* **Pre-Debug**: Prevents debugger from attaching to process or to break until after the code of interest has been executed
* **Relocate API Code**: relocate API code in separate buffer (calls dont lead to imported DLLs).
* **Return Obfuscation**: Overwrite the RET address on the stack or the code at the RET address. Variation seen that writes to the start-up code or main module that called the malware's WinMain or DllMain.
* **RtlAdjustPrivilege**: Calling RtlAdjustPrivilege to either prevent a debugger from attaching or to detect if a debugger is attached.
* **Section Misalignment**: Some analysis tools cannot handle binaries with misaligned sections.
* **Self-Debugging**: Debug itself to prevent another debugger to be attached.
* **Self-Unmapping**: UnmapViewOfFile() on itself
* **Static Linking**: Copy locally the whole content of API code.
* **Stolen API Code**: A variation of "byte stealing" where the first few instructions or bytes of an API are executed in user code, allowing the IAT to point into the middle of an API function. This confuses IAT rebuilders such as ImpRec and Scylla and may bypass breakpoints.
* **Tampering**: Erase or corrupt specific file parts to prevent rebuilding (header, packer stub, etc.).
* **Thread Timeout**: Setting dwMilliseconds in WaitForSingleObject to a small number will timeout the thread before the analyst can step through and analyze the code executing in the thread. Modifying this via patch, register, or stack to the value `0xFFFFFFFF`, the **INFINITE** constant circumvents this anti-debugging technique.
* **Use Interrupts**: The unpacking code relies on use of int 1 or int 3, or it uses the interrupt vector table as part of the decryption "key".
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|--------|-----------------------------|
|**Fake Adobe Flash Update OS X**|February 2016|[[2]](#2)|
|**Dridex**|March 2015|[[3]](#3)|
References
----------
<a name="1">[1]</a> https://anti-reversing.com/Downloads/Anti-Reversing/The_Ultimate_Anti-Reversing_Reference.pdf
<a name="2">[2]</a> https://www.synack.com/2016/02/17/analyzing-the-anti-analysis-logic-of-an-adware-installer/
<a name="3">[3]</a> http://phishme.com/dridex-code-breaking-modify-the-malware-to-bypass-the-vm-bypass/
<a name="4">[4]</a> http://antukh.com/blog/2015/01/19/malware-techniques-cheat-sheet/
<a name="5">[5]</a> http://unprotect.tdgt.org/index.php/Unprotect_Project
@@ -1,43 +0,0 @@
|||
|---------|------------------------|
|**ID**|**M0003**|
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis)|
|**Related ATT&CK Technique**|None|
Dynamic Analysis Evasion
========================
Malware may obstruct dynamic analysis in a sandbox, emulator, or virtual machine.
See [Emulator Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis/emulator-evade.md) for an emulator-specific evasion behavior, and see [Execution Guardrails](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/execution-guardrails.md) for a behavior that constrains dynamic execution based on environmental conditions.
Methods
-------
* **Alternative ntdll.dll** A copy of ntdll.dll is dropped to the filesystem and then loaded. This alternative DLL is used to execute function calls to evade sandboxes which use hooking in the operating system's ntdll.dll.
* **Data Flood**: Overloads a sandbox by generating a flood of meaningless behavioral data. [[1]](#1)
* **Delayed Execution** - Stalling code is typically executed before any malicious behavior. The malware's aim is to delay the execution of the malicious activity long enough so that an automated dynamic analysis system fails to extract the interesting malicious behavior.
* **Demo Mode**: Inclusion of a demo binary/mode that is executed when token is absent or not enough privileged.
* **Drop Code**: Original file is written to disk then executed. May confuse some sandboxes, especially if the dropped executable must be provided specific arguments and the original dropper is not associated with the drop file(s).
* **Encode File**: Encode a file on disk, such as an implant's config file.
* **Hook File System**: execution happens when a particular file or directory is accessed, often through hooking certain API calls such as CreateFileA and CreateFileW.
* **Hook Interrupt**: modification of interrupt vector or descriptor tables.
* **Illusion**: Creates an illusion; makes the analyst think something happened when it didn't.
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**Ursnif**](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/ursnif.md)|May 2016|Ursnif uses malware macros to evade sandbox detection. [[2]](#2)|
|[**Terminator**](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/terminator.md)|October 2013|The Terminator rat evades a sandbox by not executing until after a reboot. Most sandboxes don't reboot during an analysis. [[3]](#3)|
|**Nap**|2013|Trojan Nap (tied to the Kelihos Botnet) uses extended sleep calls to evade sandbox analysis. [[3]](#3)|
|**Smokeloader**|2019|Smokeloader drops a copy of ntdll.dll to %APPDATA%\Local\Temp\ [[4]](#4)|
References
----------
<a name="1">[1]</a> http://joe4security.blogspot.com/2013/06/overloading-sandboxes-new-generic.html
<a name="2">[2]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/ursnif
<a name="3">[3]</a> https://www.fireeye.com/content/dam/fireeye-www/current-threats/pdfs/pf/file/fireeye-hot-knives-through-butter.pdf
<a name="4">[4]</a> https://research.checkpoint.com/2019-resurgence-of-smokeloader/
@@ -1,18 +0,0 @@
|||
|---------|------------------------|
|**ID**|**M0005**|
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis)|
|**Related ATT&CK Technique**|None|
Emulator Evasion
================
Behaviors that obstruct analysis in an emulator.
Methods
-------
* **Different Opcode Sets**: Use different opcodes sets (ex: FPU, MMX, SSE) to block emulators.
* **Undocumented Opcodes**: Use rare or undocumented opcodes to block non-exhaustive emulators.
* **Unusual/Undocumented API Calls**: Call unusual APIs to block non-exhaustive emulators (particularly anti-virus).
* **Extra Loops/Time Locks**: Add extra loops to make time-constraint emulators give up.
@@ -1,39 +0,0 @@
|||
|---------|------------------------|
|**ID**|**M0006**|
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis)|
|**Related ATT&CK Technique**|None|
Memory Dump Evasion
===================
Malware hinders retrieval and/or discovery of the contents of the physical memory of the system on which the malware instance is executing [[1]](#1).
Methods
-------
* **Code Encryption in Memory**: Encrypt the executing malware instance code in memory.
* **Erase the PE header**: Erase PE header from memory.
* **Hide virtual memory**: Hide arbitrary segments of virtual memory.
* **SizeOfImage**: Set the SizeOfImage field of PEB.LoaderData to be huge.
* **Tampering**: Erase or corrupt specific file parts to prevent rebuilding (header, packer stub, etc.).
* **Guard Pages**: Encrypt blocks of code individually and decrypt temporarily only upon execution.
* **On-the-Fly APIs**: Resolve API addresses before each use to prevent complete dumping.
* **Feed Misinformation**: API behavior can be altered to prevent memory dumps. For example, inaccurate data can be reported when the contents of the physical memory of the system on which the malware instance is executing is retrieved. See [Hooking](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/hooking.md).
* **Flow Opcode Obstruction**: flow opcodes (e.g., jumps, loops) are removed and emulated (or decrypted) by the packer during execution, resulting in incorrect dumps. [[4]](#4)
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[Kraken](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/kraken.md)| April 2008| Dumping Kraken's c.dll module from the heap of its own process is tricky because its PE-header is erased in memory. [[2]](#2)|
References
----------
<a name="1">[1]</a> J. Stuttgen, M. Cohen, Anti-forensic resilient memory acquisition, www.dfrws.org/sites/default/files/session-files/paper-anti-forensic_resilient_memory_acquisition.pdf
<a name="2">[2]</a> http://blog.threatexpert.com/2008/04/kraken-changes-tactics.html
<a name="3">[3]</a> http://waleedassar.blogspot.com/search/label/anti-dump
<a name="4">[4]</a> https://www.gironsec.com/code/packers.pdf
@@ -1,32 +0,0 @@
|||
|---------|------------------------|
|**ID**|**E1480**|
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis), [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion)|
|**Related ATT&CK Technique**|[Execution Guardrails](https://attack.mitre.org/techniques/T1480/)|
Execution Guardrails
====================
Malware may use execution guardrails (environmental conditions) to constrain execution. This behavior is related to the [Evade Dynamic Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis/evade-dynamic-analysis.md) behavior that obstructs dynamic analysis in a sandbox, emulator, or virtual machine.
**See ATT&CK:** [**Execution Guardrails**](https://attack.mitre.org/techniques/T1480/) (which under ATT&CK does not pertain to anti-behavioral analysis behaviors).
Methods
-------
* **Deposited Keys**: Parts of the code and/or data is encrypted or otherwise relies on data external to the file itself. For example, malware that contains code that is encrypted with a key that is downloaded from a server; malware that only runs if certain other software is installed on the system. Also see Environmental Keys Method.
* **Environmental Keys**: Malware reads certain attributes of the system (BIOS version string, hostname, MAC address, etc.) and encrypts/decrypts portions of its code or data using those attributes as input, thus preventing itself from being run on an unintended system (e.g., sandbox, emulator, etc.). Also see Deposited Keys Method.
* **GetVolumeInformation**: This Windows API call is used to get the GUID on a system drive. Malware compares it to a previous (targeted) GUID value and only executes maliciously if they match. This behavior can be mitigated in non-automated analysis environments.
* **Host Fingerprint Check**: Compare a previously computed host fingerprint(e.g., based on installed applications) to the current system's to determine if the malware instance is still executing on the same system. If not, execution stops, making debugging or sandbox analysis more difficult.
* **Secure Triggers**: Code and/or data is encrypted until the underlying system satisfies a preselected condition unknown to the analyst (this is a form of Deposited Keys).
* **Token Check**: Presence check to allow the program to run (ex: dongle, CD/DVD, key, file, network, etc.). If the token is specific to a hardware element (ex: disk, OS, CPU, NIC MAC, etc.), it is considered fingerprinting.
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
References
----------
@@ -0,0 +1,117 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>B0006</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>None</b></td>
</tr>
<tr>
<td><b>Anti-Analysis Type</b></td>
<td><b>Evasion</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>29 April 2024</b></td>
</tr>
</table>
# Memory Dump Evasion
Memory dump evasion is an anti-forensic technique in which malware hinders retrieval and/or discovery of the contents of the physical memory of the system on which the malware instance is executing [[1]](#1). Tools enabling capture of malware code from memory can be software-based or hardware-based. Malicious code thwarts software-based tools by relying on such methods as resolving API addresses before each use (on-the-fly APIs method) and erasing or corrupting specific file parts to prevent rebuilding (tampering method) [[2]](#2),[[3]](#3).
## Methods
|Name|ID|Description|
|---|---|---|
|**Code Encryption in Memory**|B0006.001|Encrypt the executing malware instance code in memory.|
|**Erase the PE header**|B0006.002|Erase PE header from memory.|
|**Feed Misinformation**|B0006.008|API behavior can be altered to prevent memory dumps. For example, inaccurate data can be reported when the contents of the physical memory of the system on which the malware instance is executing is retrieved. See [Hijack Execution Flow](../defense-evasion/hijack-execution-flow.md).|
|**Flow Opcode Obstruction**|B0006.009|Flow opcodes (e.g., jumps, loops) are removed and emulated (or decrypted) by the packer during execution, resulting in incorrect dumps. [[6]](#6).|
|**Guard Pages**|B0006.006|Encrypt blocks of code individually and decrypt temporarily only upon execution. This method is related to Unprotect technique U0102.|
|**Hide virtual memory**|B0006.003|Hide arbitrary segments of virtual memory.|
|**On-the-Fly APIs**|B0006.007|Resolve API addresses before each use to prevent complete dumping.|
|**SizeOfImage**|B0006.004|Set the SizeOfImage field of PEB.LoaderData to be huge.|
|**Tampering**|B0006.005|Erase or corrupt specific file parts to prevent rebuilding (header, packer stub, etc.).|
|**Hook memory mapping APIs**|B0006.010|Hooking prevents memory dumps by preventing mapping of memory into the kernel's virtual address space. [[1]](#1)|
|**Patch MmGetPhysicalMemoryRanges**|[B0006.011](#b0006011-snippet)|Patching this function to always return NULL prevents drivers from getting information about the physical address space layout, preventing memory dumps. [[1]](#1)|
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**Kraken**](../xample-malware/kraken.md)|2008|--|Dumping Kraken's c.dll module from the heap of its own process is tricky because its PE-header is erased in memory. [[4]](#4)|
## Code Snippets
### B0006.011 Snippet
<details>
<summary> Memory Dump::Code Encryption in Memory </summary>
SHA256: 304f533ce9ea4a9ee5c19bc81c49838857c63469e26023f330823c3240ee4e03
<pre>
asm
mov cl, 65h ; 'e'
mov al, 70h ; 'p'
mov [ebp+var_23], cl
mov [ebp+var_1F], cl
mov [ebp+String], bl
mov [ebp+var_12], bl
mov [ebp+var_2E], al
mov [ebp+var_2D], al
lea ecx, [ebp+String]
mov al, 74h ; 't'
mov bl, 2Eh ; '.'
push ecx
mov [ebp+var_13], 30h
mov [ebp+var_11], 30h
mov [ebp+var_10], 0
mov [ebp+cp]
mov [ebp+var_2F], 75h
mov [ebp+var_2C], 6Fh
mov [ebp+var_2B], 72h
mov [ebp+var_2A], al
mov [ebp+var_29], bl
mov [ebp+var_28], 62h
mov [ebp+var_27], 79h
mov [ebp+var_26], 69h
mov [ebp+var_25], dl
mov [ebp+var_24], al
mov [ebp+var_22], 72h
mov [ebp+var_21], bl
mov [ebp+var_20], dl
mov [ebp+var_1E], al
mov [ebp+var_1D], 0
call ds:atoi
add esp, 4
mov dword ptr [ebp+hostshort], eax
jmp short loc_401326
</pre>
</details>
## References
<a name="1">[1]</a> J. Stüttgen and M. Cohen,"Anti-Forensic Resilient Memory Acquisition," in DFRWS USA 2013 Conference, 2013. [Online]. Available: https://dfrws.org/presentation/anti-forensic-resilient-memory-acquisition/.
<a name="2">[2]</a> L. Maffia, D. Nisi, P. Kotzias, G. Lagorio, S. Aonzo, and D. Balzarotti, "Longitudinal Study of the Prevalence of Malware Evasive Techniques," arXiv:2112.11289 , 21 Dec 2021. [Online]. Available: https://arxiv.org/pdf/2112.11289.pdf.
<a name="3">[3]</a> "PlugX: Memory Forensics Lifecycle with Volatility," Volatility Labs, blog, 6 Nov. 2015. [Online]. Available: https://volatility-labs.blogspot.com/2015/11/plugx-memory-forensics-lifecycle-with.html.
<a name="4">[4]</a> http://blog.threatexpert.com/2008/04/kraken-changes-tactics.html
<a name="5">[5]</a> https://waleedassar.blogspot.com/search/label/anti-dump
<a name="6">[6]</a> https://www.gironsec.com/code/packers.pdf
@@ -0,0 +1,155 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>B0007</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>Virtualization/Sandbox Evasion: System Checks (<a href="https://attack.mitre.org/techniques/T1497/001/">T1497.001</a>, <a href="https://attack.mitre.org/techniques/T1633/001/">T1633.001</a>), Virtualization/Sandbox Evasion: User Activity Based Checks (<a href="https://attack.mitre.org/techniques/T1497/002/">T1497.002</a>)</b></td>
</tr>
<tr>
<td><b>Anti-Analysis Type</b></td>
<td><b>Detection</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.3</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>27 April 2024</b></td>
</tr>
</table>
# Sandbox Detection
Malware checks whether it is being executed inside an instrumented and isolated sandbox (test) environment. In performing reconnaissance of its environment, the malware will check a variety of user or system based artifacts. Examples include monitoring for user action as reflected by mouse clicks or timing checks [[1]](#1), [[2]](#2). Upon detection of the sandbox, conditional execution will change the malwares behavior. For example, execution may terminate, or activity may appear benign, e.g., connecting to a benign domain.
The related **Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/techniques/T1497/), [T1633](https://attack.mitre.org/techniques/T1633/))** ATT&CK techniques were defined subsequent to this MBC behavior.
## Methods
|Name|ID|Description|
|---|---|---|
|**Check Clipboard Data**|B0007.001|Checks clipboard data which can be used to detect whether execution is inside a sandbox.|
|**Check Files**|B0007.002|Sandboxes create files on the file system. Malware can check the different folders to find sandbox artifacts.|
|**Human User Check**|B0007.003|Detects whether there is any "user" activity on the machine, such as the movement of the mouse cursor, non-default wallpaper, or recently opened Office files. Directories or file might be counted. If there is no human activity, the machine is suspected to be a virtualized machine and/or sandbox. Other items used to detect a user: mouse clicks (single/double), DialogBox, scrolling, color of background pixel [[5]](#5). This method is similar to ATT&CK's [Virtualization/Sandbox Evasion: User Activity Based Checks](https://attack.mitre.org/techniques/T1497/002/) sub-technique. This method is also related to Unprotect techniques U1316 and U1317.|
|**Injected DLL Testing**|B0007.004|Testing for the name of a particular DLL that is known to be injected by a sandbox for API hooking is a common way of detecting sandbox environments. This can be achieved through the kernel32!GetModuleHandle API call and other means.|
|**Product Key/ID Testing**|[B0007.005](#b0007005-snippet)|Checking for a particular product key/ID associated with a sandbox environment (commonly associated with the Windows host OS used in the environment) can be used to detect whether a malware instance is being executed in a particular sandbox. This can be achieved through several means, including testing for the Key/ID in the Windows registry.|
|**Screen Resolution Testing**|B0007.006|Sandboxes aren't used in the same manner as a typical user environment, so most of the time the screen resolution stays at the minimum 800x600 or lower. No one is actually working on a such small screen. Malware could potentially detect the screen resolution to determine if it's a user machine or a sandbox. This method is related to Unprotect technique U1315.|
|**Self Check**|B0007.007|Malware may check its own characteristics to determine whether it's running in a sandbox. For example, a malicious Office document might check its file name or VB project name. This method is related to Unprotect technique U1303.|
|**Timing/Date Check**|B0007.008|Calling GetSystemTime or equiv and only executing code if the current date/hour/minute/second passes some check. Often this is for running only after or only until a specific date. This behavior can be mitigated in non-automated analysis environments. This method is related to Unprotect technique U1005.|
|**Timing/Uptime Check**|B0007.009|Comparing single GetTickCount with some value to see if system has been started at least *X* amount ago. This behavior can be mitigated in non-automated analysis environments.|
|**Test API Routines**|B0007.010|Calls Windows API routines with invalid arguments to identify error supression.|
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**Redhip**](../xample-malware/redhip.md)|2011|B0007.005|Redhip detects publicly available automated analysis workbenches (e.g., Joe Box) by considering OS product keys and special DLLs and checks for sandboxes and AV modules. [[3]](#3)|
|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0007.010|The malware checks for sandboxes that suppress errors returned from API routine calls the using ZwGetWriteWatch routine. [[4]](#4)|
|[**Terminator**](../xample-malware/terminator.md)|2013|--|The Terminator RAT evades a sandbox by not executing until after a reboot. Most sandboxes don't reboot during an analysis. [[6]](#6)|
|[**Ursnif**](../xample-malware/ursnif.md)|2016|B0007.007|Ursnif uses malware macros to evade sandbox detection - checking whether the filename contains only hexadecimal characters before the extension. [[10]](#10)|
|[**GotBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR performs several checks on the compromised machine to avoid being emulated or executed in a sandbox. [[7]](#7)|
|[**EvilBunny**](../xample-malware/evilbunny.md)|2011|--|EvilBunny hooks time retrieval APIs and calls each API twice to calculate a delta. Execution aborts depending on the delta value. [[8]](#8)|
|[**Vobfus**](../xample-malware/vobfus.md)|2016|--|Vobfus uses GetModuleHandle API to check for the presence of a sandbox. [[9]](#9)|
## Detection
|Tool: capa|Mapping|APIs|
|---|---|---|
|[check for microsoft office emulation](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-vm/vm-detection/check-for-microsoft-office-emulation.yml)|Sandbox Detection::Product Key/ID Testing (B0007.005)|CreateFile|
|[check for sandbox and av modules](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml)|Sandbox Detection (B0007)|GetModuleHandle|
|Tool: CAPE|Mapping|APIs|
|---|---|---|
|[antisandbox_joe_anubis_files.py](https://github.com/kevoreilly/community/blob/master/modules/signatures/windows/antisandbox_joe_anubis_files.py)|Sandbox Detection::Check Files (B0007.002)|--|
|[antisandbox_cuckoo_files](https://github.com/kevoreilly/community/blob/master/modules/signatures/windows/antisandbox_cuckoo_files.py)|Sandbox Detection::Check Files (B0007.002)|--|
|[antisandbox_cuckoo_files](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_cuckoo_files.py)|Sandbox Detection (B0007)|--|
|[antisandbox_cuckoo_files](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_cuckoo_files.py)|Sandbox Detection::Check Files (B0007.002)|--|
|[antisandbox_threattrack_files](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_threattrack_files.py)|Sandbox Detection (B0007)|--|
|[antisandbox_threattrack_files](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_threattrack_files.py)|Sandbox Detection::Check Files (B0007.002)|--|
|[antisandbox_sleep](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_sleep.py)|Sandbox Detection (B0007)|NtDelayExecution|
|[antisandbox_sleep](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_sleep.py)|Sandbox Detection::Timing/Date Check (B0007.008)|NtDelayExecution|
|[antisandbox_mouse_hook](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_mouse_hook.py)|Sandbox Detection (B0007)|SetWindowsHookExA, SetWindowsHookExW|
|[antisandbox_mouse_hook](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_mouse_hook.py)|Sandbox Detection::Human User Check (B0007.003)|SetWindowsHookExA, SetWindowsHookExW|
|[antisandbox_foregroundwindows](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_forehwnd.py)|Sandbox Detection (B0007)|GetForegroundWindow, NtDelayExecution|
|[antisandbox_sboxie_mutex](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_sboxie_mutex.py)|Sandbox Detection (B0007)|--|
|[antisandbox_script_timer](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_scripttimer.py)|Sandbox Detection (B0007)|--|
|[antisandbox_sboxie_libs](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_sboxie_libs.py)|Sandbox Detection (B0007)|LdrGetDllHandle, LdrLoadDll|
|[antisandbox_cuckoocrash](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_cuckoocrash.py)|Sandbox Detection (B0007)|--|
|[antisandbox_joe_anubis_files](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_joe_anubis_files.py)|Sandbox Detection (B0007)|--|
|[antisandbox_joe_anubis_files](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_joe_anubis_files.py)|Sandbox Detection::Check Files (B0007.002)|--|
|[antisandbox_fortinet_files](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_fortinet_files.py)|Sandbox Detection (B0007)|--|
|[antisandbox_fortinet_files](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_fortinet_files.py)|Sandbox Detection::Check Files (B0007.002)|--|
|[antisandbox_sunbelt_files](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_sunbelt_files.py)|Sandbox Detection (B0007)|--|
|[antisandbox_sunbelt_files](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_sunbelt_files.py)|Sandbox Detection::Check Files (B0007.002)|--|
|[antisandbox_sboxie_objects](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_sboxie_objects.py)|Sandbox Detection (B0007)|NtOpenDirectoryObject|
|[antisandbox_sunbelt_libs](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_sunbelt_libs.py)|Sandbox Detection (B0007)|LdrGetDllHandle, LdrLoadDll|
|[antisandbox_cuckoo](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_cuckoo.py)|Sandbox Detection (B0007)|--|
## Code Snippets
### B0007.005 Snippet
<details>
<summary> Sandbox Detection::Product Key/ID Testing </summary>
<pre>
asm
push ebx
add esp, 0FFFFFEF4h
xor ebx, ebx
push esp ; phkResult
push 1 ; samDesired
push 0 ; ulOptions
push offset SubKey ; "Software\Microsoft\Windows\CurrentVersi"...
push 80000002h ; hKey
call RegOpenKeyExA
test eax, eax
jnz short loc_405387
mov [esp+110h+cbData], 101h
lea eax, [esp+110h+cbData]
push eax ; lpcbData
lea eax, [esp+114h+Data]
push eax ; lpData
push 0 ; lpType
push 0 ; lpReserved
push offset ValueName ; "ProductId"
mov eax, [esp+124h+hKey]
push eax ; hKey
call RegQueryValueExA
lea eax, [esp+110h+Data]
cmp eax, offset a55274640267306 ; "55274-640-2673064-23950"
jnz short loc_405387
mov bl, 1
</pre>
</details>
## References
<a name="1">[1]</a> Check Point Research,"CP<r>: Evasion Techniques," evasions.checkpoint.com, [Online]. Available: https://evasions.checkpoint.com.
<a name="2">[2]</a> Splunk Threat Research Team,"From Macros to No Macros: Continuous Malware Improvements by QakBot," Splunk, blog,, 01 December 2022. [Online]. Available: https://www.splunk.com/en_us/blog/security/from-macros-to-no-macros-continuous-malware-improvements-by-qakbot.html.
<a name="3">[3]</a> https://web.archive.org/web/20200815134441/https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
<a name="4">[4]</a> https://blogs.cisco.com/security/talos/rombertik
<a name="5">[5]</a> https://github.com/LordNoteworthy/al-khaser
<a name="6">[6]</a> https://www.fireeye.com/content/dam/fireeye-www/current-threats/pdfs/pf/file/fireeye-hot-knives-through-butter.pdf
<a name="7">[7]</a> https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/
<a name="8">[8]</a> https://web.archive.org/web/20150311013500/http://www.cyphort.com/evilbunny-malware-instrumented-lua/
<a name="9">[9]</a> https://securitynews.sonicwall.com/xmlpost/revisiting-vobfus-worm-mar-8-2013/
<a name="10">[10]</a> https://www.proofpoint.com/us/threat-insight/post/ursnif-banking-trojan-campaign-sandbox-evasion-techniques
@@ -0,0 +1,256 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>B0009</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>Virtualization/Sandbox Evasion (<a href="https://attack.mitre.org/techniques/T1497/">T1497</a>, <a href="https://attack.mitre.org/techniques/T1633/">T1633</a>)</b></td>
</tr>
<tr>
<td><b>Anti-Analysis Type</b></td>
<td><b>Detection</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.4</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>27 December 2024</b></td>
</tr>
</table>
# Virtual Machine Detection
Malware checks whether it is being executed inside a virtual environment. In performing reconnaissance of its environment, the malware will check on a variety of user or system based artifacts. Examples include:
- monitoring for user action as reflected by scrolling
- verifying system characteristics through Windows Management Interface (WMI) queries, e.g., for MAC address
- observing whether tool artifacts represented by strings or processes exist, e.g., VirtualBox.exe or joeboxserver.exe
- checking specific registry keys or values [[1]](#1)
Upon detection of the virtual machine, conditional execution will change the malwares behavior. For example, execution may terminate, or activity may appear benign, e.g., connecting to a benign domain.
The related **Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/techniques/T1497/), [T1633](https://attack.mitre.org/techniques/T1633/))** ATT&CK techniques were defined subsequent to this MBC behavior.
## Methods
|Name|ID|Description|
|---|---|---|
|**Check File and Directory Artifacts**|B0009.001|Virtual machines create files on the file system (e.g., VMware creates files in the installation directory C:\Program Files\VMware\VMware Tools). Malware can check the different folders to find virtual machine artifacts (e.g., Virtualbox has the artifact VBoxMouse.sys). [[2]](#2)|
|**Check Memory Artifacts**|B0009.002|VMware leaves many artifacts in memory. Some are critical processor structures, which, because they are either moved or changed on a virtual machine, leave recognizable footprints. Malware can search through physical memory for the strings VMware, commonly used to detect memory artifacts. [[2]](#2)|
|**Check Named System Objects**|B0009.003|Virtual machines often include specific named system objects by default, such as Windows device drivers, which can be detected by testing for specific strings, whether found in the Windows registry or other places.|
|**Check Processes**|B0009.004|The VMware Tools use processes like VMwareServices.exe or VMwareTray.exe, to perform actions on the virtual environment. Malware can list the processes and searches for the VMware string. Processes related to Virtualbox can be detected by the malware by querying the process list. [[2]](#2) This method is related to Unprotect technique U1334.|
|**Check Registry Keys**|B0009.005|Virtual machines register artifacts in the registry, which can be detected by malware. For example, a search for "VMware" or "VBOX" in the registry might reveal keys that include information about a virtual hard drive, adapters, running services, or a virtual mouse. [[2]](#2) Example registry key value artifacts include "HARDWARE\Description\System (SystemBiosVersion) (VBOX)" and "SYSTEM\ControlSet001\Control\SystemInformation (SystemManufacturer) (VMWARE)"; example registry key artifacts include "SOFTWARE\VMware, Inc.\VMware Tools (VMWARE)" and "SOFTWARE\Oracle\VirtualBox Guest Additions (VBOX)". [[5]](#5)|
|**Check Running Services**|B0009.006|VMwareService.exe runs the VMware Tools Service as a child of services.exe. It can be identified by listing services. [[2]](#2)|
|**Check Software**|B0009.007|Malware may check software version; for example, to determine whether the software is relatively current.|
|**Check Virtual Devices**|B0009.008|The presence of virtual devices can indicate a virtualized environment (e.g., "\\.\VBoxTrayIPC"). [[5]](#5)|
|**Check Windows**|B0009.009|Malware may check windows for VM-related characteristics.|
|**Check Windows - Title bars**|B0009.022|Malware may check windows for VM-related characteristics. May inject malicious code to svchost.exe to check all open window title bar text to a list of strings indicating virtualized environment.|
|**Check Windows - Unique windows**|B0009.021|Malware may check windows for VM-related characteristics. May check for the presence of known windows from analysis tools running in a VM.|
|**Check Windows - Window size**|B0009.020|Malware may check windows for VM-related characteristics. Tiny window size may indicate a VM.|
|**Check Username or Hostname**|B0009.039|Malware checks for hostnames or session usernames that indicate the use of a virtual machine.|
|**Guest Process Testing**|B0009.010|Virtual machines offer guest additions that can be installed to add functionality such as clipboard sharing. Detecting the process responsible for these tasks, via its name or other methods, is a technique employed by malware for detecting whether it is being executed in a virtual machine.|
|**HTML5 Performance Object Check**|B0009.011|In three browser families, it is possible to extract the frequency of the Windows performance counter frequency, using standard HTML and Javascript. This value can then be used to detect whether the code is being executed in a virtual machine, by detecting two specific frequencies commonly used in virtual but not physical machines.|
|**Human User Check**|B0009.012|Detects whether there is any "user" activity on the machine, such as the movement of the mouse cursor, non-default wallpaper, or recently opened Office files. Directories or file might be counted. If there is no human activity, the machine is suspected to be a virtualized machine and/or sandbox. Other items used to detect a user: mouse clicks (single/double), DialogBox, scrolling, color of background pixel, change in foreground window [[5]](#5). This method is very similar to ATT&CK's [Virtualization/Sandbox Evasion: User Activity Based Checks](https://attack.mitre.org/techniques/T1497/002/) sub-technique.|
|**Instruction Testing**|[B0009.029](#b0009029-snippet)|The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2)|
|**Instruction Testing - CPUID**|B0009.034|The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2) Checking the CPU ID found within the registry can provide information to system type. This method is related to Unprotect technique U1324.|
|**Instruction Testing - IN**|B0009.035|The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2) This method is related to Unprotect technique U1323.|
|**Instruction Testing - RDTSC**|B0009.036|The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2)|
|**Instruction Testing - SGDT/SLDT (no pill)**|B0009.031|The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2) The No Pill technique relies on the fact that the LDT structure is assigned to a processor not an Operating System. The LDT location on a host machine will be zero and on a virtual machine will be non-zero. This method is related to Unprotect technique U1327.|
|**Instruction Testing - SIDT (red pill)**|B0009.030|The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2) Red Pill is an anti-VM technique that executes the SIDT instruction to grab the value of the IDTR register. The virtual machine monitor must relocate the guest's IDTR to avoid conflict with the host's IDTR. Since the virtual machine monitor is not notified when the virtual machine runs the SIDT instruction, the IDTR for the virtual machine is returned. This method is related to Unprotect technique U1328.|
|**Instruction Testing - SMSW**|B0009.032|The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2) This method is related to Unprotect technique U1326.|
|**Instruction Testing - STR**|B0009.033|The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2) This method is related to Unprotect technique U1325.|
|**Instruction Testing - VMCPUID**|B0009.037|The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2) This method is related to Unprotect technique U1322.|
|**Instruction Testing - VPCEXT**|B0009.038|The execution of certain x86 instructions will result in different values when executed inside of a VM instead of on bare metal. Accordingly, these can be used to detect the execution of the malware in a VM. [[2]](#2) This method is related to Unprotect technique U1321.|
|**Modern Specs Check**|B0009.013|Different aspects of the hardware are inspected to determine whether the machine has modern characteristics. A machine with substandard specifications indicates a virtual environment.|
|**Modern Specs Check - Drive size**|B0009.015|Different aspects of the hardware are inspected to determine whether the machine has modern characteristics. A machine with substandard specifications indicates a virtual environment. Most modern machines have at least 80 GB disks. May use DeviceloControl (IOCTL_DISK_GET_LENGTH_INFO) or GetDiskFreeSpaceEx (TotalNumberOfBytes) [[5]](#5). This method is related to Unprotect technique U1312.|
|**Modern Specs Check - Keyboard layout**|B0009.019|Different aspects of the hardware are inspected to determine whether the machine has modern characteristics. A machine with substandard specifications indicates a virtual environment. Check keyboard layout.|
|**Modern Specs Check - Printer**|B0009.017|Different aspects of the hardware are inspected to determine whether the machine has modern characteristics. A machine with substandard specifications indicates a virtual environment. Checks whether there is a potential connected printer or default Windows printers; if not a virtual environment is suspected. This method is related to Unprotect technique U1309.|
|**Modern Specs Check - Processor count**|B0009.018|Different aspects of the hardware are inspected to determine whether the machine has modern characteristics. A machine with substandard specifications indicates a virtual environment. Checks number of processors; single CPU machines are suspect. This method is related to Unprotect technique U1340.|
|**Modern Specs Check - Total physical memory**|B0009.014|Different aspects of the hardware are inspected to determine whether the machine has modern characteristics. A machine with substandard specifications indicates a virtual environment. Most modern machines have at leave 4 GB of memory. (GlobalMemoryStatusEx) [[5]](#5). This method is related to Unprotect technique U1313.|
|**Modern Specs Check - USB drive**|B0009.016|Different aspects of the hardware are inspected to determine whether the machine has modern characteristics. A machine with substandard specifications indicates a virtual environment. Checks whether there is a potential USB drive; if not a virtual environment is suspected. This method is related to Unprotect technique U1310.|
|**Unique Hardware/Firmware Check**|B0009.023|Malware may check for hardware characteristics unique to being virtualized, allowing the malware to detect the virtual environment.|
|**Unique Hardware/Firmware Check - BIOS**|B0009.024|Malware may check for hardware characteristics unique to being virtualized, allowing the malware to detect the virtual environment. Characteristics of the BIOS, such as version, can indicate virtualization.|
|**Unique Hardware/Firmware Check - CPU Location**|B0009.027|Malware may check for hardware characteristics unique to being virtualized, allowing the malware to detect the virtual environment. When an Operating System is virtualized, the CPU is relocated. [[2]](#2)|
|**Unique Hardware/Firmware Check - CPU Name**|B0009.026|Malware may check for hardware characteristics unique to being virtualized, allowing the malware to detect the virtual environment. Checks the CPU name to determine virtualization.|
|**Unique Hardware/Firmware Check - I/O Communication Port**|B0009.025|Malware may check for hardware characteristics unique to being virtualized, allowing the malware to detect the virtual environment. VMware uses virtual I/O ports for communication between the virtual machine and the host operating system to support functionality like copy and paste between the two systems. The port can be queried and compared with a magic number VMXh to identify the use of VMware. This method is related to Unprotect technique U1336.|
|**Unique Hardware/Firmware Check - MAC Address**|B0009.028|Malware may check for hardware characteristics unique to being virtualized, allowing the malware to detect the virtual environment. VMware uses specific virtual MAC address that can be detected. The usual MAC address used started with the following numbers: "00:0C:29", "00:1C:14", "00:50:56", "00:05:69". Virtualbox uses specific virtual MAC address that can be detected by Malware. The usual MAC address used started with the following numbers: 08:00:27. [[2]](#2) This method is related to Unprotect technique U1335.|
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|--|GravityRAT checks system temperature by recording thermal readings for detecting VMs. Heat levels indicate whether the system is a VM. [[3]](#3)|
|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|B0009.018|GravityRAT determines the machine is a VM if the core count is 1. [[3]](#3)|
|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|B0009.023|GravityRAT checks if the manufacturer field in the Win32_Computer entry (in WMI) contains "Virtual," "Vmware," or "Virtualbox." [[3]](#3)|
|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|B0009.024|GravityRAT creates a WMI request to identify the BIOS version. [[13]](#13)|
|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|B0009.028|GravityRAT checks if the MAC address starts with a well-known hexadecimal number used by various VM developers. [[3]](#3)|
|[**WebCobra**](../xample-malware/webcobra.md)|2018|B0009.022|WebCobra injects malicious code in to svchost.exe and uses an infinite loop to check all open windows and to compare each windows title bar text with a set of strings to determine whether it is running in a VM. [[4]](#4)|
|[**Redhip**](../xample-malware/redhip.md)|2011|--|Redhip detects VMWare, Virtual PC, and Virtual Box. It also detects VM environments in general by considering time lapses. [[6]](#6)|
|[**Emotet**](../xample-malware/emotet.md)|2018|B0009.010|Emotet checks for various processes that are associated with various virtual machines by comparing hash values of the process names with the hash values of the list of running process names. [[7]](#7)|
|[**Vobfus**](../xample-malware/vobfus.md)|2016|--|Vobfus checks for the presence of virtualization software by querying the system registry. [[8]](#8)|
|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0009.003|Malware checks if it is running in a sandbox. If it is, the malware exits. [[9]](#9) [[10]](#10)|
|[**Ursnif**](../xample-malware/ursnif.md)|2016|B0009.004|The malware checks if there are virtual machine processes running (Vbox, vmware, etc). [[11]](#11)|
|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|B0009.012|The malware checks for an unmoving mouse cursor. [[12]](#12)|
## Detection
|Tool: capa|Mapping|APIs|
|---|---|---|
|[check for sandbox and av modules](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml)|Virtual Machine Detection (B0009)|GetModuleHandle|
|[check for Windows sandbox via genuine state](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-genuine-state.yml)|Virtual Machine Detection (B0009)|SLIsGenuineLocal, UuidFromString|
|[reference anti-VM strings targeting Parallels](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-parallels.yml)|Virtual Machine Detection (B0009)|--|
|[check for unmoving mouse cursor](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-vm/vm-detection/check-for-unmoving-mouse-cursor.yml)|Virtual Machine Detection::Human User Check (B0009.012)|--|
|[reference anti-VM strings targeting VirtualPC](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualpc.yml)|Virtual Machine Detection (B0009)|--|
|[reference anti-VM strings targeting VMWare](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-vmware.yml)|Virtual Machine Detection (B0009)|--|
|[check for foreground window switch](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-vm/vm-detection/check-for-foreground-window-switch.yml)|Virtual Machine Detection::Human User Check (B0009.012)|Sleep|
|[detect VM via disk hardware WMI queries](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-vm/vm-detection/detect-vm-via-disk-hardware-wmi-queries.yml)|Virtual Machine Detection::Unique Hardware/Firmware Check (B0009.023)|--|
|[reference anti-VM strings targeting Qemu](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-qemu.yml)|Virtual Machine Detection (B0009)|--|
|[reference anti-VM strings targeting Xen](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-xen.yml)|Virtual Machine Detection (B0009)|--|
|[check for sandbox username or hostname](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-vm/vm-detection/check-for-sandbox-username-or-hostname.yml)|Virtual Machine Detection (B0009)|--|
|[check for Windows sandbox via process name](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-process-name.yml)|Virtual Machine Detection (B0009)|--|
|[check for Windows sandbox via dns suffix](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-dns-suffix.yml)|Virtual Machine Detection (B0009)|GetAdaptersAddresses|
|[check for Windows sandbox via device](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-device.yml)|Virtual Machine Detection (B0009)|--|
|[reference anti-VM strings targeting VirtualBox](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualbox.yml)|Virtual Machine Detection (B0009)|--|
|[check for Windows sandbox via registry](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-vm/vm-detection/check-for-windows-sandbox-via-registry.yml)|Virtual Machine Detection (B0009)|RegOpenKeyEx, RegEnumValue|
|[reference anti-VM strings](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings.yml)|Virtual Machine Detection (B0009)|--|
|Tool: CAPE|Mapping|APIs|
|---|---|---|
|[antivm_generic_disk](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_disk.py)|Virtual Machine Detection (B0009)|DeviceIoControl, NtClose, NtCreateFile, NtDuplicateObject, NtOpenFile, NtDeviceIoControlFile|
|[antivm_generic_disk](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_disk.py)|Virtual Machine Detection::Modern Specs Check - Drive size (B0009.015)|DeviceIoControl, NtClose, NtCreateFile, NtDuplicateObject, NtOpenFile, NtDeviceIoControlFile|
|[antivm_vpc_mutex](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vpc_mutex.py)|Virtual Machine Detection (B0009)|--|
|[antivm_directory_objects](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_dirobjects.py)|Virtual Machine Detection (B0009)|NtQueryDirectoryObject, NtOpenDirectoryObject|
|[antivm_directory_objects](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_dirobjects.py)|Virtual Machine Detection::Check File and Directory Artifacts (B0009.001)|NtQueryDirectoryObject, NtOpenDirectoryObject|
|[antivm_network_adapters](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_network_adapter.py)|Virtual Machine Detection (B0009)|GetAdaptersAddresses|
|[antivm_generic_cpu](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_cpu.py)|Virtual Machine Detection (B0009)|--|
|[antivm_generic_cpu](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_cpu.py)|Virtual Machine Detection::Check Registry Keys (B0009.005)|--|
|[antivm_generic_cpu](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_cpu.py)|Virtual Machine Detection::Unique Hardware/Firmware Check - BIOS (B0009.024)|--|
|[antivm_vbox_provname](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vbox_provname.py)|Virtual Machine Detection (B0009)|WNetGetProviderNameW|
|[antivm_vbox_provname](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vbox_provname.py)|Virtual Machine Detection::Check File and Directory Artifacts (B0009.001)|WNetGetProviderNameW|
|[antivm_generic_bios](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_bios.py)|Virtual Machine Detection (B0009)|--|
|[antivm_generic_bios](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_bios.py)|Virtual Machine Detection::Check Registry Keys (B0009.005)|--|
|[antivm_generic_bios](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_bios.py)|Virtual Machine Detection::Unique Hardware/Firmware Check - BIOS (B0009.024)|--|
|[antivm_vbox_keys](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vbox_keys.py)|Virtual Machine Detection (B0009)|--|
|[antivm_vbox_keys](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vbox_keys.py)|Virtual Machine Detection::Check Registry Keys (B0009.005)|--|
|[antivm_vmware_events](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vmware_events.py)|Virtual Machine Detection (B0009)|NtOpenEvent, NtCreateEvent|
|[antivm_vbox_devices](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vbox_devices.py)|Virtual Machine Detection (B0009)|--|
|[antivm_vbox_devices](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vbox_devices.py)|Virtual Machine Detection::Check Virtual Devices (B0009.008)|--|
|[antivm_vmware_devices](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vmware_devices.py)|Virtual Machine Detection (B0009)|--|
|[antivm_vmware_devices](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vmware_devices.py)|Virtual Machine Detection::Check Virtual Devices (B0009.008)|--|
|[antivm_hyperv_keys](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_hyperv_keys.py)|Virtual Machine Detection (B0009)|--|
|[antivm_hyperv_keys](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_hyperv_keys.py)|Virtual Machine Detection::Check Registry Keys (B0009.005)|--|
|[antivm_vbox_files](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vbox_files.py)|Virtual Machine Detection (B0009)|--|
|[antivm_vbox_files](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vbox_files.py)|Virtual Machine Detection::Check Virtual Devices (B0009.008)|--|
|[antisandbox_mouse_hook](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_mouse_hook.py)|Virtual Machine Detection (B0009)|SetWindowsHookExA, SetWindowsHookExW|
|[antisandbox_mouse_hook](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_mouse_hook.py)|Virtual Machine Detection::Human User Check (B0009.012)|SetWindowsHookExA, SetWindowsHookExW|
|[antivm_generic_scsi](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_scsi.py)|Virtual Machine Detection (B0009)|RegOpenKeyExW, RegQueryValueExA, RegQueryValueExW, RegOpenKeyExA|
|[antivm_generic_scsi](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_scsi.py)|Virtual Machine Detection::Check Registry Keys (B0009.005)|RegOpenKeyExW, RegQueryValueExA, RegQueryValueExW, RegOpenKeyExA|
|[antivm_vmware_libs](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vmware_libs.py)|Virtual Machine Detection (B0009)|LdrLoadDll|
|[antivm_vmware_libs](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vmware_libs.py)|Virtual Machine Detection::Check File and Directory Artifacts (B0009.001)|LdrLoadDll|
|[antivm_xen_keys](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_xen_keys.py)|Virtual Machine Detection (B0009)|--|
|[antivm_xen_keys](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_xen_keys.py)|Virtual Machine Detection::Check Registry Keys (B0009.005)|--|
|[antivm_parallels_keys](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_parallels_keys.py)|Virtual Machine Detection (B0009)|--|
|[antivm_parallels_keys](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_parallels_keys.py)|Virtual Machine Detection::Check Registry Keys (B0009.005)|--|
|[antivm_generic_diskreg](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_diskreg.py)|Virtual Machine Detection (B0009)|--|
|[antivm_generic_diskreg](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_diskreg.py)|Virtual Machine Detection::Check Registry Keys (B0009.005)|--|
|[antivm_vpc_keys](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vpc_keys.py)|Virtual Machine Detection (B0009)|--|
|[antivm_vpc_keys](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vpc_keys.py)|Virtual Machine Detection::Check Registry Keys (B0009.005)|--|
|[antivm_bochs_keys](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_bochs_keys.py)|Virtual Machine Detection (B0009)|--|
|[antivm_bochs_keys](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_bochs_keys.py)|Virtual Machine Detection::Check Registry Keys (B0009.005)|--|
|[antivm_vpc_files](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vpc_files.py)|Virtual Machine Detection (B0009)|--|
|[antivm_vpc_files](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vpc_files.py)|Virtual Machine Detection::Check File and Directory Artifacts (B0009.001)|--|
|[antivm_vmware_mutexes](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vmware_mutexes.py)|Virtual Machine Detection (B0009)|--|
|[antivm_vbox_libs](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vbox_libs.py)|Virtual Machine Detection (B0009)|LdrLoadDll|
|[antivm_vbox_libs](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vbox_libs.py)|Virtual Machine Detection::Check File and Directory Artifacts (B0009.001)|LdrLoadDll|
|[antivm_generic_system](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_system.py)|Virtual Machine Detection (B0009)|--|
|[antivm_generic_system](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_system.py)|Virtual Machine Detection::Check Registry Keys (B0009.005)|--|
|[antivm_vmware_files](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vmware_files.py)|Virtual Machine Detection (B0009)|--|
|[antivm_vmware_files](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vmware_files.py)|Virtual Machine Detection::Check File and Directory Artifacts (B0009.001)|--|
|[antivm_generic_services](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_services.py)|Virtual Machine Detection::Check Registry Keys (B0009.005)|RegOpenKeyExW, RegEnumKeyExW, RegEnumKeyExA, RegOpenKeyExA|
|[antivm_generic_services](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_services.py)|Virtual Machine Detection::Check Running Services (B0009.006)|RegOpenKeyExW, RegEnumKeyExW, RegEnumKeyExA, RegOpenKeyExA|
|[antivm_generic_disk_setupapi](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_disk_setupapi.py)|Virtual Machine Detection (B0009)|SetupDiGetClassDevsA, SetupDiGetClassDevsW|
|[antisandbox_sboxie_objects](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_sboxie_objects.py)|Virtual Machine Detection (B0009)|NtOpenDirectoryObject|
|[antivm_vmware_keys](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vmware_keys.py)|Virtual Machine Detection (B0009)|--|
|[antivm_vmware_keys](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vmware_keys.py)|Virtual Machine Detection::Check Registry Keys (B0009.005)|--|
|[antivm_vbox_window](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vbox_window.py)|Virtual Machine Detection (B0009)|--|
|[antivm_vbox_window](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vbox_window.py)|Virtual Machine Detection::Check Windows (B0009.009)|--|
## Code Snippets
### B0009.029 Snippet
<details>
<summary> Virtual Machine Detection::Instruction Testing </summary>
SHA256: cfaf863181e49906df33f9104795678f2fb41a007a8fd066a84fd99f613d7ef3
<pre>
asm
; ___unwind { // __except handler4
push ebp
mov ebp, esp
push 0FFFFFFFEh
push offset stru_413980
push offset __except handler4
mov eax, large fs:0
push eax
sub esp, 14h
push ebx
push esi
push edi
mov eax, ___security_cookie
xor [epb+ms_exc.registration.ScopeTable], eax
xor eax, ebp
push eax
lea eax, [ebp+ms_exc.registration]
mov large fs:0 eax
mov [ebp+var_19], al
; __try { // __except at loc_401CB8
mov [ebp+ms_exc.registration.TryLevel], eax
push ebx
mov ebx, 0
mov eax, 1
vpcext 7, 08h
test ebx, ebx
setz [ebp+var_19]
pop ebx
jmp short loc_401CBB
</pre>
</details>
## References
<a name="1">[1]</a> Check Point Research,"CP<r>: Evasion Techniques," evasions.checkpoint.com, [Online]. Available: https://evasions.checkpoint.com.
<a name="2">[2]</a> https://search.unprotect.it/category/sandbox-evasion/
<a name="3">[3]</a> https://blog.talosintelligence.com/2018/04/gravityrat-two-year-evolution-of-apt.html
<a name="4">[4]</a> https://www.mcafee.com/blogs/other-blogs/mcafee-labs/webcobra-malware-uses-victims-computers-to-mine-cryptocurrency/
<a name="5">[5]</a> https://github.com/LordNoteworthy/al-khaser
<a name="6">[6]</a> https://web.archive.org/web/20161025013916/https://web.archive.org/web/20200815134441/https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
<a name="7">[7]</a> https://securelist.com/the-banking-trojan-emotet-detailed-analysis/69560/
<a name="8">[8]</a> https://securitynews.sonicwall.com/xmlpost/revisiting-vobfus-worm-mar-8-2013/
<a name="9">[9]</a> https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/
<a name="10">[10]</a> https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader
<a name="11">[11]</a> https://www.proofpoint.com/us/threat-insight/post/ursnif-banking-trojan-campaign-sandbox-evasion-techniques
<a name="12">[12]</a> capa v4.0, analyzed at MITRE on 10/12/2022
<a name="12">[12]</a> https://www.hackread.com/gravityrat-malware-evades-detection-targets-india/
+26 -16
View File
@@ -1,23 +1,33 @@
|||
|--|-----|
|**ID**|**M9002**|
<table>
<tr>
<td><b>ID</b></td>
<td><b>OB0002</b></td>
</tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>12 June 2023</b></td>
</tr>
</table>
# Anti-Static Analysis
Behaviors and code characteristics that prevent static analysis or make it more difficult. Simple static analysis identifies features such as embedded strings, header information, hash values, and file metadata (e.g., creation date). More involved static analysis involves the disassembly of the binary code.
Two primary resources for anti-static analysis behaviors are [[1]](#1) and [[2]](#2).
Behaviors and code characteristics that prevent or hinder static analysis of the malware. Simple static analysis identifies features such as embedded strings, header information, or file metadata. More involved static analysis involves the disassembly of the binary code.
* **Call Graph Generation Evasion** [M0010](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/evade-call-graph.md)
* **Disassembler Evasion** [M0012](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/evade-disassembler.md)
* **Executable Code Obfuscation** [M0032](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/exe-code-obfuscate.md)
* **Executable Code Optimization** [M0034](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/exe-code-optimize.md)
* **Executable Code Virtualization** [M0008](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/exe-code-virtualize.md)
* **Obfuscated Files or Information** [E1027](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/obfuscate-files.md)
* **Software Packing** [E1045](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/software-packing.md)
* **Call Graph Generation Evasion** [B0010](../anti-static-analysis/call-graph-generation-evasion.md)
* **Disassembler Evasion** [B0012](../anti-static-analysis/disassembler-evasion.md)
* **Data Flow Analysis Evasion** [B0045](../anti-static-analysis/data-flow-analysis-evasion.md)
* **Executable Code Obfuscation** [B0032](../anti-static-analysis/executable-code-obfuscation.md)
* **Executable Code Optimization** [B0034](../anti-static-analysis/executable-code-optimization.md)
* **Executable Code Virtualization** [B0008](../anti-static-analysis/executable-code-virtualization.md)
* **Obfuscated Files or Information** [E1027](../defense-evasion/obfuscated-files-or-information.md)
* **Software Packing** [F0001](../anti-static-analysis/software-packing.md)
## References
References
----------
<a name="1">[1]</a> Unprotect Project, a database about malware self-defense and protection. http://unprotect.tdgt.org/index.php/Unprotect_Project
<a name="1">[1]</a> https://search.unprotect.it/category/sandbox-evasion/
<a name="2">[2]</a> InDepthUnpacking, course content for teaching malware anti-analysis techniques and mitigations, with emphasis on packers. https://github.com/knowmalware/InDepthUnpacking
<a name="2">[2]</a> InDepthUnpacking, course content for teaching malware anti-analysis techniques and mitigations, with emphasis on packers. https://github.com/knowmalware/InDepthUnpacking
@@ -0,0 +1,57 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>B0010</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../anti-static-analysis">Anti-Static Analysis</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>None</b></td>
</tr>
<tr>
<td><b>Anti-Analysis Type</b></td>
<td><b>Evasion</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>31 August 2023</b></td>
</tr>
</table>
# Call Graph Generation Evasion
Malicious code evades accurate call graph generation, which can be used for malware detection during disassembly of the binary [[1]](#1). Evading accurate call graph generation can also hinder follow-on analysis. For instance, using randomization of call graphs, malware can defeat call graph-based similarity analysis in which analysts calculate similarity between pairs of malicious binaries [[2]](#2), [[3]](#3). Application of clustering algorithms to malware call graphs has also resulted in the discovery of malware families [[4]] (#4).
## Methods
|Name|ID|Description|
|---|---|---|
|**Invoke NTDLL System Calls via Encoded Table**|B0010.002|Invokes ntdll.dll functions without using an export table; an encoded translation table on the stack is used instead. [[5]](#5)|
|**Two-layer Function Return**|B0010.001|Two layer jumping confuses tools plotting call graphs. [[5]](#5)|
|**Shadow Process Communication**|B0010.003| Uses multiple processes (instead of one process) to make behavior detection more difficult. [[6]](#6)|
## References
<a name="1">[1]</a> P. Deshpande and M. Stamp,"Metamorphic Malware Detection Using Function Call Graph Analysis," MIS Review, Vol. 21, Nos. 1/2, Sept.(2015)/Mar.(2016), [Online]. Available: https://pdfs.semanticscholar.org/8db2/69106ea6e1f59e4dac0889665dd3336ee9b1.pdf.
<a name="2">[2]</a> K. Blokhin, D. Mentis, and J. Saxe,"Malware Similarity Identification Using Call Graph Based System Call Subsequence Features," 2013 IEEE 33rd International Conference on Distributed Computing Systems Workshops, July 2013. [Online]. Available: https://www.researchgate.net/publication/269326967_Malware_Similarity_Identification_Using_Call_Graph_Based_System_Call_Subsequence_Features.
<a name="3">[3]</a> S. Shang, N. Zheng, J. Xu, M. Xu, and H. Zhang,"Detecting Malware Variants via Function-call Graph Similarity," IEEE 2010 5th International Conference on Malicious and Unwanted Software, 2010. [Online]. Available: https://seclab.hdu.edu.cn/static/uploads/paper/10-05.pdf.
<a name="4">[4]</a> J. Kinable, "Malware Detection Through Call Graphs," Master thesis, Department of Telematics, Norwegian University of Science and Technology, Norway, June 2010. [Online]. Available: https://ntnuopen.ntnu.no/ntnu-xmlui/bitstream/handle/11250/262290/353049_FULLTEXT01.pdf?sequence=1&isAllowed=y.
<a name="5">[5]</a> http://fumalwareanalysis.blogspot.com/2012/01/malware-analysis-tutorial-10-tricks-for.html
<a name="6">[6]</a> Weiqin Ma, Pu Duan, Sanmin Liu, Guofei Gu and Jyh-Charn Liu,"Shadow Attacks: Automatically Evading System-Call-Behavior Based Malware Detection" https://people.engr.tamu.edu/guofei/paper/ShadowAttacks_final-onecolumn.pdf
@@ -0,0 +1,47 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>B0045</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../anti-static-analysis">Anti-Static Analysis</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>None</b></td>
</tr>
<tr>
<td><b>Anti-Analysis Type</b></td>
<td><b>Evasion</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.0</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>26 June 2021</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>10 November 2022</b></td>
</tr>
</table>
# Data Flow Analysis Evasion
Malware code evades data flow analysis (also known as information flow analysis and taint-tracking).
## Methods
|Name|ID|Description|
|---|---|---|
|**Control Dependence**|B0045.001|Data is propagated via an if-then-else clause instead of direct assignment.[[1]](#1)|
|**Implicit Flows**|B0045.002|Data is propagated via semantic relationships, for example one variable not changing its state could imply the state of another variable.[[1]](#1)|
|**Arbitrary Memory Corruption**|B0045.003|Data is propagated by corrupting memory, for example overwriting a region of stack space where a file pointer is held.[[1]](#1)|
## References
<a name="1">[1]</a> http://www.seclab.cs.sunysb.edu/seclab/pubs/antitaint.pdf
@@ -0,0 +1,77 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>B0012</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../anti-static-analysis">Anti-Static Analysis</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>None</b></td>
</tr>
<tr>
<td><b>Anti-Analysis Type</b></td>
<td><b>Evasion</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.3</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>27 December 2024</b></td>
</tr>
</table>
# Disassembler Evasion
Anti-disassembly techniques take advantage of weaknesses in either flow-oriented (also referred to as recursive) or linear disassembler algorithms, resulting in inaccurate or incomplete disassembly or the disassembly process halting with an error. Reportedly, the most common anti-disassembly technique is one that employs two consecutive conditional jump instructions (jz followed by jnz) that point to the same target address [[1]](#1).
## Methods
|Name|ID|Description|
|---|---|---|
|**Argument Obfuscation**|B0012.001|Simple number or string arguments to API calls are calculated at runtime, making linear disassembly more difficult.|
|**Conditional Misdirection**|B0012.002|Conditional jumps are sometimes used to confuse disassembly engines, resulting in the wrong instruction boundaries and thus wrong mnemonic and operands; may be identified by instructions *jmp/jcc to a label+#* (e.g., JNE loc_401345fe+2).|
|**Desynchronizing Opaque Predicates**|B0012.006|Opaque predicates inject superfluous branches into the disassembly, resulting in disassembly desynchronization, as well as code bloat. The junk bytes introduced damage the disassembly process when the bytes are treated as code. [[6]](#6) This method is related to Unprotect technique U0201.|
|**Fake Function**|B0012.007|A fake function call is used to call an address which confuses a disassembler and results in incorrect disassembly. Manually undefining the function call can enable the disassembler to produce the true code.|
|**pusha/popa Sequence**|B0012.008|Malware uses excessive pusha and popa instructions to confuse disassemblers.|
|**VBA Stomping**|B0012.005|Typically, VBA source code is compiled into p-code, which is stored with compressed sourced code in the OLE file with VBA macros. VBA Stomping - when the VBA source code is removed and only the p-code remains - makes analysis much harder. See [[4]](#4) for an analysis of a VBA-Stomped malicious VBA Office document. See [[5]](#5) for information on Evil Clippy, a tool that creates malicious MS Office documents.|
|**Value Dependent Jumps**|B0012.003|Explicit use of computed values for control flow, often in the same basic block or function.|
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|B0012.001|BlackEnergy contains obfuscated stack strings. [[2]](#2) [[7]](#7)|
|[**Hupigon**](../xample-malware/hupigon.md)|2013|B0012.001|Hupigon contains obfuscated stack strings. [[7]](#7)|
|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0012.001|Rombertik contains obfuscated stack strings. [[7]](#7)|
## Detection
|Tool: capa|Mapping|APIs|
|---|---|---|
|[contain anti-disasm techniques](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-disasm/contain-anti-disasm-techniques.yml)|Disassembler Evasion (B0012)|--|
## References
<a name="1">[1]</a> M. Sikorski and A. Honig, Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software, No Starch Press, 2012.
<a name="2">[2]</a> https://web.archive.org/web/20220814013655/http://staff.ustc.edu.cn/~bjhua/courses/security/2014/readings/anti-disas.pdf
<a name="3">[3]</a> https://www.kernelhacking.com/rodrigo/docs/blackhat2012-paper.pdf
<a name="4">[4]</a> https://isc.sans.edu/diary/Malicious+VBA+Office+Document+Without+Source+Code/24870
<a name="5">[5]</a> https://boingboing.net/2019/05/05/p-code-r-us.html
<a name="6">[6]</a> https://www.ndss-symposium.org/wp-content/uploads/2020/04/bar2020-23004-paper.pdf
<a name="7">[7]</a> capa v4.0, analyzed at MITRE on 10/12/2022
-30
View File
@@ -1,30 +0,0 @@
|||
|---------|------------------------|
|**ID**|**M0010**|
|**Objective(s)**| [Anti-Static Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-static-analysis)|
|**Related ATT&CK Technique**|None|
Call Graph Generation Evasion
=============================
Malware code evades accurate call graph generation during disassembly. Call graphs are used by malware similarity tools and algorithms ([[1]](#1), [[4]](#4)), as well as for malware detection [[2]](#2).
Methods
-------
* **Two-layer Function Return**: two layer jumping confuses tools plotting call graphs. [[3]](#3)
* **Invoke NTDLL System Calls via Encoded Table**: invokes ntdll.dll functions without using an export table; an encoded translation table on the stack is used instead. [[3]](#3)
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|--------|-----------------------------|
References
----------
<a name="1">[1]</a> K. Blokhin, D. Mentis, J. Saxe, "Malware Similarity Identification Using Call Graph Based System Call Subsequence Features," 2013 IEEE 33rd International Conference on Distributed Computing Systems Workshops, July 2013. https://www.researchgate.net/publication/269326967_Malware_Similarity_Identification_Using_Call_Graph_Based_System_Call_Subsequence_Features
<a name="2">[2]</a> P. Deshpande, M. Stamp, "Metamorphic Malware Detection Using Function Call Graph Analysis," MIS Review Vol. 21, Nos. 1/2, September(2015)/March(2016). https://pdfs.semanticscholar.org/8db2/69106ea6e1f59e4dac0889665dd3336ee9b1.pdf
<a name="3">[3]</a> http://fumalwareanalysis.blogspot.com/2012/01/malware-analysis-tutorial-10-tricks-for.html
<a name="4">[4]</a> S. Shang, N. Zheng, J. Xu, M. Xu, H. Zhang, "Detecting Malware Variants via Function-call Graph Similarity," IEEE 2010 5th International Conference on Malicious and Unwanted Software, 2010. http://seclab.hdu.edu.cn/static/uploads/paper/10-05.pdf
@@ -1,33 +0,0 @@
|||
|---------|------------------------|
|**ID**|**M0012**|
|**Objective(s)**| [Anti-Static Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-static-analysis)|
|**Related ATT&CK Technique**|None|
Disassembler Evasion
====================
Malware code evades disassembly in a recursive or linear disassembler. Some methods apply to both types of disassemblers; others apply to one type and not the other.
Methods
-------
* **Argument Obfuscation**: Simple number or string arguments to API calls are calculated at runtime, making linear disassembly more difficult.
* **Conditional Misdirection**: Conditional jumps are sometimes used to confuse disassembly engines, resulting in the wrong instruction boundaries and thus wrong mnemonic and operands; identified by instructions *jmp/jcc to a label+#* (e.g., JNE loc_401345fe+2).
* **Value Dependent Jumps**: Explicit use of computed values for control flow, often many times in the same basic block or function.
* **Variable Recomposition**: Variables, often strings, are broken into multiple parts and store out of order, in different memory ranges, or both. They must then be recomposed before use.
* **VBA Stomping**: Typically, VBA source code is compiled into p-code, which is stored with compressed sourced code in the OLE file with VBA macros. VBA Stomping - when the VBA source code is removed and only the p-code remains - makes analysis much harder. See [[3]](#3) for an analysis of a VBA-Stomped malicious VBA Office document. See [[4]](#4) for information on Evil Clippy, a tool that creates malicious MS Office documents.
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|--------|-----------------------------|
References
----------
<a name="1">[1]</a> http://staff.ustc.edu.cn/~bjhua/courses/security/2014/readings/anti-disas.pdf
<a name="2">[2]</a> http://www.kernelhacking.com/rodrigo/docs/blackhat2012-paper.pdf
<a name="3">[3]</a> https://isc.sans.edu/diary/Malicious+VBA+Office+Document+Without+Source+Code/24870
<a name="4">[4]</a> https://boingboing.net/2019/05/05/p-code-r-us.html
@@ -1,49 +0,0 @@
|||
|---------|------------------------|
|**ID**|**M0032**|
|**Objective(s)**| [Anti-Static Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-static-analysis)|
|**Related ATT&CK Technique**|None|
Executable Code Obfuscation
===========================
Executable code can be obfuscated to hinder disassembly and static code analysis. This behavior is specific to a malware sample's executable code (data and text sections).
For encryption and encoding characteristics of malware samples, as well as malware obfuscation behaviors related to non-malware-sample files and information, see [**Obfuscated Files or Information**](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/obfuscate-files.md).
Methods
-------
* **API Hashing**: Instead of storing function names in the Import Address Table (IAT) and calling GetProcAddress, a DLL is loaded and the name of each of its exports is hashed until it matches a specific hash. Manual symbol resolution is then used to access and execute the exported function. This method is often used by shellcode because it reduces the size of each import from a human-readable string to a sequence of four bytes. The Method is also known as "Imports by Hash" and "GET_APIS_WITH_CRC." [[1]](#1)
* **Code Insertion**: Insert code to impede disassembly.
* *Dead Code Insertion*: Include "dead" code with no real functionality.
* *Fake Code Insertion*: Add fake code similar to known packers or known goods to fool identification. Can confuse some automated unpackers.
* *Jump Insertion*: Insert jumps to make analysis visually harder.
* *Thunk Code Insertion*: Variation on Jump Insertion. Used by some compilers for user-generated functions.
* *Junk Code Insertion*: Insert dummy code between relevant opcodes. Can make signature writing more complex.
* **Data Value Obfuscation**: Obfuscate data values through indirection of local or global variables. For example, the instruction *if (a == 0) do x* can be obfuscated by setting a global variable, *Z*, to zero and using it in the instruction: *if (a==Z) do x*. [NEEDS REVIEW]
* **Entry Point Obfuscation**: Obfuscate the entry point of the malware executable.
* **Guard Pages**: Encrypt blocks of code individually and decrypt temporarily only upon execution.
* **Import Address Table Obfuscation**: Obfuscate the import address table.
* **Import Compression**: Store and load imports with a compact import table format. Each DLL needed by the executable is mentioned in the IAT, but only one function from each/most is imported; the rest are imported via GetProcAddress calls.
* **Instruction Overlap**: Jump after the first byte of an instruction to confuse disassembler.
* **Interleaving Code**: Split code into sections that may be rearranged and are connected by unconditional jumps.
* **Merged Code Sections**: Merge all sections resulting in just one entry in the sections table to make readability more difficult. May affect some detection signatures if written to be section dependent.
* **Structured Exception Handling (SEH)**: A portion of the code always generates an exception so that malicious code is executed with the exception handling. See [[3]](#3).
* **Stack Strings**: Build and decrypt strings on the stack at each use, then discard to avoid obvious references.
* **Symbol Obfuscation**: Remove or rename symbolic information commonly inserted by compilers for debugging purposes.
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------------------------|--------|-----------------------------|
|[**Heriplor Trojan**](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/heriplor.md)|March 2019|The Heriplor Trojan uses API Hashing. [[1]](#1)|
|**Geodo**|August 2018|Geodo macros are heavily obfuscated with junk functions and string substitutions. [[2]](#2)|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
References
----------
<a name="1">[1]</a> https://insights.sei.cmu.edu/cert/2019/03/api-hashing-tool-imagine-that.html
<a name="2">[2]</a> https://cofense.com/recent-geodo-malware-campaigns-feature-heavily-obfuscated-macros/
<a name="3">[3]</a> Rob Simmons, "Comparing Malicious Files," BSides, 2019. http://www.irongeek.com/i.php?page=videos/bsidescharm2019/2-04-comparing-malicious-files-robert-simmons
-24
View File
@@ -1,24 +0,0 @@
|||
|---------|------------------------|
|**ID**|**M0034**|
|**Objective(s)**| [Anti-Static Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-static-analysis)|
|**Related ATT&CK Technique**|None|
Executable Code Optimization
============================
Code is optimized, making it harder to statically analyze.
Methods
-------
* **Jump/Call Absolute Address**: Relative operands of jumps and calls into are made absolute (better compression). May confuse some basic block detection algorithms.
* **Minification**: Minification is 'the process of removing all unnecessary characters from source code without changing its functionality.' [[1]](#1) A simple example is when all the unnecessary whitespace and comments are removed. Minification is distinguished from compression in that it neither adds to nor changes the code seen by the interpreter. Minification is often used for malware written in interpreted languages, such as JavaScript, PHP, or Python. Legitimate code that is transmitted many times a second, such as JavaScript on websites, often uses minification to simply reduce the number of bytes transmitted.
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|--------|-----------------------------|
References
----------
<a name="1">[1]</a> https://en.wikipedia.org/wiki/Minification_(programming)
@@ -1,28 +0,0 @@
|||
|---------|------------------------|
|**ID**|**M0008**|
|**Objective(s)**| [Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis), [Anti-Static Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-static-analysis)|
|**Related ATT&CK Technique**|None|
Executable Code Virtualization
==============================
Original executable code is virtualized by translating the code into a special format that only a special virtual machine (VM) can run; the VM uses a customized virtual instruction set. A "stub" function calls the VM when the code is run. Virtualized code makes static analysis and reverse engineering more difficult; dumped code wont run without the VM.
Virtualized code is a software protection technique. Themida is a commercial tool; WPProtect is an open source tool. [[1]](#1)
Methods
-------
* **Multiple VMs**: multiple virtual machines with different architectures (CISC, RISC, etc.) can be used inside of a single executable in order to make reverse engineering even more difficult.
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|--------|-----------------------------|
|[**Locky Bart**](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/locky-bart.md)|January 2017|Code virtualization is added to the Locky Bart binary using WPProtect. [[2]](#2)|
References
----------
<a name="1">[1]</a> https://github.com/xiaoweime/WProtect
<a name="2">[2]</a> https://blog.malwarebytes.com/threat-analysis/2017/01/locky-bart-ransomware-and-backend-server-analysis/
@@ -0,0 +1,162 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>B0032</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../anti-static-analysis">Anti-Static Analysis</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>None</b></td>
</tr>
<tr>
<td><b>Anti-Analysis Type</b></td>
<td><b>Evasion</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.1</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>5 December 2023</b></td>
</tr>
</table>
# Executable Code Obfuscation
Executable code is obfuscated to hinder static code analysis. This behavior is specific to a malware sample's executable code (data and text sections). While the Executable Code Obfuscation behavior makes the analysis process more difficult, it does not cause incorrect or incomplete disassembly, which is how this behavior differs from the Disassembler Evasion behavior.
For encryption and encoding characteristics of malware samples, as well as malware obfuscation behaviors related to non-malware sample files and information, see **Obfuscated Files or Information ([E1027](../defense-evasion/obfuscated-files-or-information.md))**.
## Methods
|Name|ID|Description|
|---|---|---|
|**Argument Obfuscation**|B0032.020|Simple number or string arguments to API calls are calculated at runtime, making analysis more difficult.|
|**API Hashing**|B0032.001|Instead of storing function names in the Import Address Table (IAT) and calling GetProcAddress, a DLL is loaded and the name of each of its exports is hashed until it matches a specific hash. Manual symbol resolution is then used to access and execute the exported function. This method is often used by shellcode because it reduces the size of each import from a human-readable string to a sequence of four bytes. The Method is also known as "Imports by Hash" and "GET_APIS_WITH_CRC." [[1]](#1) This method is related to Unprotect technique U0217.|
|**Code Insertion**|B0032.002|Insert code to impede disassembly and make analysis more difficult.|
|**Data Value Obfuscation**|B0032.008|Obfuscate data values through indirection of local or global variables. For example, the instruction *if (a == 0) do x* can be obfuscated by setting a global variable, *Z*, to zero and using it in the instruction: *if (a==Z) do x*. [NEEDS REVIEW]|
|**Dead Code Insertion**|B0032.003|Include "dead" code with no real functionality. When executing, malware may skip over such code via an opaque predicate.|
|**Entry Point Obfuscation**|B0032.009|Obfuscate the entry point of the malware executable.|
|**Fake Code Insertion**|B0032.004|Add fake code similar to known packers or known goods to fool identification. Can confuse some automated unpackers.|
|**Guard Pages**|B0032.010|Encrypt blocks of code individually and decrypt temporarily only upon execution. This method is related to Unprotect technique U0102.|
|**Import Address Table Obfuscation**|B0032.011|Obfuscate the import address table.|
|**Import Compression**|B0032.012|Store and load imports with a compact import table format. Each DLL needed by the executable is mentioned in the IAT, but only one function from each/most is imported; the rest are imported via GetProcAddress calls.|
|**Instruction Overlap**|B0032.013|Jump after the first byte of an instruction to confuse disassembler.|
|**Interleaving Code**|B0032.014|Split code into sections that may be rearranged and may be connected by unconditional jumps. When instructions are out of order, writing a function signature is more difficult.|
|**Jump Insertion**|B0032.005|Insert jumps to make analysis visually harder.|
|**Junk Code Insertion**|B0032.007|Insert dummy code between relevant opcodes. Can make signature writing more complex. This method is related to Unprotect technique U0204.|
|**Merged Code Sections**|B0032.015|Merge all sections resulting in just one entry in the sections table to make readability more difficult. May affect some detection signatures if written to be section depe
|**Opaque Predicate**|B0032.019|An opaque predicate either always jumps (jumping over dead or junk code) or never jumps (executing essential code), but determining the execution path can be difficult. This method is related to Unprotect technique U0201.|
|**Stack Strings**|[B0032.017](#b0032017-snippet)|Build and decrypt strings on the stack at each use, then discard to avoid obvious references.|
|**Structured Exception Handling (SEH)**|B0032.016|A portion of the code always generates an exception so that malicious code is executed with the exception handling. See [[3]](#3). This method is related to Unprotect technique U0218.|
|**Symbol Obfuscation**|B0032.018|Remove or rename symbolic information commonly inserted by compilers for debugging purposes.|
|**Thunk Code Insertion**|B0032.006|Variation on Jump Insertion. Used by some compilers for user-generated functions.|
|**Variable Recomposition**|B0032.021|Variables, often strings, are broken into multiple parts and stored out of order, in different memory ranges, or both. They must then be recomposed before use, making analysis difficult.|
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**Heriplor**](../xample-malware/heriplor.md)|2012|B0032.001|The Heriplor Trojan uses API Hashing. [[1]](#1)|
|[**Emotet**](../xample-malware/emotet.md)|2018|B0032.007|Emotet macros are heavily obfuscated with junk functions and string substitutions. [[2]](#2)|
|[**Rombertik**](../anti-static-analysis/executable-code-obfuscation.md)|2015|B0032.002|Most of the malware file consists of unnecessary code or unnecessary data. [[4]](#4)|
|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|B0032.017|Poison Ivy variant encrypts all its strings. [[6]](#6)|
|[**SamSam**](../xample-malware/samsam.md)|2015|--|SamSam obfuscates functions, class names and strings, including the list of targeted file extensions, the help file contents and environment variables using DES encryption with a fixed hard-coded key and the IV. [[7]](#7)|
|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|E1027.m01|The configuration data block is encoded with a NOT XOR 0xFF operation. [[8]](#8)|
|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0032.001|The function to import APIs uses a hash value and the DLL name of the target API. The API address returned from the function is stored into a global variance. API calls are obfuscated in the same manner as the stack strings and are resolved dynamically as the malware needs to use them. The malware encodes data in a stack string and copies that data into a global character buffer as a form of string obfuscation. [[9]](#9) [[10]](#10)|
|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0032.017|The malware encodes data in a stack string and copies that data into a global character buffer as a form of string obfuscation. Different techniques are used to encrypt and obfuscate strings. Strings are dynamically decrypted when the malware needs to use them. [[9]](#9) [[10]](#10)|
|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0032.009|The malware has 4 different export functions. [[9]](#9) [[10]](#10)|
## Detection
|Tool: capa|Mapping|APIs|
|---|---|---|
|[obfuscated with ADVobfuscator](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/obfuscation/obfuscated-with-advobfuscator.yml)|Executable Code Obfuscation (B0032)|--|
|[obfuscated with DeepSea Obfuscator](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/obfuscation/obfuscated-with-deepsea-obfuscator.yml)|Executable Code Obfuscation (B0032)|--|
|[obfuscated with callobfuscator](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/obfuscation/obfuscated-with-callobfuscator.yml)|Executable Code Obfuscation (B0032)|--|
|[obfuscated with Dotfuscator](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/obfuscation/obfuscated-with-dotfuscator.yml)|Executable Code Obfuscation (B0032)|--|
|[obfuscated with vs-obfuscation](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/obfuscation/obfuscated-with-vs-obfuscation.yml)|Executable Code Obfuscation (B0032)|--|
|[obfuscated with Spices.Net Obfuscator](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/obfuscation/obfuscated-with-spicesdotnet-obfuscator.yml)|Executable Code Obfuscation (B0032)|--|
|[obfuscated with Babel Obfuscator](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/obfuscation/obfuscated-with-babel-obfuscator.yml)|Executable Code Obfuscation (B0032)|--|
|[obfuscated with SmartAssembly](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/obfuscation/obfuscated-with-smartassembly.yml)|Executable Code Obfuscation (B0032)|--|
|[obfuscated with Yano](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/obfuscation/obfuscated-with-yano.yml)|Executable Code Obfuscation (B0032)|--|
|[contain obfuscated stackstrings](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/obfuscation/string/stackstring/contain-obfuscated-stackstrings.yml)|Executable Code Obfuscation::Argument Obfuscation (B0032.020)|--|
|[contain obfuscated stackstrings](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/obfuscation/string/stackstring/contain-obfuscated-stackstrings.yml)|Executable Code Obfuscation::Stack Strings (B0032.017)|--|
|[use .NET library EncryptDecryptUtils](https://github.com/mandiant/capa-rules/blob/master/data-manipulation/encryption/aes/use-dotnet-library-encryptdecryptutils.yml)|Executable Code Obfuscation (B0032)|--|
## Code Snippets
### B0032.017 Snippet
<details>
<summary> Executable Code Obfuscation::Stack Strings </summary>
SHA256: 304f533ce9ea4a9ee5c19bc81c49838857c63469e26023f330823c3240ee4e03
<pre>
asm
mov cl, 65h ; 'e'
mov al, 70h ; 'p'
mov [ebp+var_23], cl
mov [ebp_var_1f], cl
mov [ebp_Str], bl
mov [ebp+var_12], bl
mov [ebp+var_2E], al
mov [ebp+var_2D], al
lea ecx, [ebp+Str]
mov al, 74h ; 't'
mov bl, 2Eh ; '.'
mov dl. 6Eh ; 'n'
push ecx ; STR
mov [ebp+var_13], 30h ; '0'
mov [ebp+var_11], 30h ; '0'
mov [ebp+var_10], 0
mov [ebp+cp], 73h ; 's'
mov [ebp+var_2F], 75h ; u'
mov [ebp+var_2C], 6Fh ; 'o'
mov [ebp+var_2B], 72h ; 'r'
mov [ebp+var_2A], al
mov [ebp+var_29], bl
mov [ebp+var_28], 62h ; 'b'
mov [ebp+var_27], 79h ; 'y'
mov [ebp+var_26], 69h ; 'i'
mov [ebp+var_25], dl
mov [ebp+var_24], al
mov [ebp+var_22], 72h ; 'r'
mov [ebp+var_21], bl
mov [ebp+var_20], dl
mov [ebp+var_1E], al
mov [ebp+var_1D], h
call ds:atoi
add esp, 4
mov dword ptr [ebp+hostshort], eax
jmp short loc_401326
</pre>
</details>
## References
<a name="1">[1]</a> https://insights.sei.cmu.edu/blog/api-hashing-tool-imagine-that/
<a name="2">[2]</a> https://cofense.com/blog/recent-geodo-malware-campaigns-feature-heavily-obfuscated-macros/
<a name="3">[3]</a> Rob Simmons, "Comparing Malicious Files," BSides, 2019. http://www.irongeek.com/i.php?page=videos/bsidescharm2019/2-04-comparing-malicious-files-robert-simmons
<a name="4">[4]</a> https://blogs.cisco.com/security/talos/rombertik
<a name="5">[5]</a> https://www.proofpoint.com/us/threat-insight/post/ursnif-variant-dreambot-adds-tor-functionality
<a name="6">[6]</a> https://www.fortinet.com/blog/threat-research/deep-analysis-of-new-poison-ivy-variant
<a name="7">[7]</a> https://blog.talosintelligence.com/2018/01/samsam-evolution-continues-netting-over.html
<a name="8">[8]</a> https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en
<a name="9">[9]</a> https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/
<a name="10">[10]</a> https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader
@@ -0,0 +1,46 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>B0034</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../anti-static-analysis">Anti-Static Analysis</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>None</b></td>
</tr>
<tr>
<td><b>Anti-Analysis Type</b></td>
<td><b>Evasion</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.0</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>10 November 2022</b></td>
</tr>
</table>
# Executable Code Optimization
Code is optimized, making it harder to statically analyze.
## Methods
|Name|ID|Description|
|---|---|---|
|**Jump/Call Absolute Address**|B0034.001|Relative operands of jumps and calls into are made absolute (better compression). May confuse some basic block detection algorithms.|
|**Minification**|B0034.002|Minification is 'the process of removing all unnecessary characters from source code without changing its functionality.' [[1]](#1) A simple example is when all the unnecessary whitespace and comments are removed. Minification is distinguished from compression in that it neither adds to nor changes the code seen by the interpreter. Minification is often used for malware written in interpreted languages, such as JavaScript, PHP, or Python. Legitimate code that is transmitted many times a second, such as JavaScript on websites, often uses minification to simply reduce the number of bytes transmitted.|
## References
<a name="1">[1]</a> https://en.wikipedia.org/wiki/Minification_(programming)
@@ -0,0 +1,57 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>B0008</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a>, <a href="../anti-static-analysis">Anti-Static Analysis</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>None</b></td>
</tr>
<tr>
<td><b>Anti-Analysis Type</b></td>
<td><b>Evasion</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.0</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>8 May 2023</b></td>
</tr>
</table>
# Executable Code Virtualization
Code virtualization obfuscates code to hinder static analysis and reverse engineering of the binary, allowing successful masking of the codes malicious behavior. Code virtualization selects specific parts of original executable code and transforms them “to bytecode in a new, custom virtual instruction set architecture (ISA)”[[1]](#1). As explained further in [[1]](#), “At execution time, the bytecode is emulated by an embedded virtual machine (or interpreter) on the real machine. The new ISA can be designed independently, and thus the bytecode and interpreter greatly differ from those in every protected instance. In this way, the programs original code never reappears.”
While malicious actors can create a custom VM-based obfuscator as observed in Wslink [[2]](#2), other options are available to them such as Themida, a commercial tool, and VMProtect, an open source tool.
## Methods
|Name|ID|Description|
|---|---|---|
|**Multiple VMs**|B0008.001|Multiple virtual machines with different architectures (CISC, RISC, etc.) can be used inside of a single executable in order to make reverse engineering even more difficult.|
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|--|Code virtualization is added to the Locky Bart binary using WPProtect. [[3]](#3)|
## References
<a name="1">[1]</a> D. Xu, J. Ming, Y. Fu, and D. Wu, "Verifiable Approach to Partially-Virtualized Binary Code Simplification," in 2018 ACM SIGSAC Conference on Computer and Communications Security (CCS 18),Toronto, ON, Canada, pp. 442-458, [Online]. Available: https://doi.org/10.1145/3243734.3243827.
<a name="2">[2]</a> V. Hrčka, "Under the hood of Wslinks multilayered virtual machine," welivesecurity.com, 28 March 2022. [Online]. Available: https://www.welivesecurity.com/2022/03/28/under-hood-wslink-multilayered-virtual-machine.
<a name="3">[3]</a> https://blog.malwarebytes.com/threat-analysis/2017/01/locky-bart-ransomware-and-backend-server-analysis/
+133 -26
View File
@@ -1,33 +1,140 @@
|||
|---------|------------------------|
|**ID**|**E1045**|
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis), [Anti-Static Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-static-analysis), [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion)|
|**Related ATT&CK Technique**|[Software Packing](https://attack.mitre.org/techniques/T1045/)|
<table>
<tr>
<td><b>ID</b></td>
<td><b>F0001</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a>, <a href="../anti-static-analysis">Anti-Static Analysis</a>, <a href="../defense-evasion">Defense Evasion</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>Obfuscated Files or Information: Software Packing (<a href="https://attack.mitre.org/techniques/T1027/002/">T1027.002</a>, <a href="https://attack.mitre.org/techniques/T1406/002/">T1406.002</a>)</b></td>
</tr>
<tr>
<td><b>Anti-Analysis Type</b></td>
<td><b>Evasion</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.3</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>27 April 2024</b></td>
</tr>
</table>
Software Packing
================
This code characteristic - Software Packing - can make static and behavioral analysis difficult and includes packing with software protectors, such as Themida and Armadillo [[1]](#1). Methods related to anti-analysis are below.
# Software Packing
This description refines the ATT&CK [**Software Packing**](https://attack.mitre.org/techniques/T1045/) technique.
This code characteristic - Software Packing - can make static and behavioral analysis difficult and includes packing with software protectors, such as Themida and Armadillo [[1]](#1). Methods related to anti-analysis are below. This behavior covers both characteristics of the malware (i.e., how it is packed) as well as behaviors of the malware (e.g., the malware packs another executable file).
Methods
-------
* **Nested Packing**: the malware is packed by one packer, the result is packed, etc.
* **Standard Compression**: Uses a standard algorithm, such as UPX or LZMA, to compress an executable file.
* **Standard Compression of Code**: Uses a standard algorithm to compress the opcode mnemonics.
* **Standard Compression of Data**: Uses a standard algorithm to compress strings and variables (executable file data).
* **Custom Compression**: Uses a custom algorithm to compress an executable file.
* **Custom Compression of Code**: Uses a custom algorithm to compress opcode mnemonics.
* **Custom Compression of Data**: Uses a custom algorithm to compress strings and variables (executable file data).
This description refines the ATT&CK **Obfuscated Files or Information: Software Packing ([T1027.002](https://attack.mitre.org/techniques/T1027/002/), [T1406.002](https://attack.mitre.org/techniques/T1406/002/))** techniques.
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
## Methods
|Name|ID|Description|
|---|---|---|
|**Armadillo**|F0001.012|Uses Armadillo.|
|**ASPack**|F0001.013|Uses ASPack. This method is related to Unprotect technique U1411.|
|**Confuser**|F0001.009|Uses Confuser packer.|
|**Custom Compression**|F0001.005|Uses a custom algorithm to compress an executable file.|
|**Custom Compression of Code**|F0001.006|Uses a custom algorithm to compress opcode mnemonics.|
|**Custom Compression of Data**|F0001.007|Uses a custom algorithm to compress strings and variables (executable file data).|
|**Nested Packing**|F0001.001|The malware is packed by one packer, the result is packed, etc.|
|**Standard Compression**|F0001.002|Uses a standard algorithm, such as UPX or LZMA, to compress an executable file.|
|**Standard Compression of Code**|F0001.003|Uses a standard algorithm to compress the opcode mnemonics.|
|**Standard Compression of Data**|F0001.004|Uses a standard algorithm to compress strings and variables (executable file data).|
|**Themida**|F0001.011|Uses Themida.This method is related to Unprotect technique U1406.|
|**UPX**|F0001.008|Uses UPX packer. This method is related to Unprotect technique U1402.|
|**VMProtect**|F0001.010|Uses VMProtect. This method is related to Unprotect technique U1410.|
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**Redhip**](../xample-malware/redhip.md)|2011|--|Redhip samples are packed with different custom packers. [[3]](#3)|
|[**Kovter**](../xample-malware/kovter.md)|2016|--|The malware comes packed by a crypter/FUD. [[4]](#4)|
|[**Conficker**](../xample-malware/conficker.md)|2008|F0001.008|Conficker is propagated as a DLL which has been backed using the UPX packer. [[5]](#5)|
|[**DarkComet**](../xample-malware/dark-comet.md)|2008|--|DarkComet has the option to compress its payload using UPX or MPRESS. [[6]](#6)|
|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|The malware has a custom packer to obfuscate itself. [[7]](#7)|
|[**Emotet**](../xample-malware/emotet.md)|2018|F0001.005|Emotet uses custom packers which first decrypt the loaders and the loaders decrypt and load Emotet's main payloads. [[8]](#8)|
|[**Snake**](../xample-malware/snake.md)|2004|--|Snake is distributed in a packed format. [[9]](#9)|
## Detection
|Tool: capa|Mapping|APIs|
|---|---|---|
|[packed with pebundle](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/packer/pebundle/packed-with-pebundle.yml)|Software Packing (F0001)|--|
|[packed with Themida](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/packer/themida/packed-with-themida.yml)|Software Packing::Themida (F0001.011)|--|
|[packed with VMProtect](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/packer/vmprotect/packed-with-vmprotect.yml)|Software Packing::VMProtect (F0001.010)|--|
|[packed with y0da crypter](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/packer/y0da/packed-with-y0da-crypter.yml)|Software Packing (F0001)|--|
|[packed with pelocknt](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/packer/pelocknt/packed-with-pelocknt.yml)|Software Packing (F0001)|--|
|[packed with GoPacker](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/packer/gopacker/packed-with-gopacker.yml)|Software Packing::Standard Compression (F0001.002)|--|
|[packed with Confuser](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/packer/confuser/packed-with-confuser.yml)|Software Packing::Confuser (F0001.009)|--|
|[packed with rlpack](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/packer/rlpack/packed-with-rlpack.yml)|Software Packing (F0001)|--|
|[packed with ASPack](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/packer/aspack/packed-with-aspack.yml)|Software Packing (F0001)|--|
|[packed with generic packer](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/packer/generic/packed-with-generic-packer.yml)|Software Packing::Standard Compression (F0001.002)|--|
|[packed with amber](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/packer/amber/packed-with-amber.yml)|Software Packing (F0001)|--|
|[packed with petite](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/packer/petite/packed-with-petite.yml)|Software Packing (F0001)|--|
|[packed with peshield](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/packer/peshield/packed-with-peshield.yml)|Software Packing (F0001)|--|
|[packed with UPX](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/packer/upx/packed-with-upx.yml)|Software Packing::UPX (F0001.008)|--|
|[packed with upack](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/packer/upack/packed-with-upack.yml)|Software Packing (F0001)|--|
|[packed with PECompact](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/packer/pecompact/packed-with-pecompact.yml)|Software Packing (F0001)|--|
|[packed with Huan](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/packer/huan/packed-with-huan.yml)|Software Packing (F0001)|--|
|[packed with nspack](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/packer/nspack/packed-with-nspack.yml)|Software Packing (F0001)|--|
|[packed with kkrunchy](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/packer/kkrunchy/packed-with-kkrunchy.yml)|Software Packing (F0001)|--|
|[packed with PESpin](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/packer/pespin/packed-with-pespin.yml)|Software Packing (F0001)|--|
|[packed with nmm-protect](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/packer/nmm-protect/packed-with-nmm-protect.yml)|Software Packing::VMProtect (F0001.010)|--|
|Tool: CAPE|Mapping|APIs|
|---|---|---|
|[packer_nspack](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_nspack.py)|Software Packing (F0001)|--|
|[packer_vmprotect](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_vmprotect.py)|Software Packing (F0001)|--|
|[packer_vmprotect](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_vmprotect.py)|Software Packing::VMProtect (F0001.010)|--|
|[packer_confuser](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_confuser.py)|Software Packing (F0001)|--|
|[packer_confuser](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_confuser.py)|Software Packing::Confuser (F0001.009)|--|
|[packer_smartassembly](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_smartassembly.py)|Software Packing (F0001)|--|
|[packer_mpress](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_mpress.py)|Software Packing (F0001)|--|
|[packer_enigma](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_enigma.py)|Software Packing (F0001)|--|
|[packer_aspirecrypt](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_aspirecrypt.py)|Software Packing (F0001)|--|
|[packer_nate](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_nate.py)|Software Packing (F0001)|--|
|[packer_entropy](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_entropy.py)|Software Packing (F0001)|--|
|[packer_unknown_pe_section_name](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_anomaly.py)|Software Packing (F0001)|--|
|[packer_upx](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_upx.py)|Software Packing (F0001)|--|
|[packer_upx](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_upx.py)|Software Packing::UPX (F0001.008)|--|
|[packer_aspack](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_aspack.py)|Software Packing (F0001)|--|
|[packer_aspack](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_aspack.py)|Software Packing::ASPack (F0001.013)|--|
|[packer_bedsprotector](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_bedsprotector.py)|Software Packing (F0001)|--|
|[packer_themida](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_themida.py)|Software Packing (F0001)|FindWindowA|
|[packer_themida](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_themida.py)|Software Packing::Themida (F0001.011)|FindWindowA|
|[packer_themida](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_themida.py)|Software Packing (F0001)|--|
|[packer_themida](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_themida.py)|Software Packing::Themida (F0001.011)|--|
|[packer_spices](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_spices.py)|Software Packing (F0001)|--|
|[packer_yoda](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_yoda.py)|Software Packing (F0001)|--|
|[packer_titan](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/packer_titan.py)|Software Packing (F0001)|--|
## References
References
----------
<a name="1">[1]</a> Ange Albertini, Packers, 5 April 2010, https://gironsec.com/code/packers.pdf
<a name="2">[2]</a> Jiang Ming et al, Towards Paving the Way for Large-Scale Windows Malware Analysis: Generic Binary Unpacking with Orders-of-Magnitude Performance Boost, October 2018, https://dl.acm.org/citation.cfm?id=3243771.
<a name="2">[2]</a> Jiang Ming et al, Towards Paving the Way for Large-Scale Windows Malware Analysis: Generic Binary Unpacking with Orders-of-Magnitude Performance Boost, October 2018, https://dl.acm.org/citation.cfm?id=3243771
<a name="3">[3]</a> https://web.archive.org/web/20200815134441/https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
<a name="4">[4]</a> https://blog.malwarebytes.com/threat-analysis/2016/07/untangling-kovter/
<a name="5">[5]</a> http://www.csl.sri.com/users/vinod/papers/Conficker/
<a name="6">[6]</a> https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/
<a name="7">[7]</a> https://www.securityartwork.es/wp-content/uploads/2017/07/Trickbot-report-S2-Grupo.pdf
<a name="8">[8]</a> https://documents.trendmicro.com/assets/white_papers/ExploringEmotetsActivities_Final.pdf
<a name="9">[9]</a> https://www.cybereason.com/blog/research/threat-analysis-report-snake-infostealer-malware
+466
View File
@@ -0,0 +1,466 @@
# capa Rule Distribution #
19 September 2023
## Histograms ##
The histograms below show the number of capa rules mapped into ATT&CK techniques (organized by tactic), MBC behaviors (organized by objective), and MBC micro-behaviors (organized by micro-objective). The count tracks ATT&CK techniques and sub-techniques and MBC behaviors and methods individually. For example, both B0009 and B0009.012 are counted under the Anti-Behavioral Analysis objective. The explicit techniques/sub-techiques, behaviors/methods, and micro-behaviors/micro-methods follow the histograms.
### ATT&CK Mapping Histogram ###
| **TACTIC** | **Number of Techniques** | |
|-----|-----|-----|
|Reconnaissance|0| |
|Resource Development|0| |
|Initial Access|0| |
|**Execution**|8| **XXXXXXXX** |
|**Persistence**|22| **XXXXXXXXXXXXXXXXXXXXXX** |
|**Privilege Escalation**|1| **X** |
|**Defense Evasion**|37| **XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX** |
|**Credential Access**|4| **XXXX** |
|**Discovery**|17| **XXXXXXXXXXXXXXXXX** |
|Lateral Movement|0| |
|**Collection**|7| **XXXXXXX** |
|**Command and Control**|1| **X** |
|Exfiltration|0| |
|**Impact**|5| **XXXXX** |
### MBC Mapping Histogram (Objectives) ###
| **OBJECTIVE** | **Number of Behaviors** | |
|-----|-----|-----|
|**Anti-Behavioral Analysis**|24| **XXXXXXXXXXXXXXXXXXXXXXXX** |
|**Anti-Static Analysis**|10| **XXXXXXXXXX** |
|**Collection**|5| **XXXXX** |
|**Command and Control**|3| **XXX** |
|Credential Access|0| |
|**Defense Evasion**|15| **XXXXXXXXXXXXXXX** |
|**Discovery**|8| **XXXXXXXX** |
|**Execution**|2| **XX** |
|Exfiltration|0| |
|**Impact**|6| **XXXXXX** |
|Lateral Movement|0| |
|**Persistence**|2| **XX** |
|Privilege Escalation|0| |
### MBC Mapping Histogram (Micro-Objectives) ###
| **MICRO-OBJECTIVE** | **Number of Micro-Behaviors** | |
|-----|-----|-----|
|**Communication**|38| **XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX** |
|**Cryptography**|27| **XXXXXXXXXXXXXXXXXXXXXXXXXXX** |
|**Data**|16| **XXXXXXXXXXXXXXXX** |
|**File System**|11| **XXXXXXXXXXX** |
|**Hardware**|4| **XXXX** |
|**Memory**|2| **XX** |
|**Operating System**|11| **XXXXXXXXXXX** |
|**Process**|14| **XXXXXXXXXXXXXX** |
## ATT&CK MAPPINGS ##
### Reconnaissance ###
num: 0
### Resource Development ###
num: 0
### Initial Access ###
num: 0
### Execution ###
num: 8
- Command and Scripting Interpreter [T1059] Count-3
- Windows Management Instrumentation [T1047] Count-1
- System Services::Service Execution [T1569.002] Count-1
- Shared Modules [T1129] Count-8
- Command and Scripting Interpreter::PowerShell [T1059.001] Count-1
- Command and Scripting Interpreter::Unix Shell [T1059.004] Count-2
- Command and Scripting Interpreter::Windows Command Shell [T1059.003] Count-2
- Command and Scripting Interpreter::Python [T1059.006] Count-2
### Persistence ###
num: 22
- Hijack Execution Flow [T1574] Count-1
- Create or Modify System Process::Windows Service [T1543.003] Count-9
- Pre-OS Boot::System Firmware [T1542.001] Count-2
- Boot or Logon Autostart Execution::Shortcut Modification [T1547.009] Count-1
- Server Software Component [T1505] Count-2
- Event Triggered Execution::Unix Shell Configuration Modification [T1546.004] Count-1
- Boot or Logon Autostart Execution::XDG Autostart Entries [T1547.013] Count-1
- Server Software Component::IIS Components [T1505.004] Count-2
- Office Application Startup::Add-ins [T1137.006] Count-3
- Modify Authentication Process::Network Provider DLL [T1556.008] Count-1
- Boot or Logon Autostart Execution::Security Support Provider [T1547.005] Count-1
- Boot or Logon Autostart Execution::Authentication Package [T1547.002] Count-1
- Modify Authentication Process::Password Filter DLL [T1556.002] Count-1
- Boot or Logon Initialization Scripts::RC Scripts [T1037.004] Count-1
- Server Software Component::Transport Agent [T1505.002] Count-1
- Scheduled Task/Job::Scheduled Task [T1053.005] Count-2
- Scheduled Task/Job::At [T1053.002] Count-1
- Boot or Logon Autostart Execution::Active Setup [T1547.014] Count-1
- Event Triggered Execution::AppInit DLLs [T1546.010] Count-2
- Event Triggered Execution [T1546] Count-1
- Boot or Logon Autostart Execution::Winlogon Helper DLL [T1547.004] Count-1
- Boot or Logon Autostart Execution::Registry Run Keys / Startup Folder [T1547.001] Count-3
### Privilege Escalation ###
num: 1
- Access Token Manipulation [T1134] Count-2
### Defense Evasion ###
num: 37
- Obfuscated Files or Information::Software Packing [T1027.002] Count-20
- Virtualization/Sandbox Evasion::System Checks [T1497.001] Count-16
- Impair Defenses::Indicator Blocking [T1562.006] Count-1
- Impair Defenses::Disable or Modify Tools [T1562.001] Count-3
- Virtualization/Sandbox Evasion::User Activity Based Checks [T1497.002] Count-2
- Virtualization/Sandbox Evasion [T1497] Count-1
- Debugger Evasion [T1622] Count-2
- Indicator Removal [T1070] Count-2
- Impair Defenses::Disable Windows Event Logging [T1562.002] Count-1
- Process Injection [T1055] Count-7
- Access Token Manipulation::Parent PID Spoofing [T1134.004] Count-1
- Indicator Removal::Clear Windows Event Logs [T1070.001] Count-1
- Indicator Removal::File Deletion [T1070.004] Count-1
- Indicator Removal::Timestomp [T1070.006] Count-1
- Obfuscated Files or Information [T1027] Count-44
- Obfuscated Files or Information::Indicator Removal from Tools [T1027.005] Count-1
- Deobfuscate/Decode Files or Information [T1140] Count-2
- Subvert Trust Controls::Mark-of-the-Web Bypass [T1553.005] Count-1
- Hide Artifacts::Hidden File System [T1564.005] Count-1
- File and Directory Permissions Modification [T1222] Count-1
- Hide Artifacts::Hidden Window [T1564.003] Count-1
- Hide Artifacts [T1564] Count-1
- Process Injection::Process Doppelgänging [T1055.013] Count-1
- Process Injection::Portable Executable Injection [T1055.002] Count-1
- Process Injection::Dynamic-link Library Injection [T1055.001] Count-2
- Process Injection::Thread Execution Hijacking [T1055.003] Count-2
- Process Injection::Extra Window Memory Injection [T1055.011] Count-1
- Process Injection::Asynchronous Procedure Call [T1055.004] Count-1
- Process Injection::Process Hollowing [T1055.012] Count-1
- Modify Registry [T1112] Count-4
- Impair Defenses::Safe Mode Boot [T1562.009] Count-1
- Subvert Trust Controls::Code Signing Policy Modification [T1553.006] Count-1
- Abuse Elevation Control Mechanism::Bypass User Account Control [T1548.002] Count-4
- Reflective Code Loading [T1620] Count-1
- Obfuscated Files or Information::Dynamic API Resolution [T1027.007] Count-1
- Hijack Execution Flow [T1574] Count-1
- BITS Jobs [T1197] Count-1
### Credential Access ###
num: 4
- Credentials from Password Stores::Windows Credential Manager [T1555.004] Count-1
- Credentials from Password Stores::Password Managers [T1555.005] Count-1
- Credentials from Password Stores [T1555] Count-48
- Credentials from Password Stores::Credentials from Web Browsers [T1555.003] Count-2
### Discovery ###
num: 17
- File and Directory Discovery [T1083] Count-10
- System Information Discovery [T1082] Count-16
- Process Discovery [T1057] Count-9
- System Location Discovery::System Language Discovery [T1614.001] Count-2
- System Service Discovery [T1007] Count-3
- Application Window Discovery [T1010] Count-2
- System Owner/User Discovery [T1033] Count-4
- Account Discovery [T1087] Count-2
- Query Registry [T1012] Count-3
- Software Discovery::Security Software Discovery [T1518.001] Count-1
- Software Discovery [T1518] Count-1
- System Network Configuration Discovery::Internet Connection Discovery [T1016.001] Count-1
- System Network Configuration Discovery [T1016] Count-8
- Network Sniffing [T1040] Count-1
- System Location Discovery [T1614] Count-1
- Group Policy Discovery [T1615] Count-1
- Domain Trust Discovery [T1482] Count-1
### Lateral Movement ###
num: 0
### Collection ###
num: 7
- Archive Collected Data::Archive via Library [T1560.002] Count-1
- Clipboard Data [T1115] Count-3
- Video Capture [T1125] Count-1
- Input Capture::Keylogging [T1056.001] Count-3
- Data from Information Repositories [T1213] Count-2
- Audio Capture [T1123] Count-1
- Screen Capture [T1113] Count-2
### Command and Control ###
num: 1
- Ingress Tool Transfer [T1105] Count-1
### Exfiltration ###
num: 0
### Impact ###
num: 5
- Endpoint Denial of Service [T1499] Count-1
- System Shutdown/Reboot [T1529] Count-1
- Data Manipulation::Transmitted Data Manipulation [T1565.002] Count-1
- Inhibit System Recovery [T1490] Count-1
- Disk Wipe::Disk Structure Wipe [T1561.002] Count-1
## MBC MAPPINGS ##
### Anti-Behavioral Analysis ###
num: 24
- Emulator Detection [B0004] Count-1
- Virtual Machine Detection [B0009] Count-14
- Sandbox Detection [B0007] Count-1
- Virtual Machine Detection::Human User Check [B0009.012] Count-2
- Virtual Machine Detection::Unique Hardware/Firmware Check [B0009.023] Count-1
- Sandbox Detection::Product Key/ID Testing [B0007.005] Count-1
- Debugger Evasion [B0002] Count-2
- Debugger Detection [B0001] Count-3
- Debugger Detection::Software Breakpoints [B0001.025] Count-1
- Debugger Detection::Process Environment Block BeingDebugged [B0001.035] Count-1
- Debugger Detection::Timing/Delay Check GetTickCount [B0001.032] Count-1
- Debugger Detection::SetHandleInformation [B0001.024] Count-1
- Debugger Detection::OutputDebugString [B0001.016] Count-1
- Debugger Detection::Memory Write Watching [B0001.010] Count-1
- Debugger Detection::Timing/Delay Check QueryPerformanceCounter [B0001.033] Count-1
- Debugger Detection::Hardware Breakpoints [B0001.005] Count-1
- Debugger Detection::NtQueryInformationProcess [B0001.012] Count-1
- Debugger Detection::CheckRemoteDebuggerPresent [B0001.002] Count-1
- Debugger Detection::WudfIsAnyDebuggerPresent [B0001.031] Count-1
- Debugger Detection::Process Environment Block NtGlobalFlag [B0001.036] Count-1
- Debugger Detection::Anti-debugging Instructions [B0001.034] Count-1
- Conditional Execution::Runs as Service [B0025.007] Count-1
- Debugger Detection::Process Environment Block [B0001.019] Count-1
- Dynamic Analysis Evasion::Delayed Execution [B0003.003] Count-1
### Anti-Static Analysis ###
num: 10
- Disassembler Evasion [B0012] Count-1
- Software Packing [F0001] Count-14
- Software Packing::Themida [F0001.011] Count-1
- Software Packing::VMProtect [F0001.010] Count-1
- Software Packing::Standard Compression [F0001.002] Count-2
- Software Packing::Confuser [F0001.009] Count-1
- Software Packing::UPX [F0001.008] Count-1
- Executable Code Obfuscation [B0032] Count-10
- Executable Code Obfuscation::Argument Obfuscation [B0032.020] Count-1
- Executable Code Obfuscation::Stack Strings [B0032.017] Count-1
### Collection ###
num: 5
- Input Capture [E1056] Count-1
- Keylogging::Polling [F0002.002] Count-1
- Keylogging::Application Hook [F0002.001] Count-1
- Screen Capture::WinAPI [E1113.m01] Count-1
- Screen Capture [E1113] Count-1
### Command and Control ###
num: 3
- C2 Communication::Send Data [B0030.001] Count-1
- C2 Communication::Receive Data [B0030.002] Count-1
- C2 Communication::Server to Client File Transfer [B0030.003] Count-1
### Credential Access ###
num: 0
### Defense Evasion ###
num: 15
- Disable or Evade Security Tools::Heavens Gate [F0004.008] Count-1
- Disable or Evade Security Tools [F0004] Count-1
- Disable or Evade Security Tools::Modify Policy [F0004.005] Count-2
- Process Injection::Patch Process Command Line [E1055.m04] Count-1
- Self Deletion::COMSPEC Environment Variable [F0007.001] Count-1
- Obfuscated Files or Information::Encryption [E1027.m04] Count-1
- Obfuscated Files or Information::Encryption-Standard Algorithm [E1027.m05] Count-21
- Obfuscated Files or Information::Encoding-Standard Algorithm [E1027.m02] Count-3
- Disable or Evade Security Tools::Bypass Windows File Protection [F0004.007] Count-1
- Process Injection [E1055] Count-4
- Disable or Evade Security Tools::Disable Code Integrity [F0004.009] Count-1
- Process Injection::Injection via Windows Fibers [E1055.m05] Count-1
- Hijack Execution Flow::Abuse Windows Function Calls [F0015.006] Count-1
- Hijack Execution Flow::Import Address Table Hooking [F0015.003] Count-1
- Obfuscated Files or Information [E1027] Count-1
### Discovery ###
num: 8
- Analysis Tool Discovery::Process detection [B0013.001] Count-1
- System Information Discovery [E1082] Count-5
- File and Directory Discovery [E1083] Count-7
- Application Window Discovery [E1010] Count-1
- Taskbar Discovery [B0043] Count-1
- File and Directory Discovery::Log File [E1083.m01] Count-2
- Code Discovery::Enumerate PE Sections [B0046.001] Count-1
- Code Discovery::Inspect Section Memory Permissions [B0046.002] Count-1
### Execution ###
num: 2
- Command and Scripting Interpreter [E1059] Count-2
- Install Additional Program [B0023] Count-2
### Exfiltration ###
num: 0
### Impact ###
num: 6
- Modify Hardware::Mouse [B0042.002] Count-1
- Modify Hardware::CDROM [B0042.001] Count-1
- Clipboard Modification [E1510] Count-1
- Remote Access::Reverse Shell [B0022.001] Count-2
- Data Destruction::Delete Shadow Copies [E1485.m04] Count-1
- Disk Wipe [F0014] Count-1
### Lateral Movement ###
num: 0
### Persistence ###
num: 2
- Hijack Execution Flow [F0015] Count-1
- Registry Run Keys / Startup Folder [F0012] Count-1
### Privilege Escalation ###
num: 0
## MBC MICRO-BEHAVIOR MAPPINGS ##
### Communication ###
num: 38
- Interprocess Communication [C0003] Count-2
- HTTP Communication::Read Header [C0002.014] Count-2
- HTTP Communication::WinHTTP [C0002.008] Count-1
- HTTP Communication::IWebBrowser [C0002.010] Count-2
- HTTP Communication [C0002] Count-2
- HTTP Communication::Set Header [C0002.013] Count-1
- HTTP Communication::Start Server [C0002.018] Count-1
- HTTP Communication::Receive Request [C0002.015] Count-1
- HTTP Communication::Send Response [C0002.016] Count-1
- HTTP Communication::Get Response [C0002.017] Count-5
- HTTP Communication::Send Request [C0002.003] Count-1
- HTTP Communication::Download URL [C0002.006] Count-1
- HTTP Communication::Create Request [C0002.012] Count-2
- HTTP Communication::Send Data [C0002.005] Count-1
- HTTP Communication::Open URL [C0002.004] Count-1
- HTTP Communication::Connect to Server [C0002.009] Count-1
- HTTP Communication::Extract Body [C0002.011] Count-1
- Socket Communication::Start TCP Server [C0001.005] Count-1
- Socket Communication::TCP Client [C0001.008] Count-1
- Interprocess Communication::Create Pipe [C0003.001] Count-2
- Interprocess Communication::Write Pipe [C0003.004] Count-1
- Interprocess Communication::Connect Pipe [C0003.002] Count-1
- Interprocess Communication::Read Pipe [C0003.003] Count-1
- FTP Communication::Send File [C0004.001] Count-1
- FTP Communication::WinINet [C0004.002] Count-1
- DNS Communication::Server Connect [C0011.002] Count-1
- DNS Communication::Resolve [C0011.001] Count-1
- Socket Communication::Get Socket Status [C0001.012] Count-1
- Socket Communication::Create Socket [C0001.003] Count-2
- Socket Communication::Set Socket Config [C0001.001] Count-1
- Socket Communication::Initialize Winsock Library [C0001.009] Count-1
- Socket Communication::Connect Socket [C0001.004] Count-1
- Socket Communication::Create TCP Socket [C0001.011] Count-2
- Socket Communication::Send TCP Data [C0001.014] Count-2
- Socket Communication::Create UDP Socket [C0001.010] Count-1
- Socket Communication::Send Data [C0001.007] Count-1
- Socket Communication::Receive Data [C0001.006] Count-1
- ICMP Communication::Echo Request [C0014.002] Count-1
### Cryptography ###
num: 27
- Encryption Key::Import Public Key [C0028.001] Count-1
- Decrypt Data [C0031] Count-1
- Encrypt Data [C0027] Count-4
- Encryption Key [C0028] Count-2
- Encrypt Data::HC-128 [C0027.006] Count-2
- Encrypt Data::RC6 [C0027.010] Count-1
- Encrypt Data::Twofish [C0027.005] Count-1
- Encrypt Data::AES [C0027.001] Count-4
- Decrypt Data::AES [C0031.001] Count-1
- Encrypt Data::Sosemanuk [C0027.008] Count-1
- Encrypt Data::Camellia [C0027.003] Count-1
- Encrypt Data::3DES [C0027.004] Count-2
- Encrypt Data::RC4 [C0027.009] Count-4
- Generate Pseudo-random Sequence::RC4 PRGA [C0021.004] Count-1
- Encryption Key::RC4 KSA [C0028.002] Count-1
- Encrypt Data::Skipjack [C0027.013] Count-1
- Encrypt Data::Blowfish [C0027.002] Count-1
- Cryptographic Hash [C0029] Count-2
- Cryptographic Hash::Tiger [C0029.005] Count-1
- Cryptographic Hash::SHA1 [C0029.002] Count-1
- Cryptographic Hash::SHA256 [C0029.003] Count-1
- Cryptographic Hash::MD5 [C0029.001] Count-1
- Cryptographic Hash::SHA224 [C0029.004] Count-1
- Hashed Message Authentication Code [C0061] Count-1
- Generate Pseudo-random Sequence::Use API [C0021.003] Count-2
- Generate Pseudo-random Sequence [C0021] Count-1
- Crypto Library [C0059] Count-5
### Data ###
num: 16
- Checksum::Luhn [C0032.002] Count-3
- Checksum::Adler [C0032.005] Count-1
- Checksum::CRC32 [C0032.001] Count-1
- Non-Cryptographic Hash::MurmurHash [C0030.001] Count-1
- Non-Cryptographic Hash::FNV [C0030.005] Count-1
- Non-Cryptographic Hash::djb2 [C0030.006] Count-1
- Encode Data::XOR [C0026.002] Count-1
- Encode Data::Base64 [C0026.001] Count-3
- Check String [C0019] Count-2
- Decompress Data::aPLib [C0025.003] Count-1
- Decompress Data::IEncodingFilterFactory [C0025.002] Count-1
- Compress Data [C0024] Count-3
- Decompress Data [C0025] Count-2
- Decompress Data::QuickLZ [C0025.001] Count-1
- Modulo [C0058] Count-1
- Compression Library [C0060] Count-2
### File System ###
num: 11
- Set File Attributes [C0050] Count-2
- Create Directory [C0046] Count-1
- Delete File [C0047] Count-1
- Delete Directory [C0048] Count-1
- Get File Attributes [C0049] Count-1
- Move File [C0063] Count-1
- Writes File [C0052] Count-3
- Copy File [C0045] Count-1
- Read File [C0051] Count-4
- Read Virtual Disk [C0056] Count-1
- Create File [C0016] Count-1
### Hardware ###
num: 4
- Simulate Hardware::Ctrl-Alt-Del [C0057.001] Count-1
- Install Driver [C0037] Count-1
- Install Driver::Minifilter [C0037.001] Count-1
- Load Driver::Minifilter [C0023.001] Count-1
### Memory ###
num: 2
- Free Memory [C0044] Count-1
- Allocate Memory [C0007] Count-4
### Operating System ###
num: 11
- Environment Variable::Set Variable [C0034.001] Count-1
- Environment Variable [C0034] Count-1
- Wallpaper [C0035] Count-1
- Console [C0033] Count-2
- Registry::Set Registry Key [C0036.001] Count-2
- Registry::Open Registry Key [C0036.003] Count-2
- Registry::Query Registry Key [C0036.005] Count-1
- Registry::Query Registry Value [C0036.006] Count-2
- Registry::Create Registry Key [C0036.004] Count-2
- Registry::Delete Registry Key [C0036.002] Count-1
- Registry::Delete Registry Value [C0036.007] Count-1
### Process ###
num: 14
- Create Thread [C0038] Count-2
- Suspend Thread [C0055] Count-1
- Terminate Thread [C0039] Count-1
- Resume Thread [C0054] Count-1
- Enumerate Threads [C0064] Count-1
- Create Mutex [C0042] Count-2
- Check Mutex [C0043] Count-2
- Terminate Process [C0018] Count-3
- Allocate Thread Local Storage [C0040] Count-1
- Set Thread Local Storage Value [C0041] Count-1
- Create Process [C0017] Count-4
- Create Process::Create Suspended Process [C0017.003] Count-1
- Open Process [C0065] Count-1
- Open Thread [C0066] Count-1
+601
View File
@@ -0,0 +1,601 @@
# CAPE Rule Distribution #
February 2023
## Histograms ##
The histograms below show the number of CAPE rules mapped to ATT&CK techniques (organized by tactic), MBC behaviors (organized by objective), and MBC micro-behaviors (organized by micro-objective). The explicit techniques, behaviors, and micro-behaviors follow.
The data below reflects [community repository signatures](https://github.com/kevoreilly/community/tree/master/modules/signatures) (not including deprecated signatures), as well as [CAPEv2 signatures](https://github.com/kevoreilly/CAPEv2/blob/master/modules/signatures/CAPE.py).
Information on CAPE signatures can be found [here](https://github.com/kevoreilly/CAPEv2/blob/master/docs/book/src/customization/signatures.rst).
### ATT&CK Mapping Histogram ###
| **TACTIC** | **Number of Techniques** | |
|-----|-----|-----|
|**Reconnaissance**|5| **XXXXX** |
|**Resource Development**|2| **XX** |
|**Initial Access**|4| **XXXX** |
|**Execution**|18| **XXXXXXXXXXXXXXXXXX** |
|**Persistence**|34| **XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX** |
|**Privilege Escalation**|27| **XXXXXXXXXXXXXXXXXXXXXXXXXXX** |
|**Defense Evasion**|70| **XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX** |
|**Credential Access**|15| **XXXXXXXXXXXXXXX** |
|**Discovery**|19| **XXXXXXXXXXXXXXXXXXX** |
|**Lateral Movement**|3| **XXX** |
|**Collection**|10| **XXXXXXXXXX** |
|**Command And Control**|18| **XXXXXXXXXXXXXXXXXX** |
|**Exfiltration**|4| **XXXX** |
|**Impact**|11| **XXXXXXXXXXX** |
### MBC Mapping Histogram ###
| **OBJECTIVE** | **Number of Behaviors** | |
|-----|-----|-----|
|**Anti-behavioral Analysis**|36| **XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX** |
|**Anti-static Analysis**|7| **XXXXXXX** |
|**Collection**|6| **XXXXXX** |
|**Command And Control**|4| **XXXX** |
|**Credential Access**|6| **XXXXXX** |
|**Defense Evasion**|22| **XXXXXXXXXXXXXXXXXXXXXX** |
|**Discovery**|7| **XXXXXXX** |
|**Execution**|3| **XXX** |
|**Exfiltration**|1| **X** |
|**Impact**|9| **XXXXXXXXX** |
|**Lateral Movement**|1| **X** |
|**Persistence**|11| **XXXXXXXXXXX** |
|**Privilege Escalation**|4| **XXXX** |
### MBC Mapping Histogram ###
| **MICRO-OBJECTIVE** | **Number of Micro-Behaviors** | |
|-----|-----|-----|
|**Communication**|13| **XXXXXXXXXXXXX** |
|**Cryptography**|3| **XXX** |
|**Data**|1| **X** |
|**File System**|9| **XXXXXXXXX** |
|**Hardware**|1| **X** |
|**Memory**|3| **XXX** |
|**Process**|5| **XXXXX** |
|**Operating System**|7| **XXXXXXX** |
### Objective-only Mapping Counts ###
This histogram indicates the number of CAPE signatures that map to an MBC objective.
| **OBJECTIVE** | **Number of CAPE signatures** | |
|-----|-----|-----|
|**Anti-behavioral Analysis**|84| **XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX** |
|**Anti-static Analysis**|23| **XXXXXXXXXXXXXXXXXXXXXXX** |
|**Collection**|10| **XXXXXXXXXX** |
|**Command And Control**|15| **XXXXXXXXXXXXXXX** |
|**Credential Access**|16| **XXXXXXXXXXXXXXXX** |
|**Defense Evasion**|98| **XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX** |
|**Discovery**|68| **XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX** |
|**Execution**|72| **XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX** |
|**Exfiltration**|3| **XXX** |
|**Impact**|22| **XXXXXXXXXXXXXXXXXXXXXX** |
|Lateral Movement|0| |
|**Persistence**|22| **XXXXXXXXXXXXXXXXXXXXXX** |
|**Privilege Escalation**|4| **XXXX** |
This histogram indicates the number of CAPE signatures that map to an MBC micro-objective.
| **MICRO-OBJECTIVE** | **Number of CAPE signatures** | |
|-----|-----|-----|
|**Communication**|45| **XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX** |
|**Cryptography**|12| **XXXXXXXXXXXX** |
|**Data**|1| **X** |
|**File System**|51| **XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX** |
|**Hardware**|1| **X** |
|**Memory**|3| **XXX** |
|**Process**|72| **XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX** |
|**Operating System**|94| **XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX** |
## ATT&CK MAPPINGS ##
### Reconnaissance ###
num: 5
- Gather Victim Host Information [T1592] Count-2
- Client Configurations [T1592.004] Count-2
- Gather Victim Identity Information [T1589] Count-1
- Credentials [T1589.001] Count-1
- Software [T1592.002] Count-1
### Resource Development ###
num: 2
- Develop Capabilities [T1587] Count-1
- Digital Certificates [T1587.003] Count-1
### Initial Access ###
num: 4
- Replication Through Removable Media [T1091] Count-1
- Spearphishing Link [T1192] Count-1
- Phishing [T1566] Count-1
- Spearphishing Link [T1566.002] Count-1
### Execution ###
num: 18
- Exploitation for Client Execution [T1203] Count-19
- Command and Scripting Interpreter [T1059] Count-52
- Native API [T1106] Count-13
- Scripting [T1064] Count-20
- JavaScript [T1059.007] Count-5
- PowerShell [T1086] Count-12
- Regsvr32 [T1117] Count-4
- PowerShell [T1059.001] Count-14
- Visual Basic [T1059.005] Count-5
- Windows Command Shell [T1059.003] Count-2
- InstallUtil [T1118] Count-2
- User Execution [T1204] Count-6
- Scheduled Task/Job [T1053] Count-2
- Scheduled Task [T1053.005] Count-2
- At [T1053.002] Count-1
- Windows Management Instrumentation [T1047] Count-5
- Malicious File [T1204.002] Count-4
- Shared Modules [T1129] Count-2
### Persistence ###
num: 34
- Office Application Startup [T1137] Count-20
- Browser Extensions [T1176] Count-2
- Modify Existing Service [T1031] Count-6
- New Service [T1050] Count-5
- Create or Modify System Process [T1543] Count-6
- Windows Service [T1543.003] Count-6
- Bootkit [T1067] Count-6
- Pre-OS Boot [T1542] Count-5
- Bootkit [T1542.003] Count-5
- Office Template Macros [T1137.001] Count-6
- Hidden Files and Directories [T1158] Count-3
- Image File Execution Options Injection [T1183] Count-2
- Event Triggered Execution [T1546] Count-4
- Image File Execution Options Injection [T1546.012] Count-2
- Server Software Component [T1505] Count-3
- Web Shell [T1505.003] Count-3
- Registry Run Keys / Startup Folder [T1060] Count-4
- Boot or Logon Autostart Execution [T1547] Count-5
- Registry Run Keys / Startup Folder [T1547.001] Count-4
- Scheduled Task/Job [T1053] Count-2
- Scheduled Task [T1053.005] Count-2
- At [T1053.002] Count-1
- Accessibility Features [T1015] Count-1
- Accessibility Features [T1546.008] Count-1
- Hijack Execution Flow [T1574] Count-2
- Kernel Modules and Extensions [T1215] Count-1
- Kernel Modules and Extensions [T1547.006] Count-1
- DLL Side-Loading [T1574.002] Count-1
- Add-ins [T1137.006] Count-1
- Create Account [T1136] Count-2
- Local Account [T1136.001] Count-2
- Account Manipulation [T1098] Count-1
- Application Shimming [T1138] Count-1
- Application Shimming [T1546.011] Count-1
### Privilege Escalation ###
num: 27
- Process Injection [T1055] Count-20
- New Service [T1050] Count-5
- Create or Modify System Process [T1543] Count-6
- Windows Service [T1543.003] Count-6
- Extra Window Memory Injection [T1055.011] Count-2
- Image File Execution Options Injection [T1183] Count-2
- Event Triggered Execution [T1546] Count-4
- Image File Execution Options Injection [T1546.012] Count-2
- Boot or Logon Autostart Execution [T1547] Count-5
- Registry Run Keys / Startup Folder [T1547.001] Count-4
- Scheduled Task/Job [T1053] Count-2
- Scheduled Task [T1053.005] Count-2
- At [T1053.002] Count-1
- Accessibility Features [T1015] Count-1
- Accessibility Features [T1546.008] Count-1
- Hijack Execution Flow [T1574] Count-2
- Kernel Modules and Extensions [T1547.006] Count-1
- Bypass User Account Control [T1088] Count-5
- Abuse Elevation Control Mechanism [T1548] Count-6
- Bypass User Account Control [T1548.002] Count-5
- DLL Side-Loading [T1574.002] Count-1
- Application Shimming [T1138] Count-1
- Application Shimming [T1546.011] Count-1
- Portable Executable Injection [T1055.002] Count-1
- Process Hollowing [T1055.012] Count-2
- Extra Window Memory Injection [T1181] Count-1
- Process Doppelgänging [T1055.013] Count-1
### Defense Evasion ###
num: 70
- Virtualization/Sandbox Evasion [T1497] Count-39
- Time Based Evasion [T1497.003] Count-4
- Modify Registry [T1112] Count-75
- Masquerading [T1036] Count-11
- Masquerade Task or Service [T1036.004] Count-1
- Match Legitimate Name or Location [T1036.005] Count-3
- Disabling Security Tools [T1089] Count-22
- Impair Defenses [T1562] Count-30
- Disable or Modify Tools [T1562.001] Count-17
- Hidden Window [T1143] Count-1
- Hide Artifacts [T1564] Count-6
- Hidden Window [T1564.003] Count-1
- System Checks [T1497.001] Count-12
- Scripting [T1064] Count-20
- Software Packing [T1045] Count-21
- Obfuscated Files or Information [T1027] Count-30
- Software Packing [T1027.002] Count-22
- Indicator Blocking [T1054] Count-7
- Impair Command History Logging [T1562.003] Count-1
- Indicator Blocking [T1562.006] Count-7
- Regsvr32 [T1117] Count-4
- System Binary Proxy Execution [T1218] Count-8
- Regsvr32 [T1218.010] Count-4
- Rootkit [T1014] Count-4
- Process Injection [T1055] Count-20
- Disable or Modify System Firewall [T1562.004] Count-3
- Timestomp [T1099] Count-4
- Indicator Removal [T1070] Count-11
- Timestomp [T1070.006] Count-4
- Pre-OS Boot [T1542] Count-5
- Bootkit [T1542.003] Count-5
- Extra Window Memory Injection [T1055.011] Count-2
- Code Signing [T1116] Count-2
- Subvert Trust Controls [T1553] Count-5
- Code Signing [T1553.002] Count-3
- Invalid Code Signature [T1036.001] Count-2
- Hidden Files and Directories [T1158] Count-3
- Hidden Files and Directories [T1564.001] Count-3
- InstallUtil [T1118] Count-2
- Trusted Developer Utilities Proxy Execution [T1127] Count-3
- InstallUtil [T1218.004] Count-2
- Image File Execution Options Injection [T1183] Count-2
- Clear Windows Event Logs [T1070.001] Count-1
- NTFS File Attributes [T1096] Count-3
- NTFS File Attributes [T1564.004] Count-2
- Indirect Command Execution [T1202] Count-4
- Rename System Utilities [T1036.003] Count-1
- Install Root Certificate [T1130] Count-1
- Deobfuscate/Decode Files or Information [T1140] Count-4
- Install Root Certificate [T1553.004] Count-2
- Compile After Delivery [T1500] Count-3
- Compile After Delivery [T1027.004] Count-3
- File Deletion [T1107] Count-2
- File Deletion [T1070.004] Count-2
- User Activity Based Checks [T1497.002] Count-1
- Hijack Execution Flow [T1574] Count-2
- Bypass User Account Control [T1088] Count-5
- Abuse Elevation Control Mechanism [T1548] Count-6
- Bypass User Account Control [T1548.002] Count-5
- DLL Side-Loading [T1073] Count-1
- DLL Side-Loading [T1574.002] Count-1
- Disable Windows Event Logging [T1562.002] Count-1
- CMSTP [T1218.003] Count-1
- Template Injection [T1221] Count-1
- Portable Executable Injection [T1055.002] Count-1
- Process Hollowing [T1093] Count-2
- Process Hollowing [T1055.012] Count-2
- Extra Window Memory Injection [T1181] Count-1
- Process Doppelgänging [T1186] Count-1
- Process Doppelgänging [T1055.013] Count-1
### Credential Access ###
num: 15
- Credentials in Files [T1081] Count-7
- OS Credential Dumping [T1003] Count-18
- Unsecured Credentials [T1552] Count-8
- Credentials In Files [T1552.001] Count-7
- Input Capture [T1056] Count-3
- Keylogging [T1056.001] Count-2
- Credentials from Password Stores [T1555] Count-6
- Credentials from Web Browsers [T1503] Count-5
- Credentials from Web Browsers [T1555.003] Count-5
- Group Policy Preferences [T1552.006] Count-1
- Steal Web Session Cookie [T1539] Count-1
- LSASS Memory [T1003.001] Count-1
- Security Account Manager [T1003.002] Count-4
- LSA Secrets [T1003.004] Count-1
- Network Sniffing [T1040] Count-1
### Discovery ###
num: 19
- Process Discovery [T1057] Count-35
- File and Directory Discovery [T1083] Count-31
- Virtualization/Sandbox Evasion [T1497] Count-39
- Time Based Evasion [T1497.003] Count-4
- System Information Discovery [T1082] Count-24
- System Checks [T1497.001] Count-12
- Security Software Discovery [T1063] Count-18
- Software Discovery [T1518] Count-21
- Security Software Discovery [T1518.001] Count-18
- Application Window Discovery [T1010] Count-3
- Permission Groups Discovery [T1069] Count-2
- Query Registry [T1012] Count-21
- System Owner/User Discovery [T1033] Count-3
- System Network Configuration Discovery [T1016] Count-4
- Domain Trust Discovery [T1482] Count-2
- Account Discovery [T1087] Count-3
- User Activity Based Checks [T1497.002] Count-1
- System Service Discovery [T1007] Count-1
- Network Sniffing [T1040] Count-1
### Lateral Movement ###
num: 3
- Remote Services [T1021] Count-4
- Remote Desktop Protocol [T1021.001] Count-3
- Replication Through Removable Media [T1091] Count-1
### Collection ###
num: 10
- Data from Local System [T1005] Count-7
- Email Collection [T1114] Count-2
- Input Capture [T1056] Count-3
- Keylogging [T1056.001] Count-2
- Data Staged [T1074] Count-1
- Screen Capture [T1113] Count-2
- Clipboard Data [T1115] Count-3
- Archive Collected Data [T1560] Count-4
- Browser Session Hijacking [T1185] Count-3
- Automated Collection [T1119] Count-1
### Command And Control ###
num: 18
- Application Layer Protocol [T1071] Count-35
- Remote Access Software [T1219] Count-39
- Proxy [T1090] Count-5
- Web Protocols [T1071.001] Count-19
- Multi-hop Proxy [T1188] Count-3
- Multi-hop Proxy [T1090.003] Count-3
- Standard Cryptographic Protocol [T1032] Count-15
- Encrypted Channel [T1573] Count-14
- File Transfer Protocols [T1071.002] Count-1
- Non-Application Layer Protocol [T1095] Count-4
- Custom Command and Control Protocol [T1094] Count-2
- DNS [T1071.004] Count-7
- Ingress Tool Transfer [T1105] Count-2
- Data Encoding [T1132] Count-1
- Standard Encoding [T1132.001] Count-1
- Domain Generation Algorithms [T1483] Count-2
- Dynamic Resolution [T1568] Count-3
- Domain Generation Algorithms [T1568.002] Count-2
### Exfiltration ###
num: 4
- Exfiltration Over C2 Channel [T1041] Count-2
- Automated Exfiltration [T1020] Count-1
- Data Encrypted [T1022] Count-4
- Exfiltration Over Alternative Protocol [T1048] Count-2
### Impact ###
num: 11
- Data Encrypted for Impact [T1486] Count-22
- Endpoint Denial of Service [T1499] Count-3
- Application or System Exploitation [T1499.004] Count-3
- Service Stop [T1489] Count-1
- Defacement [T1491] Count-1
- Internal Defacement [T1491.001] Count-1
- System Shutdown/Reboot [T1529] Count-1
- Inhibit System Recovery [T1490] Count-8
- Data Destruction [T1485] Count-4
- Disk Wipe [T1561] Count-1
- Resource Hijacking [T1496] Count-2
## MBC MAPPINGS ##
### Anti-behavioral Analysis ###
num: 36
- Sandbox Detection [B0007] Count-10
- Sandbox Detection [B0007.002] Count-5
- Dynamic Analysis Evasion [B0003] Count-5
- Dynamic Analysis Evasion [B0003.002] Count-1
- Dynamic Analysis Evasion [B0003.003] Count-1
- Virtual Machine Detection [B0009] Count-29
- Virtual Machine Detection [B0009.015] Count-1
- Software Packing [F0001] Count-19
- Software Packing [F0001.010] Count-1
- Virtual Machine Detection [B0009.001] Count-6
- Debugger Detection [B0001] Count-9
- Debugger Detection [B0001.002] Count-1
- Debugger Detection [B0001.012] Count-1
- Debugger Detection [B0001.001] Count-1
- Software Packing [F0001.009] Count-1
- Dynamic Analysis Evasion [B0003.010] Count-1
- Emulator Detection [B0004] Count-4
- Virtual Machine Detection [B0009.005] Count-13
- Virtual Machine Detection [B0009.024] Count-2
- Debugger Detection [B0001.030] Count-1
- Virtual Machine Detection [B0009.008] Count-3
- Debugger Detection [B0001.016] Count-1
- Sandbox Detection [B0007.003] Count-1
- Virtual Machine Detection [B0009.012] Count-1
- Debugger Detection [B0001.032] Count-1
- Emulator Detection [B0004.003] Count-2
- Software Packing [F0001.008] Count-1
- Debugger Detection [B0001.009] Count-1
- Debugger Evasion [B0002] Count-3
- Debugger Evasion [B0002.008] Count-1
- Software Packing [F0001.013] Count-1
- Virtual Machine Detection [B0009.006] Count-1
- Software Packing [F0001.011] Count-2
- Debugger Evasion [B0002.024] Count-1
- Debugger Detection [B0001.014] Count-1
- Virtual Machine Detection [B0009.009] Count-1
### Anti-static Analysis ###
num: 7
- Software Packing [F0001] Count-19
- Software Packing [F0001.010] Count-1
- Software Packing [F0001.009] Count-1
- Obfuscated Files or Information [E1027] Count-6
- Software Packing [F0001.008] Count-1
- Software Packing [F0001.013] Count-1
- Software Packing [F0001.011] Count-2
### Collection ###
num: 6
- Keylogging [F0002] Count-2
- Keylogging [F0002.001] Count-1
- Screen Capture [E1113] Count-2
- Cryptocurrency [B0028] Count-1
- Cryptocurrency [B0028.001] Count-1
- Input Capture [E1056] Count-3
### Command And Control ###
num: 4
- C2 Communication [B0030] Count-14
- C2 Communication [B0030.005] Count-1
- Ingress Tool Transfer [E1105] Count-1
- Domain Name Generation [B0031] Count-2
### Credential Access ###
num: 6
- Keylogging [F0002] Count-2
- Keylogging [F0002.001] Count-1
- Screen Capture [E1113] Count-2
- Cryptocurrency [B0028] Count-1
- Cryptocurrency [B0028.001] Count-1
- Input Capture [E1056] Count-3
### Defense Evasion ###
num: 22
- Modify Registry [E1112] Count-71
- Disable or Evade Security Tools [F0004] Count-23
- Hidden Files and Directories [F0005] Count-7
- Hidden Files and Directories [F0005.002] Count-1
- Indicator Blocking [F0006] Count-7
- Software Packing [F0001] Count-19
- Software Packing [F0001.010] Count-1
- Rootkit [E1014] Count-4
- Process Injection [E1055] Count-23
- Software Packing [F0001.009] Count-1
- Hidden Files and Directories [F0005.004] Count-3
- Bypass Data Execution Prevention [B0037] Count-1
- Bootkit [F0013] Count-5
- Obfuscated Files or Information [E1027] Count-6
- Disable or Evade Security Tools [F0004.005] Count-3
- Polymorphic Code [B0029] Count-1
- Self Deletion [F0007] Count-2
- Disable or Evade Security Tools [F0004.007] Count-1
- Software Packing [F0001.008] Count-1
- Disable or Evade Security Tools [F0004.003] Count-1
- Software Packing [F0001.013] Count-1
- Software Packing [F0001.011] Count-2
### Discovery ###
num: 7
- File and Directory Discovery [E1083] Count-17
- System Information Discovery [E1082] Count-24
- Application Window Discovery [E1010] Count-1
- Analysis Tool Discovery [B0013] Count-5
- Analysis Tool Discovery [B0013.001] Count-1
- Analysis Tool Discovery [B0013.009] Count-1
- Analysis Tool Discovery [B0013.008] Count-1
### Execution ###
num: 3
- Exploitation for Client Execution [E1203] Count-26
- Command and Scripting Interpreter [E1059] Count-47
- Install Additional Program [B0023] Count-5
### Exfiltration ###
num: 1
- Archive Collected Data [E1560] Count-6
### Impact ###
num: 9
- Exploitation for Client Execution [E1203] Count-26
- Data Encrypted for Impact [E1486] Count-8
- Remote Access [B0022] Count-43
- Denial of Service [B0033] Count-4
- Disk Wipe [F0014] Count-2
- Disk Wipe [F0014.001] Count-1
- Data Destruction [E1485] Count-4
- Resource Hijacking [B0018] Count-2
- Resource Hijacking [B0018.002] Count-1
### Lateral Movement ###
num: 1
- Ingress Tool Transfer [E1105] Count-1
### Persistence ###
num: 11
- Remote Access [B0022] Count-43
- Modify Registry [E1112] Count-71
- Hidden Files and Directories [F0005] Count-7
- Hidden Files and Directories [F0005.002] Count-1
- Kernel Modules and Extensions [F0010] Count-2
- Kernel Modules and Extensions [F0010.001] Count-1
- Modify Existing Service [F0011] Count-6
- Hidden Files and Directories [F0005.004] Count-3
- Bootkit [F0013] Count-5
- Registry Run Keys / Startup Folder [F0012] Count-3
- Ingress Tool Transfer [E1105] Count-1
### Privilege Escalation ###
num: 4
- Process Injection [E1055] Count-23
- Kernel Modules and Extensions [F0010] Count-2
- Kernel Modules and Extensions [F0010.001] Count-1
- Modify Existing Service [F0011] Count-6
## MBC MICRO-BEHAVIOR MAPPINGS ##
### Communication ###
num: 13
- HTTP Communication [C0002] Count-23
- HTTP Communication [C0002.003] Count-1
- HTTP Communication [C0002.005] Count-3
- WinINet [C0005] Count-5
- WinINet [C0005.002] Count-1
- WinINet [C0005.003] Count-1
- SMTP Communication [C0012] Count-1
- Socket Communication [C0001] Count-6
- WinINet [C0005.001] Count-1
- DNS Communication [C0011] Count-8
- ICMP Communication [C0014] Count-2
- Interprocess Communication [C0003] Count-1
- Interprocess Communication [C0003.001] Count-1
### Cryptography ###
num: 3
- Encrypt Data [C0027] Count-10
- Encryption Key [C0028] Count-1
- Decrypt Data [C0031] Count-1
### Data ###
num: 1
- Decompress Data [C0025] Count-1
### File System ###
num: 9
- Create File [C0016] Count-24
- Writes File [C0052] Count-8
- Create Directory [C0046] Count-1
- Alter File Extension [C0015] Count-4
- Delete File [C0047] Count-7
- Read File [C0051] Count-6
- Create File [C0016.002] Count-1
- Copy File [C0045] Count-1
- Create File [C0016.001] Count-1
### Hardware ###
num: 1
- Load Driver [C0023] Count-1
### Memory ###
num: 3
- Change Memory Protection [C0008] Count-1
- Heap Spray [C0006] Count-1
- Allocate Memory [C0007] Count-1
### Process ###
num: 5
- Create Mutex [C0042] Count-59
- Check Mutex [C0043] Count-4
- Create Process [C0017] Count-3
- Create Process [C0017.002] Count-1
- Create Thread [C0038] Count-4
### Operating System ###
num: 7
- Registry [C0036] Count-89
- Registry [C0036.001] Count-9
- Wallpaper [C0035] Count-1
- Console [C0033] Count-1
- Registry [C0036.005] Count-16
- Registry [C0036.003] Count-3
- Registry [C0036.006] Count-1
+23 -22
View File
@@ -1,24 +1,25 @@
|||
|--|-----|
|**ID**|**M9003**|
<table>
<tr>
<td><b>ID</b></td>
<td><b>OB0003</b></td>
</tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>18 December 2023</b></td>
</tr>
</table>
# Collection #
Behaviors that identify and gather information, such as sensitive files, from a target network prior to exfiltration. This objective includes locations on a system or network where the malware may look for information to exfiltrate.
* **Access Call Log** [T1433](https://github.com/MBCProject/mbc-markdown/blob/master/collection/access-call-log.md)
* **Access Sensitive Data or Credentials in Files** [E1409](https://github.com/MBCProject/mbc-markdown/blob/master/collection/access-sensitive-data.md)
* **Audio Capture** [T1123](https://github.com/MBCProject/mbc-markdown/blob/master/collection/audio-capture.md)
* **Automated Collection** [T1119](https://github.com/MBCProject/mbc-markdown/blob/master/collection/auto-collect.md)
* **Capture SMS Message** [T1412](https://github.com/MBCProject/mbc-markdown/blob/master/collection/capture-sms.md)
* **Clipboard Data** [T1115](https://github.com/MBCProject/mbc-markdown/blob/master/collection/clipboard-data.md)
* **Data from Local System** [T1005](https://github.com/MBCProject/mbc-markdown/blob/master/collection/data-local-system.md)
* **Data from Network Shared Drive** [T1039](https://github.com/MBCProject/mbc-markdown/blob/master/collection/data-network-share.md)
* **Data from Removable Media** [T1025](https://github.com/MBCProject/mbc-markdown/blob/master/collection/data-removable-media.md)
* **Data Staged** [T1074](https://github.com/MBCProject/mbc-markdown/blob/master/collection/data-staged.md)
* **Email Collection** [T1114](https://github.com/MBCProject/mbc-markdown/blob/master/collection/email-collect.md)
* **Input Capture** [E1056](https://github.com/MBCProject/mbc-markdown/blob/master/collection/input-capture.md)
* **Location Tracking** [T1430](https://github.com/MBCProject/mbc-markdown/blob/master/collection/location-track.md)
* **Man in the Browser** [T1185](https://github.com/MBCProject/mbc-markdown/blob/master/collection/man-in-browser.md)
* **Microphone or Camera Capture** [T1429](https://github.com/MBCProject/mbc-markdown/blob/master/collection/micro-cam-capture.md)
* **Screen Capture** [T1113](https://github.com/MBCProject/mbc-markdown/blob/master/collection/screen-capture.md)
* **Video Capture** [T1125](https://github.com/MBCProject/mbc-markdown/blob/master/collection/video-capture.md)
# Collection
Behaviors that enable malware to identify and gather information, such as sensitive files, from a machine or network. Sources often targeted include drives, browsers, audio/video, and email. Often the malware's next objective is to exfiltrate the information gathered.
* **Archive Collected Data** [E1560](../collection/archive-collected-data.md)
* **Cryptocurrency** [B0028](../collection/cryptocurrency.md)
* **Hijack Execution Flow** [F0015](../defense-evasion/hijack-execution-flow.md)
* **Input Capture** [E1056](../collection/input-capture.md)
* **Keylogging** [F0002](../collection/keylogging.md)
* **Screen Capture** [E1113](../collection/screen-capture.md)
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1433**|
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|**Related ATT&CK Technique**|[Access Call Log](https://attack.mitre.org/techniques/T1433/)|
Access Call Log
===============
Malware gathers call log data.
**See ATT&CK:** [**Access Call Log**](https://attack.mitre.org/techniques/T1433/).
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**E1409**|
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection), [Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access)|
|**Related ATT&CK Technique**|[Access Sensitive Data or Credentials in Files](https://attack.mitre.org/techniques/T1409/)|
Access Sensitive Data or Credentials in Files
=============================================
Malware accesses files that contain sensitive data or credentials (e.g., passwords). Access of Bitcoin and other cryptocurrency wallets also fall under this behavior.
**See ATT&CK:** [**Access Sensitive Data or Credentials in Files**](https://attack.mitre.org/techniques/T1409/).
+73
View File
@@ -0,0 +1,73 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>E1560</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../collection">Collection</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>Archive Collected Data (<a href="https://attack.mitre.org/techniques/T1560/">T1560</a>)</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>4.1</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>27 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>27 April 2024</b></td>
</tr>
</table>
# Archive Collected Data
Malware may collect and package (or archive) the information they have gathered from a compromised system. Once collected, the data is often compressed and encrypted into an archive file using various tools or utilities. Common formats for archive files include .zip, .tar, .rar, or .7z. This helps the attack by reducing the size of the data, making it easier and quicker to exfiltrate, and helps avoid detection, since many security tools may not inspect the contents of compressed or encrypted files.
See ATT&CK Technique: **Archive Collected Data ([T1560](https://attack.mitre.org/techniques/T1560/))**.
## Methods
|Name|ID|Description|
|---|---|---|
|**Encoding**|E1560.m01|Data is encoded.|
|**Encoding - Custom Algorithm**|E1560.m04|Data is encoded. A custom algorithm is used to encode the exfiltrated data.|
|**Encoding - Standard Algorithm**|E1560.m03|Data is encoded. A standard algorithm, such as base64 encoding, is used to encode the exfiltrated data.|
|**Encryption**|E1560.m02|Data is encrypted.|
|**Encryption - Custom Algorithm**|E1560.m06|Data is encrypted. A custom algorithm is used to encrypt the exfiltrated data.|
|**Encryption - Standard Algorithm**|E1560.m05|Data is encrypted. A standard algorithm, such as Rijndael/AES, DES, RC4, is used to encrypt the exfiltrated data.|
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**TrickBot**](../xample-malware/trickbot.md)|2016|E1560.m02|The malware uses a custom crypter leveraging Microsoft's CryptoAPI to encrypt C2 traffic. C2 update responses seem to have been digitally signed using bcrypt. [[1]](#1)|
|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|E1560.m04|Exfiltrated payloads are XORed with a static 31-byte long byte string found inside Stuxnet and hexified in order to be passed on as an ASCII data parameter in an HTTP request to the C2 servers. [[2]](#2)|
|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|E1560.m03|Malware sends data as a Base64 string of JSON. [[3]](#3) [[4]](#4)|
## Detection
|Tool: CAPE|Mapping|APIs|
|---|---|---|
|[encrypt_data_agenttesla_http](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/malware_data_encryption.py)|Archive Collected Data (E1560)|CryptEncrypt|
|[encrypt_data_agenttesla_http](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/malware_data_encryption.py)|Archive Collected Data::Encryption (E1560.m02)|CryptEncrypt|
|[encrypt_data_agentteslat2_http](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/malware_data_encryption.py)|Archive Collected Data (E1560)|CryptEncrypt, GetUserNameW, GetComputerNameW|
|[encrypt_data_agentteslat2_http](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/malware_data_encryption.py)|Archive Collected Data::Encryption (E1560.m02)|CryptEncrypt, GetUserNameW, GetComputerNameW|
|[encrypt_data_nanocore](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/malware_data_encryption.py)|Archive Collected Data (E1560)|CryptEncrypt, GetUserNameW, GetComputerNameW|
|[encrypt_data_nanocore](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/malware_data_encryption.py)|Archive Collected Data::Encryption (E1560.m02)|CryptEncrypt, GetUserNameW, GetComputerNameW|
## References
<a name="1">[1]</a> https://www.bitdefender.com/blog/labs/trickbot-is-dead-long-live-trickbot/
<a name="2">[2]</a> https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en
<a name="3">[3]</a> https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/
<a name="4">[4]</a> https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1123**|
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|**Related ATT&CK Technique**|[Audio Capture](https://attack.mitre.org/techniques/T1123/)|
Audio Capture
=============
Malware leverages system's peripheral devices to capture audio.
**See ATT&CK:** [**Audio Capture**](https://attack.mitre.org/techniques/T1123/).
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1119**|
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|**Related ATT&CK Technique**|[Automated Collection](https://attack.mitre.org/techniques/T1119/)|
Automated Collection
====================
Malware uses automated techniques for collecting system data.
**See ATT&CK:** [**Automated Collection**](https://attack.mitre.org/techniques/T1119/).
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1412**|
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection), [Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access)|
|**Related ATT&CK Technique**|[Capture SMS Messages](https://attack.mitre.org/techniques/T1412/)|
Capture SMS Messages
====================
Malware captures data sent via SMS (e.g., authentication credentials).
**See ATT&CK:** [**Capture SMS Messages**](https://attack.mitre.org/techniques/T1412/).
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1115**|
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|**Related ATT&CK Technique**|[Clipboard Data](https://attack.mitre.org/techniques/T1115/)|
Clipboard Data
==============
Malware collects data stored in the Windows clipboard.
**See ATT&CK:** [**Clipboard Data**](https://attack.mitre.org/techniques/T1115/).
+55
View File
@@ -0,0 +1,55 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>B0028</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../collection">Collection</a>, <a href="../credential-access">Credential Access</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>None</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.3</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>14 August 2020</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>27 April 2024</b></td>
</tr>
</table>
# Cryptocurrency
Malware accesses files that contain sensitive data or credentials related to Bitcoin and other cryptocurrency wallets.
## Methods
|Name|ID|Description|
|---|---|---|
|**Bitcoin**|B0028.001|Access Bitcoin data.|
|**Ethereum**|B0028.002|Access Ethereum data.|
|**Zcash**|B0028.003|Access Zcash data.|
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**ElectroRAT**](../xample-malware/electrorat.md)|2020|--|ElectroRat examines the disk for cryptocurrency addresses and keys to steal money from a wallet. It compromises multiple currencies, including Monaro, Doegecoin, Ethereum, Litecoin, and Bitcoin. [[1]](#1)|
## Detection
|Tool: CAPE|Mapping|APIs|
|---|---|---|
|[infostealer_bitcoin](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/infostealer_bitcoin.py)|Cryptocurrency (B0028)|--|
|[infostealer_bitcoin](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/infostealer_bitcoin.py)|Cryptocurrency::Bitcoin (B0028.001)|--|
## References
<a name="1">[1]</a> https://www.intezer.com/blog/research/operation-electrorat-attacker-creates-fake-companies-to-drain-your-crypto-wallets/
-22
View File
@@ -1,22 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1005**|
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|**Related ATT&CK Technique**|[Data from Local System](https://attack.mitre.org/techniques/T1005/)|
Data from Local System
======================
Malware collects sensitive data from local system sources.
**See ATT&CK:** [**Data from Local System**](https://attack.mitre.org/techniques/T1005/).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|[**Poison-Ivy**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/poison-ivy.md)|2005|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[1]](#1)|
References
----------
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1039**|
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|**Related ATT&CK Technique**|[Data from Network Shared Drive](https://attack.mitre.org/techniques/T1039/)|
Data from Network Shared Drive
==============================
Malware collects from remote systems via shared network drives that are accessible from the compromised system.
**See ATT&CK:** [**Data from Network Shared Drive**](https://attack.mitre.org/techniques/T1039/).
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1025**|
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|**Related ATT&CK Technique**|[Data from Removable Media](https://attack.mitre.org/techniques/T1025/)|
Data from Removable Media
=========================
Malware collects from removable media connected to the compromised system.
**See ATT&CK:** [**Data from Removable Media**](https://attack.mitre.org/techniques/T1025/).
-21
View File
@@ -1,21 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1074**|
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|**Related ATT&CK Technique**|[Data Staged](https://attack.mitre.org/techniques/T1074/)|
Data Staged
===========
Malware stages collected data prior to [Exfiltration](https://github.com/MBCProject/mbc-markdown/tree/master/exfiltration).
**See ATT&CK:** [**Data Staged**](https://attack.mitre.org/techniques/T1074/).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|--------|-----------------------------|
|[**Poison-Ivy**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/poison-ivy.md)|2005|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[1]](#1)|
References
----------
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
-17
View File
@@ -1,17 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1114**|
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|**Related ATT&CK Technique**|[Email Collection](https://attack.mitre.org/techniques/T1114/)|
Email Collection
================
Malware targets user email for collection.
**See ATT&CK:** [**Email Collection**](https://attack.mitre.org/techniques/T1114/).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
+71 -21
View File
@@ -1,26 +1,76 @@
|||
|---------|------------------------|
|**ID**|**E1056**|
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection), [Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access)|
|**Related ATT&CK Technique**|[Input Capture](https://attack.mitre.org/techniques/T1056/)|
<table>
<tr>
<td><b>ID</b></td>
<td><b>E1056</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../collection">Collection</a>, <a href="../credential-access">Credential Access</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>Input Capture (<a href="https://attack.mitre.org/techniques/T1056">T1056</a>, <a href="https://attack.mitre.org/techniques/T1417/">T1417</a>)</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.3</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>27 April 2024</b></td>
</tr>
</table>
Input Capture
=============
Malware captures user input.
**See ATT&CK:** [**Input Capture**](https://attack.mitre.org/techniques/T1056/).
# Input Capture
Methods
-------
* **Mouse Events**: Mouse events are captured.
* **Keyboard Events**: Keyboard events are captured.
Malware may record user inputs, typically without the user's knowledge. This is often used to capture sensitive information such as usernames, passwords, credit card numbers, and other personal data. The most common form of input capture is keylogging, where the malware records every keystroke made on a device. However, it can also involve capturing mouse clicks, touch screen interactions, or even voice inputs. The captured data is then usually transmitted to the attacker for use in further malicious activities like identity theft or unauthorized access.
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|--------|-----------------------------|
|[**Poison-Ivy**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/poison-ivy.md)|2005|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[1]](#1)|
See ATT&CK: **Input Capture ([T1056](https://attack.mitre.org/techniques/T1056), [T1417](https://attack.mitre.org/techniques/T1417/))**.
## Methods
|Name|ID|Description|
|---|---|---|
|**Mouse Events**|E1056.m01|Mouse events are captured.|
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|The malware injects itself into a browser and captures user input data. [[1]](#1)|
|[**Ursnif**](../xample-malware/ursnif.md)|2016|--|The malware injects HTML into a browser session to collect sensitive online banking information when the victim performs their online banking. [[2]](#2)|
|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|--|Poison Ivy can capture audio and video. [[4]](#4)|
|[**Clipminer**](../xample-malware/clipminer.md)|2011|--|Clipminer monitors keyboard and mouse activity to determine if the machine is in use. [[5]](#5)|
|[**ElectroRAT**](../xample-malware/electrorat.md)|2020|--|ElectroRat monitors keyboard and mouse activity to determine whether the machine is in use. [[6]](#6)|
## Detection
|Tool: capa|Mapping|APIs|
|---|---|---|
|[use .NET library SharpClipboard](https://github.com/mandiant/capa-rules/blob/master/collection/use-dotnet-library-sharpclipboard.yml)|Input Capture (E1056)|--|
|Tool: CAPE|Mapping|APIs|
|---|---|---|
|[antisandbox_mouse_hook](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_mouse_hook.py)|Input Capture (E1056)|SetWindowsHookExA, SetWindowsHookExW|
|[antisandbox_mouse_hook](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_mouse_hook.py)|Input Capture::Mouse Events (E1056.m01)|SetWindowsHookExA, SetWindowsHookExW|
|[browser_scanbox](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/browser_scanbox.py)|Input Capture (E1056)|JsEval, COleScript_ParseScriptText, COleScript_Compile|
## References
<a name="1">[1]</a> https://blogs.cisco.com/security/talos/rombertik
<a name="2">[2]</a> https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/BKDR_URSNIF.SM?_ga=2.129468940.1462021705.1559742358-1202584019.1549394279
<a name="3">[3]</a> https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/clipminer-bitcoin-mining-hijacking
<a name="4">[4]</a> https://www.cyber.nj.gov/threat-center/threat-profiles/trojan-variants/poison-ivy
<a name="5">[5]</a> https://www.mandiant.com/sites/default/files/2021-09/rpt-poison-ivy.pdf
<a name="6">[6]</a> https://www.intezer.com/blog/research/operation-electrorat-attacker-creates-fake-companies-to-drain-your-crypto-wallets/
References
----------
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
+109
View File
@@ -0,0 +1,109 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>F0002</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../collection">Collection</a>, <a href="../credential-access">Credential Access</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>Input Capture: Keylogging (<a href="https://attack.mitre.org/techniques/T1056/001">T1056.001</a>, <a href="https://attack.mitre.org/techniques/T1417/001/">T1417.001</a>)</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.3</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>14 August 2020</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>27 April 2024</b></td>
</tr>
</table>
# Keylogging
Malware captures user keyboard input.
See ATT&CK: **Input Capture: Keylogging ([T1056.001](https://attack.mitre.org/techniques/T1056/001), [T1417.001](https://attack.mitre.org/techniques/T1417/001/))**
## Methods
|Name|ID|Description|
|---|---|---|
|**Application Hook**|F0002.001|Keystrokes are captured with an application hook.|
|**Polling**|F0002.002|Keystrokes are captured via polling (e.g., user32.GetAsyncKeyState, user32.GetKeyState).|
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Certain variants of the malware may have keylogging functionality. [[1]](#1)|
|[**Hupigon**](../xample-malware/hupigon.md)|2013|F0002.002|Malware logs keystrokes via polling. [[9]](#9)|
|[**UP007**](../xample-malware/up007.md)|2016|--|The malware logs keystrokes to a file. [[2]](#2)|
|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|BlackEnergy's keylogger plugin allows for the collection of keystrokes. [[3]](#3)|
|[**DarkComet**](../xample-malware/dark-comet.md)|2008|--|DarkComet can capture keystrokes. [[4]](#4)|
|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|F0002.002|Malware logs keystrokes via polling. [[9]](#9)|
|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|--|Poison Ivy can capture keystrokes. [[5]](#5)|
|[**CHOPSTICK**](../xample-malware/chopstick.md)|2015|--|CHOPSTICK collects user keystrokes. [[6]](#6)|
|[**Kovter**](../xample-malware/kovter.md)|2016|F0002.002|Malware logs keystrokes via polling. [[9]](#9)|
|[**Redhip**](../xample-malware/redhip.md)|2011|F0002.001|Malware logs keystrokes via application hook. [[9]](#9)|
|[**Redhip**](../xample-malware/redhip.md)|2011|F0002.002|Malware logs keystrokes via polling. [[9]](#9)|
|[**Rombertik**](../xample-malware/rombertik.md)|2015|F0002.002|Malware logs keystrokes via polling. [[9]](#9)|
|[**Ursnif**](../xample-malware/ursnif.md)|2016|F0002.002|Malware logs keystrokes via polling. [[9]](#9)|
|[**Snake**](../xample-malware/snake.md)|2004|F0002.001|Malware logs keystrokes via application hook. [[10]](#10)|
## Detection
|Tool: capa|Mapping|APIs|
|---|---|---|
|[log keystrokes via polling](https://github.com/mandiant/capa-rules/blob/master/collection/keylog/log-keystrokes-via-polling.yml)|Keylogging::Polling (F0002.002)|user32.GetAsyncKeyState, user32.GetKeyState, user32.GetKeyboardState, user32.VkKeyScan, user32.VkKeyScanEx, user32.GetKeyNameText|
|[log keystrokes via application hook](https://github.com/mandiant/capa-rules/blob/master/collection/keylog/log-keystrokes-via-application-hook.yml)|Keylogging::Application Hook (F0002.001)|--|
|Tool: CAPE|Mapping|APIs|
|---|---|---|
|[infostealer_keylog](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/infostealer_keylog.py)|Keylogging (F0002)|SetWindowsHookExA, GetAsyncKeyState, SetWindowsHookExW|
|[infostealer_keylog](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/infostealer_keylog.py)|Keylogging::Application Hook (F0002.001)|SetWindowsHookExA, GetAsyncKeyState, SetWindowsHookExW|
|[browser_scanbox](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/browser_scanbox.py)|Keylogging (F0002)|JsEval, COleScript_ParseScriptText, COleScript_Compile|
### F0002.002 Snippet
<details>
<summary> Collection::Keylogging::Polling </summary>
SHA256: 000b535ab2a4fec86e2d8254f8ed65c6ebd37309ed68692c929f8f93a99233f6
Location: 0x438af1
<pre>
push 0x11 ; provide argument for function call. In this case, 0x11 is the Windows keyboard code for indicating the 'CTRL' key
call USER32.DLL::GetKeyState ; call function to get the state of the control key
test ax, 0x8000 ; test to see what the previous function returned. In this case, we are seeing if the return value's high-order bit is a 1, which would mean the ctrl key is pressed
setnz al ; if the previous condition is not met (the zero flag is 1), a 1 is stored in byte al
</pre>
</details>
## References
<a name="1">[1]</a> https://www.f-secure.com/v-descs/backdoor_w32_hupigon.shtml
<a name="2">[2]</a> https://citizenlab.ca/2016/04/between-hong-kong-and-burma/
<a name="3">[3]</a> https://securelist.com/be2-custom-plugins-router-abuse-and-target-profiles/67353/
<a name="4">[4]</a> https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/
<a name="5">[5]</a> https://www.cyber.nj.gov/threat-center/threat-profiles/trojan-variants/poison-ivy
<a name="6">[6]</a> https://web.archive.org/web/20210307034415/https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf
<a name="7">[7]</a> capa v4.0, analyzed at MITRE on 10/12/2022
<a name="8">[8]</a> https://www.mandiant.com/sites/default/files/2021-09/rpt-poison-ivy.pdf
<a name="9">[9]</a> capa v4.0, analyzed at MITRE on 10/12/2022
<a name="10">[10]</a> https://www.cybereason.com/blog/research/threat-analysis-report-snake-infostealer-malware
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1430**|
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|**Related ATT&CK Technique**|[Location Tracking](https://attack.mitre.org/techniques/T1430/)|
Location Tracking
=================
Malware tracks a system's physical location.
**See ATT&CK:** [**Location Tracking**](https://attack.mitre.org/techniques/T1430/).
-17
View File
@@ -1,17 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1185**|
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|**Related ATT&CK Technique**|[Man in the Browser](https://attack.mitre.org/techniques/T1185/)|
Man in the Browser
==================
Malware leverages vulnerabilities and functionality in browser software to change content, modify behavior, and intercept information.
**See ATT&CK:** [**Man in the Browser**](https://attack.mitre.org/techniques/T1185/).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1429**|
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|**Related ATT&CK Technique**|[Microphone or Camera Recordings](https://attack.mitre.org/techniques/T1429/), [Capture Camera](https://attack.mitre.org/techniques/T1512/), [Capture Audio](https://attack.mitre.org/techniques/T1429/)|
Microphone or Camera Capture
============================
Malware records activities using the device microphone and/or camera.
**See ATT&CK:** [**Microphone or Camera Recordings**](https://attack.mitre.org/techniques/T1429/), [Capture Camera](https://attack.mitre.org/techniques/T1512/), [Capture Audio](https://attack.mitre.org/techniques/T1429/).
+99 -9
View File
@@ -1,11 +1,101 @@
|||
|---------|------------------------|
|**ID**|**T1113**|
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|**Related ATT&CK Technique**|[Screen Capture](https://attack.mitre.org/techniques/T1113/)|
<table>
<tr>
<td><b>ID</b></td>
<td><b>E1113</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../collection">Collection</a>, <a href="../credential-access">Credential Access</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>Screen Capture (<a href="https://attack.mitre.org/techniques/T1113/">T1113</a>)</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.3</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>27 April 2024</b></td>
</tr>
</table>
Screen Capture
==============
Malware takes screen captures.
**See ATT&CK:** [**Screen Capture**](https://attack.mitre.org/techniques/T1113/).
# Screen Capture
Malware takes screen captures of the desktop. This technique is often used by cyber attackers to gather sensitive information, such as login credentials, personal data, or confidential documents. The malware can use various methods to capture the screen, including using built-in functions of the operating system or third-party libraries. The captured screenshots are then typically sent back to the attacker's command and control server. This technique is commonly used by spyware, information stealers, and advanced persistent threats (APTs).
See ATT&CK: **Screen Capture ([T1113](https://attack.mitre.org/techniques/T1113/))**.
## Methods
|Name|ID|Description|
|---|---|---|
|**WinAPI**|E1113.m01|Screen is captured using WinAPI functions (e.g., user32.GetDesktopWindow).|
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR is capable of capturing screenshots. [[1]](#1)|
|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|BlackEnergy's screenshot plugin allows for collection of screenshots. [[2]](#2)|
|[**DarkComet**](../xample-malware/dark-comet.md)|2008|E1113.m01|DarkComet can take screenshots of the victim's computer. [[3]](#3) [[5]](#5)|
|[**CHOPSTICK**](../xample-malware/chopstick.md)|2015|--|CHOPSTICK takes snapshots of deskop and window contents. [[4]](#4)|
|[**Hupigon**](../xample-malware/hupigon.md)|2013|E1113.m01|Malware captures screenshots. [[5]](#5)|
|[**Kovter**](../xample-malware/kovter.md)|2016|E1113.m01|Malware captures screenshots. [[5]](#5)|
|[**Rombertik**](../xample-malware/rombertik.md)|2015|E1113.m01|Malware captures screenshots. [[5]](#5)|
|[**Snake**](../xample-malware/snake.md)|2004|--|Malware captures screenshots. [[6]](#6)|
## Detection
|Tool: capa|Mapping|APIs|
|---|---|---|
|[capture screenshot](https://github.com/mandiant/capa-rules/blob/master/collection/screenshot/capture-screenshot.yml)|Screen Capture::WinAPI (E1113.m01)|user32.GetWindowDC, user32.GetDC, gdi32.CreateDC, gdi32.BitBlt, gdi32.GetDIBits, gdi32.CreateCompatibleDC, gdi32.CreateCompatibleBitmap, user32.GetSystemMetrics = fetch screen dimensions, user32.GetDesktopWindow = get entire desktop, BitBlt, System.Drawing.Graphics::CopyFromScreen|
|[capture screenshot via keybd event](https://github.com/mandiant/capa-rules/blob/master/collection/screenshot/capture-screenshot-via-keybd-event.yml)|Screen Capture (E1113)|--|
|Tool: CAPE|Mapping|APIs|
|---|---|---|
|[poullight_files](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/infostealer_poullight.py)|Screen Capture (E1113)|--|
|[captures_screenshot](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/infostealer_screenshot.py)|Screen Capture (E1113)|LdrGetProcedureAddress, NtCreateFile|
### E1113.m01 Snippet
<details>
<summary> Collection::Screen Capture::WinAPI </summary>
SHA256: c6930e298bba86c01d0fe2c8262c46b4fce97c6c5037a193904cfc634246fbec
Location: 0x4036de
<pre>
push 0xcc0020 ; Raster operation code to copy the source rectangle directly onto the destination rectangle
push 0x0 ; y-coordinate of upper left corner of source rectangle
push 0x0 ; x-coordinate of upper left corner of source rectangle
push dword ptr [esi] ; handle to source device
push eax ; height of source/destination rectangles
mov eax, dword ptr [esi + 0xc]
sub eax, param_2
sub param_2, ebx
push eax ; width of source/destination rectangles
push param_1 ; y-coordinate of upper left corner of destination rectangle
push param_2 ; x-coordinate of upper left corner of destination rectangle
push dword ptr [ebp + local_28] ; handle to destingation device
call dword ptr [->GDI32.DLL::BitBlt] ; Windows API function to transfer a rectangle of pixels from one device to another
</pre>
</details>
## References
<a name="1">[1]</a> https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/
<a name="2">[2]</a> https://securelist.com/be2-custom-plugins-router-abuse-and-target-profiles/67353/
<a name="3">[3]</a> https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/
<a name="4">[4]</a> https://web.archive.org/web/20210307034415/https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf
<a name="5">[5]</a> capa v4.0, analyzed at MITRE on 10/12/2022
<a name="6">[6]</a> https://www.cybereason.com/blog/research/threat-analysis-report-snake-infostealer-malware
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1125**|
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/collection)|
|**Related ATT&CK Technique**|[Video Capture](https://attack.mitre.org/techniques/T1125/)|
Video Capture
=============
Malware captures video recordings.
**See ATT&CK:** [**Video Capture**](https://attack.mitre.org/techniques/T1125/).
+18 -23
View File
@@ -1,26 +1,21 @@
|||
|--|-----|
|**ID**|**M9004**|
<table>
<tr>
<td><b>ID</b></td>
<td><b>OB0004</b></td>
</tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>29 November 2022</b></td>
</tr>
</table>
# Command and Control
Behaviors malware may use to communicate with systems under its control within a target network. There are many ways malware can establish command and control with various levels of covertness, depending on system configuration and network topology. Behaviors may relate to C2 servers or a bot that is part of a botnet.
* **Command and Control Communication** [M0030](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/command-control-comm.md)
* **Commonly Used Port** [T1043](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/common-port.md)
* **Connection Proxy** [T1090](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/connect-proxy.md)
* **Custom Command and Control Protocol** [T1094](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/custom-c2-protocol.md)
* **Custom Cryptographic Protocol** [T1024](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/custom-crypto-protocol.md)
* **Data Encoding** [T1132](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/data-encode.md)
* **Data Obfuscation** [T1001](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/data-obfuscate.md)
* **Domain Name Generation** [M0031](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/domain-name-generate.md)
* **Fallback Channels** [T1008](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/fallback-channels.md)
* **Multi-hop Proxy** [T1188](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/multihop-proxy.md)
* **Multi-Stage Channels** [T1104](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/multi-stage-channels.md)
* **Port Knocking** [T1205](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/port-knocking.md)
* **Remote Access Tools** [T1219](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/remote-access-tools.md)
* **Remote File Copy** [E1105](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/remote-file-copy.md)
* **Standard Application Layer Protocol** [T1071](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/std-app-protocol.md)
* **Standard Cryptographic Protocol** [T1032](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/std-crypto-protocol.md)
* **Standard Non-Application Layer Protocol** [T1095](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/std-non-app-protocol.md)
* **Uncommonly Used Port** [T1065](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/uncommon-port.md)
* **Web Service** [T1102](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/web-service.md)
Behaviors that enable malware to communicate with systems such as C2 servers or bots. Malware can establish command and control with various levels of covertness, depending on system configuration and network topology.
* **Command and Control Communication** [B0030](../command-and-control/c2-communication.md)
* **Domain Name Generation** [B0031](../command-and-control/domain-name-generation.md)
* **Ingress Tool Transfer** [E1105](../command-and-control/ingress-tool-transfer.md)
+186
View File
@@ -0,0 +1,186 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>B0030</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../command-and-control">Command and Control</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>None</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.4</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>28 April 2024</b></td>
</tr>
</table>
# C2 Communication
All command and control malware use implant/controller communication. The methods listed below can be used to capture explicit communication details. Remote file copy behavior is captured separately, as is done in ATT&CK - see **Ingress Tool Transfer ([E1105](../command-and-control/ingress-tool-transfer.md))**.
Command and Control Communication relates to *autonomous* communications, not explicit, on-demand commands that malware provides to an adversary (such commands should be captured with [Remote Commands](../execution/remote-commands.md) under the Execution objective).
As "server" and "client" are confusing terminology, we use the terms "controller" and "implant". The controller is the software running on adversary-controlled infrastructure and used to send commands to the implant. The implant is the software running on victim-controlled infrastructure that receives commands from the adversary, executes those commands on the victim, and optionally sends the results back to the adversary.
## Methods
|Name|ID|Description|
|---|---|---|
|**Authenticate**|B0030.011|Implant may authenticate itself to the controller, controller may authenticate itself to implant, or both. This is often at or near the start of communication. Examples include but are not limited to a simple shared secret (e.g. password), challenge-response with symmetric encryption, or challenge-response with asymmetric encryption.|
|**Check for Payload**|B0030.005|An implant may check with the controller for additional payloads or instructions, sometimes at a regular interval. This is also known as beaconing.|
|**Directory Listing**|B0030.012|Controller requests a directory listing from the implant, optionally from a given path, optionally recursive.|
|**Execute File**|B0030.013|Execute/run/open the file using default operating system functionality, optionally with provided command-and-scripting-interpreter arguments. The file may or may not already exist on the victim.|
|**Execute Shell Command**|B0030.014|Execute/run the given command using a built-in program (e.g. cmd.exe, PowerShell, bash). This differs from Start Interactive Shell because the shell process is started only for the received command or set of commands and then exits. There is no loop looking for additional commands while the shell process is still running.|
|**File search**|B0030.015|Controller requests the implant to search for a given filename pattern, often a [glob](https://en.wikipedia.org/wiki/Glob_(programming)).|
|**Implant to Controller File Transfer**|B0030.004|File is transferred from implant to controller.|
|**Receive Data**|[B0030.002](#b0030002-snippet)|Receive data or command from a controller.|
|**Request Command**|B0030.008|Implant requests a command.|
|**Request Email Address List**|B0030.010|Request email address list.|
|**Request Email Template**|B0030.009|Request email template.|
|**Send Data**|B0030.001|Send data to a controller.|
|**Send Heartbeat**|B0030.007|Heartbeat sent.|
|**Send System Information**|B0030.006|Implant sends system information.|
|**Server to Client File Transfer**|B0030.003|File is transferred from controller to implant.|
|**Start Interactive Shell**|B0030.016|Starts an interactive shell using a built-in program (e.g. cmd.exe, PowerShell, bash). This is often implemented with polling the network connection from the controller for text commands to redirect to the shell's stdin and polling the shell's stdout and stderr to redirect over the network to the controller. This differs from Execute Shell Command because the shell process runs across multiple iterations of the recv-command(s)-send-result loop.|
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**CryptoWall**](../xample-malware/cryptowall.md)|2014|B0030.001|The malware sends a hash value generated from system information. [[1]](#1)|
|[**CryptoWall**](../xample-malware/cryptowall.md)|2014|B0030.002|The malware receives a public key from the C2. [[1]](#1)|
|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|B0030.001|The malware sends a hash value generated from system information. [[14]](#14)|
|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|B0030.002|The malware receives a public key from the C2. [[14]](#14)|
|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|B0030.011|The malware sends a phone-home message with encryption to start. [[14]](#14)|
|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|B0030.002|GoBotKR receives data from the C2. [[2]](#2) [[19]](#19)|
|[**Terminator**](../xample-malware/terminator.md)|2013|B0030.001|The malware sends data to the C2. [[3]](#3)|
|[**UP007**](../xample-malware/up007.md)|2016|B0030.001|The malware sends hardened HTTP headers disguised as Microsoft Update traffic. [[4]](#4)|
|[**UP007**](../xample-malware/up007.md)|2016|B0030.002|The malware receives payloads. [[4]](#4)|
|[**YiSpecter**](../xample-malware/yispecter.md)|2015|B0030.006|The malware connects to the C2 server using HTTP to send device information. [[5]](#5)|
|[**Ursnif**](../xample-malware/ursnif.md)|2016|B0030.011|Ursnif variant Dreambot authenticates and encrypts traffic to the C2 server using TOR. [[6]](#6)|
|[**Emotet**](../xample-malware/emotet.md)|2018|B0030.010|New email addresses are collected automatically from the victim's address books. [[7]](#7)|
|[**CHOPSTICK**](../xample-malware/chopstick.md)|2015|B0030.001|CHOPSTICK sends data to the C2 server using HTTP POST requests. [[8]](#8)|
|[**CozyCar**](../xample-malware/cozycar.md)|2010|--|CozyCar communicates with a C2 server. [[9]](#9)|
|[**EvilBunny**](../xample-malware/evilbunny.md)|2011|--|EvilBunny communicates C2 via HTTP. [[10]](#10)|
|[**Clipminer**](../xample-malware/clipminer.md)|2011|--|Clipminer communicates to a Tor Onion Service via HTTP. [[11]](#11)|
|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0030.001|The malware sends collected data about the system to C2 server. [[12]](#12) [[13]](#13)|
|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0030.002|The C2 server returns Base64 encoded data containing the information about the next command for the loader. [[12]](#12) [[13]](#13)|
|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0030.013|The payload is run by explorer.exe. [[12]](#12) [[13]](#13)|
|[**Gamut**](../xample-malware/gamut.md)|2014|B0030.002|Gamut receives data from the C2. [[15]](#15)|
|[**Gamut**](../xample-malware/gamut.md)|2014|B0030.003|The malware receives files from the C2. [[15]](#15)|
|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|B0030.002|GravityRAT receives data from the C2. [[19]](#19)|
|[**Heriplor**](../xample-malware/heriplor.md)|2012|B0030.002|Heriplor malware has a capability to connect with a C2 to download arbitrary code. [[16]](#16)|
|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0030.001|The malware sends data to the C2. [[17]](#17) [[19]](#19)|
|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0030.002|The malware receives data from the C2. [[19]](#19)|
|[**Hupigon**](../xample-malware/hupigon.md)|2013|BB0030.001|The malware sends data to the C2. [[19]](#19)|
|[**Hupigon**](../xample-malware/hupigon.md)|2013|B0030.002|The malware receives data from the C2. [[19]](#19)|
|[**Kovter**](../xample-malware/kovter.md)|2016|B0030.001|The malware sends data to the C2. [[19]](#19)|
|[**Kovter**](../xample-malware/kovter.md)|2016|B0030.002|The malware receives data from the C2. [[19]](#19)|
|[**SearchAwesome**](../xample-malware/searchawesome.md)|2018|B0030.002|The malware receives data from the C2 server. [[18]](#18)|
|[**ElectroRAT**](../xample-malware/electrorat.md)|2020|--|ElectroRat communicates to a Pastebin site via HTTP. [[20]](#20)|
## Detection
|Tool: capa|Mapping|APIs|
|---|---|---|
|[send data](https://github.com/mandiant/capa-rules/blob/master/communication/send-data.yml)|C2 Communication::Send Data (B0030.001)|--|
|[receive data](https://github.com/mandiant/capa-rules/blob/master/communication/receive-data.yml)|C2 Communication::Receive Data (B0030.002)|--|
|[download and write a file](https://github.com/mandiant/capa-rules/blob/master/communication/c2/file-transfer/download-and-write-a-file.yml)|C2 Communication::Server to Client File Transfer (B0030.003)|--|
|Tool: CAPE|Mapping|APIs|
|---|---|---|
|[office_cve2017_11882_network](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/office_exploit.py)|C2 Communication (B0030)|ConnectEx, URLDownloadToFileW|
|[internet_dropper](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/internet_dropper.py)|C2 Communication (B0030)|HttpOpenRequestA, InternetConnectA, HttpOpenRequestW, InternetConnectW|
|[internet_dropper](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/internet_dropper.py)|C2 Communication::Check for Payload (B0030.005)|HttpOpenRequestA, InternetConnectA, HttpOpenRequestW, InternetConnectW|
|[bot_madness](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/bot_madness.py)|C2 Communication (B0030)|--|
|[bot_drive](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/bot_drive.py)|C2 Communication (B0030)|--|
|[recon_beacon](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/recon_beacon.py)|C2 Communication (B0030)|HttpOpenRequestA, HttpSendRequestA|
|[nemty_network_activity](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/ransomware_nemty.py)|C2 Communication (B0030)|InternetOpenA, InternetOpenUrlA|
|[bot_drive2](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/bot_drive2.py)|C2 Communication (B0030)|--|
|[bot_dirtjumper](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/bot_dirtjumper.py)|C2 Communication (B0030)|--|
|[bot_athenahttp](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/bot_athenahttp.py)|C2 Communication (B0030)|--|
|[network_dns_tunneling_request](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/network_dns_suspicious.py)|C2 Communication (B0030)|DnsQuery_A, DnsQuery_W|
|[network_questionable_host](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/network_questionable_host.py)|C2 Communication (B0030)|--|
|[injection_network_traffic](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/injection_network.py)|C2 Communication (B0030)|HttpOpenRequestA, URLDownloadToFileW, HttpOpenRequestW, InternetConnectW, InternetConnectA, connect, InternetCrackUrlW, InternetCrackUrlA, WSASend|
|[network_bind](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/network_bind.py)|C2 Communication (B0030)|listen, bind|
|[network_document_http](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/network_docfile_http.py)|C2 Communication (B0030)|URLDownloadToFileW, HttpOpenRequestW, InternetCrackUrlW, InternetCrackUrlA, WSASend, InternetReadFile|
|[network_country_distribution](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/network_cnc_generic.py)|C2 Communication (B0030)|--|
|[banker_zeus_url](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/banker_zeus_url.py)|C2 Communication (B0030)|--|
|[network_dyndns](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/network_dyndns.py)|C2 Communication (B0030)|--|
|[script_network_activity](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/script_downloader.py)|C2 Communication (B0030)|URLDownloadToFileW, HttpOpenRequestW, send, WSAConnect, InternetCrackUrlW, InternetCrackUrlA, SslEncryptPacket, InternetReadFile|
## Code Snippets
### B0030.002 Snippet
<details>
<summary> C2 Communication::Receive Data </summary>
SHA256: 304f533ce9ea4a9ee5c19bc81c49838857c63469e26023f330823c3240ee4e0
<pre>
asm
loc_401981
mov ecx, s
mov edx, edi
sub edx, esi
push 0 ; flags
lea eax, [esi+ebx]
push edx ;len
push eax ;buf
push ecx ;s
call recv
jmp short loc_4019A2
</pre>
</details>
## References
<a name="1">[1]</a> https://news.sophos.com/en-us/2015/12/17/the-current-state-of-ransomware-cryptowall/
<a name="2">[2]</a> https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/
<a name="3">[3]</a> https://paper.seebug.org/papers/APT/APT_CyberCriminal_Campagin/2013/FireEye-Terminator_RAT.pdf
<a name="4">[4]</a> https://citizenlab.ca/2016/04/between-hong-kong-and-burma/
<a name="5">[5]</a> https://unit42.paloaltonetworks.com/yispecter-first-ios-malware-attacks-non-jailbroken-ios-devices-by-abusing-private-apis/
<a name="6">[6]</a> https://www.proofpoint.com/us/threat-insight/post/ursnif-variant-dreambot-adds-tor-functionality
<a name="7">[7]</a> https://securelist.com/the-banking-trojan-emotet-detailed-analysis/69560/
<a name="8">[8]</a> https://web.archive.org/web/20210307034415/https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf
<a name="9">[9]</a> https://unit42.paloaltonetworks.com/tracking-minidionis-cozycars-new-ride-is-related-to-seaduke
<a name="10">[10]</a> https://web.archive.org/web/20150311013500/http://www.cyphort.com/evilbunny-malware-instrumented-lua/
<a name="11">[11]</a> https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/clipminer-bitcoin-mining-hijacking
<a name="12">[12]</a> https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/
<a name="13">[13]</a> https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader
<a name="14">[14]</a> https://www.secureworks.com/research/cryptolocker-ransomware
<a name="15">[15]</a> https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/gamut-spambot-analysis/
<a name="16">[16]</a> https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/troj_heriplor.a
<a name="17">[17]</a> https://blogs.cisco.com/security/talos/rombertik
<a name="18">[18]</a> https://www.malwarebytes.com/blog/news/2018/10/mac-malware-intercepts-encrypted-web-traffic-for-ad-injection
<a name="19">[19]</a> capa v4.0, analyzed at MITRE on 10/12/2022
<a name="20">[20]</a> https://www.intezer.com/blog/research/operation-electrorat-attacker-creates-fake-companies-to-drain-your-crypto-wallets/
@@ -1,20 +0,0 @@
|||
|---------|------------------------|
|**ID**|**M0030**|
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|**Related ATT&CK Technique**|None|
C2 Communication
================
All command and control malware use client/server communication. The methods listed below can be used to capture explicit communication details. Remote file copy behavior is captured separately, as is done in ATT&CK - see [Remote File Copy](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/remote-file-copy.md).
Command and Control Communication relates to *autonomous* client/server communications, not explicit, on-demand commands that malware provides to an adversary (such commands should be captured with [Remote Commands](https://github.com/MBCProject/mbc-markdown/blob/master/execution/remote-commands.md) under the Execution objective).
Methods
-------
* **Check for Payload**
* **Send System Information**
* **Send Heartbeat**
* **Request Command**
* **Request Email Template**
* **Request Email Address List**
-18
View File
@@ -1,18 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1043**|
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|**Related ATT&CK Technique**|[Commonly Used Port](https://attack.mitre.org/techniques/T1043/), [Commonly Used Port - Mobile](https://attack.mitre.org/techniques/T1436/)|
Commonly Used Port
==================
Malware may use a common port to avoid detection of command and control activity.
**See ATT&CK:** [**Commonly Used Port**](https://attack.mitre.org/techniques/T1043/) and [**Commonly Used Port (Mobile)**](https://attack.mitre.org/techniques/T1436/).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1090**|
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|**Related ATT&CK Technique**|[Connection Proxy](https://attack.mitre.org/techniques/T1090/)|
Connection Proxy
================
Malware may use a connection proxy to manage command and control communications.
**See ATT&CK:** [**Connection Proxy**](https://attack.mitre.org/techniques/T1090/).
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1094**|
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|**Related ATT&CK Technique**|[Custom Command and Control Protocol](https://attack.mitre.org/techniques/T1094/)|
Custom Command and Control Protocol
===================================
Malware may use a custom command and control protocol instead of encapsulating commands and data in a [Standard Application Layer Protocol](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control/std-protocol.md).
**See ATT&CK:** [**Custom Command and Control Protocol**](https://attack.mitre.org/techniques/T1094/).
@@ -1,17 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1024**|
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|**Related ATT&CK Technique**|[Custom Cryptographic Protocol](https://attack.mitre.org/techniques/T1024/)|
Custom Cryptographic Protocol
=============================
Malware may use a custom cryptographic protocol to hide command and control communications.
**See ATT&CK:** [**Custom Cryptographic Protocol**](https://attack.mitre.org/techniques/T1024/).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1132**|
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|**Related ATT&CK Technique**|[Data Encoding](https://attack.mitre.org/techniques/T1132/)|
Data Encoding
=============
Malware encodes its command and control information using a standard system such as Unicode, Base64, etc.
**See ATT&CK:** [**Data Encoding**](https://attack.mitre.org/techniques/T1132/).
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1001**|
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|**Related ATT&CK Technique**|[Data Obfuscation](https://attack.mitre.org/techniques/T1001/)|
Data Obfuscation
================
Malware hides its command and control information.
**See ATT&CK:** [**Data Obfuscation**](https://attack.mitre.org/techniques/T1001/).
@@ -1,26 +0,0 @@
|||
|---------|------------------------|
|**ID**|**M0031**|
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|**Related ATT&CK Technique**|[Domain Generation Algorithms](https://attack.mitre.org/techniques/T1483/)|
Domain Name Generation
======================
Malware generates the domain name of the command and control server to which it connects. Access to on the fly domains enables C2 to operate as domains and IP addresses are blocked. The algorithm can be complicated in more advanced bots; understanding the details so that names can be predicted can be useful in mitigation and response. [[1]](#1)
The subsequently defined ATT&CK technique [Domain Generation Algorithms](https://attack.mitre.org/techniques/T1483/), which is oriented toward an adversary perspective (although its examples include malware), is related to this MBC behavior.
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|--------|-----------------------------|
|[**Kraken**](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/kraken.md) | April 2008 | Kraken uses a domain generating algorithm to provide new domains. [[2]](#2)|
|[**Conficker**](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/conficker.md)| November 2008| Conficker uses a domain name generator. [[3]](#3)
References
----------
<a name="1">[1]</a> https://blog.malwarebytes.com/security-world/2016/12/explained-domain-generating-algorithm/
<a name="2">[2]</a> http://blog.threatexpert.com/2008/04/kraken-changes-tactics.html
<a name="3">[3]</a> https://en.wikipedia.org/wiki/Conficker
@@ -0,0 +1,65 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>B0031</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../command-and-control">Command and Control</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>Dynamic Resolution: Domain Generation Algorithms (<a href="https://attack.mitre.org/techniques/T1568/002/">T1568.002</a>)</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>28 April 2024</b></td>
</tr>
</table>
# Domain Name Generation
Malware generates the domain name of the controller to which it connects. Access to on the fly domains enables C2 to operate as domains and IP addresses are blocked. The algorithm can be complicated in more advanced implants; understanding the details so that names can be predicted can be useful in mitigation and response. [[1]](#1)
The related **Dynamic Resolution: Domain Generation Algorithms ([T1568.002](https://attack.mitre.org/techniques/T1568/002/))** ATT&CK sub-technique (oriented toward an adversary perspective with examples that include malware) was defined subsequent to this MBC behavior.
This behavior is related to Unprotect technique U0906.
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**Kraken**](../xample-malware/kraken.md)|2008|--|Kraken uses a domain generating algorithm to provide new domains. [[2]](#2)|
|[**Conficker**](../xample-malware/conficker.md)|2008|--|Conficker uses a domain name generator seeded by the current date to ensure that every copy of the virus generates the same names on their respective days. [[3]](#3)|
|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|--|The malware uses an internal domain generation algorithm. [[4]](#4)|
|[**Ursnif**](../xample-malware/ursnif.md)|2016|--|Previous interations of Ursnif have used a Domain Name Generation algorithm. [[5]](#5)|
## Detection
|Tool: CAPE|Mapping|APIs|
|---|---|---|
|[whois_create](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/whois_create.py)|Domain Name Generation (B0031)|--|
|[network_dga](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/network_dga.py)|Domain Name Generation (B0031)|--|
|[network_dga_fraunhofer](https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/network_dga_fraunhofer.py)|Domain Name Generation (B0031)|--|
## References
<a name="1">[1]</a> https://blog.malwarebytes.com/security-world/2016/12/explained-domain-generating-algorithm/
<a name="2">[2]</a> http://blog.threatexpert.com/2008/04/kraken-changes-tactics.html
<a name="3">[3]</a> https://en.wikipedia.org/wiki/Conficker
<a name="4">[4]</a> https://www.secureworks.com/research/cryptolocker-ransomware
<a name="5">[5]</a> https://www.proofpoint.com/us/threat-insight/post/ursnif-variant-dreambot-adds-tor-functionality
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1008**|
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|**Related ATT&CK Technique**|[Fallback Channels](https://attack.mitre.org/techniques/T1008/)|
Fallback Channels
=================
Malware may contain a secondary command and control server or may communicate over a backup channel.
**See ATT&CK:** [**Fallback Channels**](https://attack.mitre.org/techniques/T1008/).
@@ -0,0 +1,85 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>E1105</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../command-and-control">Command and Control</a>, <a href="../lateral-movement">Lateral Movement</a>, <a href="../persistence">Persistence</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>Ingress Tool Transfer (<a href="https://attack.mitre.org/techniques/T1105/">T1105</a>)</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>28 April 2024</b></td>
</tr>
</table>
# Ingress Tool Transfer
Malware may copy files from an external system to a system on a compromised network.
Note that this behavior is separate from possible execution (installation) of the file, which is covered by the **Install Additional Program ([B0023](../execution/install-additional-program.md))** behavior.
See ATT&CK: **Ingress Tool Transfer ([T1105](https://attack.mitre.org/techniques/T1105/))**.
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|--|After the Poison Ivy implant is running on the target machine, the attacker can use a Windows GUI controller to control the target computer. [[1]](#1)|
|[**DarkComet**](../xample-malware/dark-comet.md)|2008|--|DarkComet can download files from a remote repository upon instruction. [[2]](#2)|
|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Shamoon creates a folder on remote computers and then copies its executables (Shamoon and Filerase) into that directory. [[3]](#3)|
|[**CozyCar**](../xample-malware/cozycar.md)|2010|--|CozyCar requests a file using SSL to a C2 domain. [[4]](#4)|
|[**Vobfus**](../xample-malware/vobfus.md)|2016|--|Vobfus downloads its latest version from a remote server. [[5]](#5)|
|[**TEARDROP**](../xample-malware/teardrop.md)|2018|--|TEARDROP executes the decrypted, embedded code buffer, which is a Cobalt Strike RAT. [[6]](#6)|
|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|--|Malware downloads DLLs from the hardcoded URL/remote server. [[7]](#7) [[8]](#8)|
|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR can download additional files and update itself. [[9]](#9)|
|[**Gamut**](../xample-malware/gamut.md)|2014|--|Gamut receives files from the C2. [[10]](#10)|
|[**UP007**](../xample-malware/up007.md)|2016|--|UP007 downloads files from the C2. [[11]](#11)|
## Detection
|Tool: CAPE|Mapping|APIs|
|---|---|---|
|[suspicious_mpcmdrun_use](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/windows_utilities.py)|Ingress Tool Transfer (E1105)|--|
|[network_document_file](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/network_payload_download.py)|Ingress Tool Transfer (E1105)|URLDownloadToFileW, HttpOpenRequestW, send, InternetCrackUrlW, InternetCrackUrlA, WSASend, URLDownloadToCacheFileW|
## References
<a name="1">[1]</a> https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/
<a name="2">[2]</a> https://www.mcafee.com/blogs/other-blogs/mcafee-labs/shamoon-attackers-employ-new-tool-kit-to-wipe-infected-systems/
<a name="3">[3]</a> https://unit42.paloaltonetworks.com/tracking-minidionis-cozycars-new-ride-is-related-to-seaduke
<a name="2">[2]</a> https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/
<a name="3">[3]</a> https://www.mcafee.com/blogs/other-blogs/mcafee-labs/shamoon-attackers-employ-new-tool-kit-to-wipe-infected-systems/
<a name="4">[4]</a> https://unit42.paloaltonetworks.com/tracking-minidionis-cozycars-new-ride-is-related-to-seaduke
<a name="5">[5]</a> https://securitynews.sonicwall.com/xmlpost/revisiting-vobfus-worm-mar-8-2013/
<a name="6">[6]</a> https://www.cisa.gov/uscert/ncas/analysis-reports/ar21-039b
<a name="7">[7]</a> https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/
<a name="8">[8]</a> https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader
<a name="9">[9]</a> https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/
<a name="10">[10]</a> https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/gamut-spambot-analysis/
<a name="11">[11]</a> https://citizenlab.ca/2016/04/between-hong-kong-and-burma/
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1104**|
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|**Related ATT&CK Technique**|[Multi-Stage Channels](https://attack.mitre.org/techniques/T1104/)|
Multi-Stage Channels
====================
Malware may create multiple stages for command and control, making detection more difficult.
**See ATT&CK:** [**Multi-Stage Channels**](https://attack.mitre.org/techniques/T1104/).
-13
View File
@@ -1,13 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1188**|
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|**Related ATT&CK Technique**|[Multi-hop Proxy](https://attack.mitre.org/techniques/T1188/)|
Multi-hop Proxy
===============
Malware may chain together multiple proxies to disguise the source of malicious C2 traffic.
In MBC, this behavior includes installing a multi-hop proxy, such as Tor.
**See ATT&CK:** [**Multi-hop Proxy**](https://attack.mitre.org/techniques/T1188/).
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1205**|
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control), [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion), [Persistence](https://github.com/MBCProject/mbc-markdown/tree/master/persistence)|
|**Related ATT&CK Technique**|[Port Knocking](https://attack.mitre.org/techniques/T1205/)|
Port Knocking
=============
Malware may hide open ports.
**See ATT&CK:** [**Port Knocking**](https://attack.mitre.org/techniques/T1205/).
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1219**|
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|**Related ATT&CK Technique**|[Remote Access Tools](https://attack.mitre.org/techniques/T1219/)|
Remote Access Tools
===================
Malware may use legitimate desktop support and remote access software to establish an interactive command and control channel to target systems.
**See ATT&CK:** [**Remote Access Tools**](https://attack.mitre.org/techniques/T1219/).
-24
View File
@@ -1,24 +0,0 @@
|||
|---------|------------------------|
|**ID**|**E1105**|
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control), [Lateral Movement](https://github.com/MBCProject/mbc-markdown/tree/master/lateral-movement), [Persistence](https://github.com/MBCProject/mbc-markdown/tree/master/persistence)|
|**Related ATT&CK Technique**|[Remote File Copy](https://attack.mitre.org/techniques/T1105/)|
Remote File Copy
================
Malware may copy files from one system to another.
Note that this behavior is separate from possible execution (installation) of the file, which is covered by the [Install Additional Program](https://github.com/MBCProject/mbc-markdown/blob/master/execution/install-prog.md) behavior.
**See ATT&CK:** [**Remote File Copy**](https://attack.mitre.org/techniques/T1105/).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|[**Poison-Ivy**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/poison-ivy.md)|2005|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[1]](#1)|
References
----------
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
-17
View File
@@ -1,17 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1071**|
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|**Related ATT&CK Technique**|[Standard Application Layer Protocol](https://attack.mitre.org/techniques/T1071/)|
Standard Application Layer Protocol
===================================
Malware may use a standard application layer protocol (e.g., HTTP) to blend with usual traffic.
**See ATT&CK:** [**Standard Application Layer Protocol**](https://attack.mitre.org/techniques/T1071/).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
@@ -1,21 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1032**|
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|**Related ATT&CK Technique**|[Standard Cryptographic Protocol](https://attack.mitre.org/techniques/T1032/)|
Standard Cryptographic Protocol
===============================
Malware may use a standard cryptographic protocol to conceal command and control traffic or other data.
**See ATT&CK:** [**Standard Cryptographic Protocol**](https://attack.mitre.org/techniques/T1032/).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|--------|-----------------------------|
|[**Poison-Ivy**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/poison-ivy.md)|2005|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[1]](#1)|
References
----------
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1095**|
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|**Related ATT&CK Technique**|[Standard Non-Application Layer Protocol](https://attack.mitre.org/techniques/T1095/)|
Standard Non-Application Layer Protocol
=======================================
Malware may use a standard non-application layer protocol (e.g., ICMP) because such protocols may be less commonly monitored, enabling communication to be hidden.
**See ATT&CK:** [**Standard Non-Application Layer Protocol**](https://attack.mitre.org/techniques/T1095/).
-22
View File
@@ -1,22 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1065**|
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control)|
|**Related ATT&CK Technique**|[Uncommonly Used Port](https://attack.mitre.org/techniques/T1065/)|
Uncommonly Used Port
====================
Malware may use an uncommon port to bypass poorly configured boundary controllers.
**See ATT&CK:** [**Uncommonly Used Port**](https://attack.mitre.org/techniques/T1065/).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|[**Poison-Ivy**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/poison-ivy.md)|2005|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[1]](#1)|
References
----------
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1102**|
|**Objective(s)**|[Command and Control](https://github.com/MBCProject/mbc-markdown/tree/master/command-and-control), [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion)|
|**Related ATT&CK Technique**|[Web Service](https://attack.mitre.org/techniques/T1102/)|
Web Service
===========
Malware may use existing external Web services for relaying C2 commands.
**See ATT&CK:** [**Web Service**](https://attack.mitre.org/techniques/T1102/).
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1171**|
|**Objective(s)**|[Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access)|
|**Related ATT&CK Technique**|[LLMNR/NBT-NS Poisoning](https://attack.mitre.org/techniques/T1171/)|
LLMNR/NBT-NS Poisoning
======================
Link-Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service (NBT-NS) are Microsoft Windows components that serve as alternate methods of host identification. Malware may spoof an authoritative source, poisoning the service.
**See ATT&CK:** [**LLMNR/NBT-NS Poisoning**](https://attack.mitre.org/techniques/T1171/).
+19 -16
View File
@@ -1,19 +1,22 @@
|||
|--|-----|
|**ID**|**M9005**|
<table>
<tr>
<td><b>ID</b></td>
<td><b>OB0005</b></td>
</tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>29 November 2022</b></td>
</tr>
</table>
# Credential Access
Behaviors to obtain credential access, allowing it or its underlying threat actor to assume control of an account, with the associated system and network permissions.
* **Access Sensitive Data or Credentials in Files** [E1409](https://github.com/MBCProject/mbc-markdown/blob/master/collection/access-sensitive-data.md)
* **Account Manipulation** [T1098](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/acct-manipulate.md)
* **Capture SMS Messages** [T1412](https://github.com/MBCProject/mbc-markdown/blob/master/collection/capture-sms.md)
* **Credential Dumping** [T1003](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/credential-dump.md)
* **Credentials in Files** [T1081](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/credentials-in-files.md)
* **Credentials in Registry** [T1214](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/credentials-in-registry.md)
* **Credentials in Web Browsers** [T1503](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/credentials-in-web-browsers.md)
* **Hooking** [E1179](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/hooking.md)
* **Input Capture** [E1056](https://github.com/MBCProject/mbc-markdown/blob/master/collection/input-capture.md)
* **LLMNR/NBT-NS Poisoning** [T1171](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/LLMNR-poison.md)
* **Network Sniffing** [T1040](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/network-sniff.md)
* **Private Keys** [T1145](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/private-keys.md)
Behaviors to obtain credential access, allowing it or its underlying threat actor to assume control of an account with the associated system and network permissions.
* **Cryptocurrency** [B0028](../collection/cryptocurrency.md)
* **Input Capture** [E1056](../collection/input-capture.md)
* **Keylogging** [F0002](../collection/keylogging.md)
* **Screen Capture** [E1113](../collection/screen-capture.md)
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1098**|
|**Objective(s)**|[Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access)|
|**Related ATT&CK Technique**|[Account Manipulation](https://attack.mitre.org/techniques/T1098/)|
Account Manipulation
====================
Malware may manipulate accounts to maintain access to credentials or permission levels.
**See ATT&CK:** [**Account Manipulation**](https://attack.mitre.org/techniques/T1098/).
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1003**|
|**Objective(s)**|[Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access)|
|**Related ATT&CK Technique**|[Credential Dumping](https://attack.mitre.org/techniques/T1003/)|
Credential Dumping
==================
Malware may obtain account login and password information.
**See ATT&CK:** [**Credential Dumping**](https://attack.mitre.org/techniques/T1003/).
-17
View File
@@ -1,17 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1081**|
|**Objective(s)**|[Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access)|
|**Related ATT&CK Technique**|[Credentials in Files](https://attack.mitre.org/techniques/T1081/)|
Credentials in Files
====================
Malware may search local file system and remote file shares for files containing passwords.
**See ATT&CK:** [**Credentials in Files**](https://attack.mitre.org/techniques/T1081/).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
@@ -1,17 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1214**|
|**Objective(s)**|[Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access)|
|**Related ATT&CK Technique**|[Credentials in Registry](https://attack.mitre.org/techniques/T1214/)|
Credentials in Registry
=======================
Malware may query the Registry looking for credentials and passwords.
**See ATT&CK:** [**Credentials in Registry**](https://attack.mitre.org/techniques/T1214/).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
@@ -1,17 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1503**|
|**Objective(s)**|[Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access)|
|**Related ATT&CK Technique**|[Credentials in Web Browsers](https://attack.mitre.org/techniques/T1503/)|
Credentials in Web Browsers
===========================
Malware may acquire credentials from web browsers by reading files specific to the target browser.
**See ATT&CK:** [**Credentials in Web Browsers**](https://attack.mitre.org/techniques/T1503/).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
-37
View File
@@ -1,37 +0,0 @@
|||
|------------------|------------------------|
|**ID**|**E1179**|
|**Objective(s)**|[Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis), [Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access), [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion), [Persistence](https://github.com/MBCProject/mbc-markdown/tree/master/persistence), [Privilege Escalation](https://github.com/MBCProject/mbc-markdown/tree/master/privilege-escalation)|
|**Related ATT&CK Technique**|[Hooking](https://attack.mitre.org/techniques/T1179/)|
Hooking
=======
Malware alters API behavior or redirects execution to a malicious API version for a variety of purposes. Malware may use hooking to load and execute code within the context of another process, hiding execution and gaining elevated privileges and access to the process's memory. Methods related to anti-behavioral analysis are below. For example, hooking can be used to prevent memory dumps - see also [Memory Dump Obstruction](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/memory-dump-obstruct.md).
For discussion related to the Credential Access, Persistence, and Privilege Escalation objectives, see ATT&CK: [**Hooking**](https://attack.mitre.org/techniques/T1179/).
Note that in MBC, but not in ATT&CK, Hooking is also associated with the [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion) and [Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-markdown/tree/master/anti-behavioral-analysis) objectives.
Methods
-------
* **Patch MmGetPhysicalMemoryRanges**: Patching this function to always return NULL prevents drivers from getting information about the physical address space layout, preventing memory dumps. [[1]](#1)
* **Hook memory mapping APIs**: Prevents memory dumps by preventing mapping of memory into the kernel's virtual address space. [[1]](#1)
* **Hook procedures**: Intercepts and executes designated code in response to events such as messages, keystrokes, and mouse inputs. [[3]](#3)
* **Import Address Hooking (IAT) Hooking**: uses modifications to a process's IAT where pointers to imported API functions are stored.
* **Inline Hooking**: overwrites the first bytes in an API function to redirect code flow.
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|**Kronos**|June 2014 |Kronos hooks the API of processes to prevent detection. [[2]](#2)|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
References
----------
<a name="1">[1]</a> J. Stuttgen, M. Cohen, Anti-forensic resilient memory acquisition, www.dfrws.org/sites/default/files/session-files/paper-anti-forensic_resilient_memory_acquisition.pdf
<a name="2">[2]</a> https://blog.malwarebytes.com/cybercrime/2017/08/inside-kronos-malware/
<a name="3">[3]</a> https://docs.microsoft.com/en-us/windows/win32/winmsg/about-hooks?redirectedfrom=MSDN#hook-procedures
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1145**|
|**Objective(s)**|[Credential Access](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access)|
|**Related ATT&CK Technique**|[Private Keys](https://attack.mitre.org/techniques/T1145/)|
Private Keys
============
Malware may gather private keys from compromised systems.
**See ATT&CK:** [**Private Keys**](https://attack.mitre.org/techniques/T1145/).
+36 -53
View File
@@ -1,55 +1,38 @@
|||
|--|-----|
|**ID**|**M9006**|
<table>
<tr>
<td><b>ID</b></td>
<td><b>OB0006</b></td>
</tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>8 May 2023</b></td>
</tr>
</table>
# Defense Evasion #
Behaviors that evade detection or avoid other defenses.
* **Access Token Manipulation** [T1134](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/access-token.md)
* **Alternative Installation Location** [M0027](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/alter-install-location.md)
* **Application Discovery** [T1418](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/app-discover.md)
* **Binary Padding** [T1009](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/binary-pad.md)
* **BITS Jobs** [T1197](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/bits-jobs.md)
* **Boot Sector Modification** [M0028](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/boot-sector-mod.md)
* **Bypass User Account Control** [T1088](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/bypass-user-acct-cntl.md)
* **Code Signing** [T1116](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/code-signing.md)
* **Component Object Model Hijacking** [T1122](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/component-hijack.md)
* **Configuration Modification** [E1478](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/config-mod.md)
* **Covert Location** [M0040](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/convert-location.md)
* **DCShadow** [T1207](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/dcshadow.md)
* **Deobfuscate/Decode Files or Information** [T1140](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/deobfuscate-files.md)
* **Disabling Security Tools** [E1089](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/disable-security-tools.md)
* **DLL Search Order Hijacking** [T1038](https://github.com/MBCProject/mbc-markdown/blob/master/privilege-escalation/dll-search-order-hijack.md)
* **Execution Guardrails** [E1480](https://github.com/MBCProject/mbc-markdown/blob/master/anti-behavioral-analysis/execution-guardrails.md)
* **Exploitation for Defense Evasion** [T1211](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/exploit-for-defense.md)
* **File Deletion** [E1107](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/file-deletion.md)
* **File Permissions Modification** [T1222](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/file-permission-mod.md)
* **File System Logical Offsets** [T1006](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/file-sys-logical-offset.md)
* **Hidden Files and Directories** [E1158](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/hidden-files.md)
* **Hidden Window** [T1143](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/hidden-window.md)
* **HISTCONTROL** [T1148](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/histcontrol.md)
* **Hooking** [E1179](https://github.com/MBCProject/mbc-markdown/blob/master/credential-access/hooking.md)
* **Image File Execution Options Injection** [T1183](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/image-file-exe-opt-inj.md)
* **Indicator Blocking** [E1054](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/indicator-blocking.md)
* **Indicator Removal on Host** [T1070](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/indicator-remove-host.md)
* **Indirect Command Execution** [T1202](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/indirect-command.md)
* **Install Root Certificate** [T1130](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/install-root-cert.md)
* **Masquerading** [T1036](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/masquerading.md)
* **Modify Registry** [E1112](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/modify-reg.md)
* **Modify Trusted Execution Environment** [T1399](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/mod-trust-exe-environ.md)
* **NTFS File Attributes** [T1096](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/ntfs-file-attr.md)
* **Obfuscated Files or Information** [E1027](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/obfuscate-files.md)
* **Parent PID Spoofing** [T1502](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/parent-pid-spoof.md)
* **Polymorphic Code** [M0029](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/polymorphic-code.md)
* **Port Knocking** [T1205](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/port-knocking.md)
* **Process Hollowing** [T1093](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/process-hollow.md)
* **Process Injection** [E1055](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/process-inject.md)
* **Redundant Access** [T1008](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/redundant-access.md)
* **Regsvr32** [T1117](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/regsvr32.md)
* **Rundll32** [T1085](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/rundll32.md)
* **Rootkit Behavior** [E1014](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/rootkit-behavior.md)
* **Scripting** [T1064](https://github.com/MBCProject/mbc-markdown/blob/master/execution/scripting.md)
* **Software Packing** [E1045](https://github.com/MBCProject/mbc-markdown/blob/master/anti-static-analysis/software-packing.md)
* **Timestomp** [T1099](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/timestomp.md)
* **Virtualization/Sandbox Evasion** [T1497](https://github.com/MBCProject/mbc-markdown/blob/master/defense-evasion/virtualization-sandbox-evade.md)
* **Web Service** [T1102](https://github.com/MBCProject/mbc-markdown/blob/master/command-and-control/web-service.md)
# Defense Evasion
Behaviors that enable malware to evade detection.
* **Alternative Installation Location** [B0027](../defense-evasion/alternative-installation-location.md)
* **Bootkit** [F0013](../defense-evasion/bootkit.md)
* **Bypass DEP** [B0037](../defense-evasion/bypass-data-execution-prevention.md)
* **Component Firmware** [F0009](../persistence/component-firmware.md)
* **Conditional Execution** [B0025](../execution/conditional-execution.md)
* **Covert Location** [B0040](../defense-evasion/covert-location.md)
* **Disable or Evade Security Tools** [F0004](../defense-evasion/disable-or-evade-security-tools.md)
* **Hide Artifacts** [E1564](../defense-evasion/hide-artifacts.md)
* **Hidden Files and Directories** [F0005](../defense-evasion/hidden-files-and-directories.md)
* **Hijack Execution Flow** [F0015](../defense-evasion/hijack-execution-flow.md)
* **Indicator Blocking** [F0006](../defense-evasion/indicator-blocking.md)
* **Install Insecure or Malicious Configuration** [B0047](../defense-evasion/install-insecure-or-malicious-configuration.md)
* **Modify Registry** [E1112](../defense-evasion/modify-registry.md)
* **Obfuscated Files or Information** [E1027](../defense-evasion/obfuscated-files-or-information.md)
* **Polymorphic Code** [B0029](../defense-evasion/polymorphic-code.md)
* **Process Injection** [E1055](../defense-evasion/process-injection.md)
* **Rootkit** [E1014](../defense-evasion/rootkit.md)
* **Self Deletion** [F0007](../defense-evasion/self-deletion.md)
* **Software Packing** [F0001](../anti-static-analysis/software-packing.md)
-12
View File
@@ -1,12 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1134**|
|**Objective(s)**| [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion), [Privilege Escalation](https://github.com/MBCProject/mbc-markdown/tree/master/privilege-escalation)|
|**Related ATT&CK Technique**|[Access Token Manipulation](https://attack.mitre.org/techniques/T1134)|
Access Token Manipulation
=========================
Malware manipulates access tokens to make a running process appear as thought it belongs to someone other than the user who started the process.
See ATT&CK: [**Access Token Manipulation**](https://attack.mitre.org/techniques/T1134).
-25
View File
@@ -1,25 +0,0 @@
|||
|---------|------------------------|
|**ID**|**M0027**|
|**Objective(s)**| [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion)|
|**Related ATT&CK Technique**|None|
Alternative Installation Location
=================================
Malware may install itself not as a file on the hard drive. [[1]](#1)
Methods
-------
* **Fileless Malware**: Stores itself in memory.
* **Registry Install**: Stores itself in the Windows registry.
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|--------|-----------------------------|
|[**Kovter**](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/kovter.md)|2016|Stores malware files in the Registry instead of the hard drive. [[1]](#1)|
References
----------
<a name="1">[1]</a> https://www.bleepingcomputer.com/virus-removal/remove-kovter-trojan
@@ -0,0 +1,62 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>B0027</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../defense-evasion">Defense Evasion</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>None</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.0</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>17 August 2023</b></td>
</tr>
</table>
# Alternative Installation Location
Malware may install itself in areas other than the hard drive [[1]](#1). Other possible locations include the BIOS/Unified Extensible Firmware Interface (UEFI) firmware, which is embedded on a chip on the motherboard, and the graphics processor unit (GPU), where malware is stored in its memory buffer (also known as VRAM) [[2]](#2)[[3]](#3). Volatile memory is a third possibility and when installation occurs here, malware is known as “fileless.”
While the definition of fileless malware can be ambiguous, here it represents malware that lives in memory only, not on disk, and it does not preclude fileless malware from using files on the system. Microsoft and Zeltser have addressed this ambiguity by providing more context in [[4]](#4) and [[5]](#5), respectively.
## Methods
|Name|ID|Description|
|---|---|---|
|**Fileless Malware**|B0027.001|Stores itself in memory. This method is related to Unprotect technique U1205 and ATT&CK sub-technique Obfuscated Files or Information: Fileless Storage [T1027.011](https://attack.mitre.org/techniques/T1027/011/). |
|**Registry Install**|B0027.002|Stores itself in the Windows registry.|
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**Kovter**](../xample-malware/kovter.md)|2016|B0027.002|Kovter stores malware files in the Registry instead of on the hard drive. [[1]](#1)|
|[**SYNful Knock**](../xample-malware/synful-knock.md)|2015|B0027.001|100 memory-resident modules can be installed. [[6]](#6)|
## References
<a name="1">[1]</a> https://labs.vipre.com/analysis-of-kovter-a-very-clever-piece-of-malware/#:~:text=Kovter%20copies%20the%20fileless%20persistence,written%20on%20to%20the%20filesystem.
<a name="2">[2]</a> J. Glazova,"CosmicStrand: A UEFI Rootkit," Kaspersky, blog, 26 Jul. 2022. [Online]. Available: https://usa.kaspersky.com/blog/cosmicstrand-uefi-rootkit/26807/.
<a name="3">[3]</a> I. Ilascu,"Cybercriminal sells tool to hide malware in AMD, NVIDIA GPUs," bleepingcomputer.com, 31 Aug. 2021. [Online]. Available: https://www.bleepingcomputer.com/news/security/cybercriminal-sells-tool-to-hide-malware-in-amd-nvidia-gpus/.
<a name="4">[4]</a> Contributors: D. Simpson, A. Lobo, A. Jupudi, D. Vangel, and C. Davis,"Fileless threats," learn.microsoft.com, 02 June 2023. [Online]. Available: https://learn.microsoft.com/en-us/microsoft-365/security/intelligence/fileless-threats?view=o365-worldwide.
<a name="5">[5]</a> L. Zeltser,"The History of Fileless Malware Looking Beyond the Buzzword," zeltser.com, blog, 12 Oct. 2018. [Online]. Available: https://zeltser.com/fileless-malware-beyond-buzzword/.
<a name="6">[6]</a> B. HAU, T. LEE, and J. HOMAN,"SYNful Knock - A Cisco router implant - Part I," Mandiant.com, 15 Sept. 2015. [Online]. Available: https://www.mandiant.com/resources/synful-knock-acis.
-12
View File
@@ -1,12 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1009**|
|**Objective(s)**| [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion)|
|**Related ATT&CK Technique**|[Binary Padding](https://attack.mitre.org/techniques/T1009)|
Binary Padding
==============
Malware is padded to increase its size beyond what security tools can handle or to change its hash.
See ATT&CK: [**Binary Padding**](https://attack.mitre.org/techniques/T1009).
-12
View File
@@ -1,12 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1197**|
|**Objective(s)**| [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion), [Persistence](https://github.com/MBCProject/mbc-markdown/tree/master/persistence)|
|**Related ATT&CK Technique**|[BITS Jobs](https://attack.mitre.org/techniques/T1197)|
BITS Jobs
=========
Malware may abuse Windows Background Intelligent Transfer Service (BITS) to download and/or execute malicious code.
See ATT&CK: [**BITS Jobs**](https://attack.mitre.org/techniques/T1197).
-22
View File
@@ -1,22 +0,0 @@
|||
|---------|------------------------|
|**ID**|**M0028**|
|**Objective(s)**|[Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion), [Persistence](https://github.com/MBCProject/mbc-markdown/tree/master/persistence)|
|**Related ATT&CK Technique**|[Bootkit](https://attack.mitre.org/techniques/T1067/)|
Boot Sector Modification
========================
The boot sectors of a hard drive are modified (e.g., Master Boot Record (MBR)). ATT&CK associates bootkits with the Persistence. See ATT&CK: [**Bootkit**](https://attack.mitre.org/techniques/T1067/).
The MBC also associates the Bootkit behavior with Defense Evasion because the malware may execute before or external to the system's kernel or hypervisor (e.g., through the BIOS), making it more difficult to detect.
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**Mebromi**](https://github.com/MBCProject/mbc-markdown/blob/master/xample-malware/mebromi.md)|2011|An MBR bootkit and a BIOS bootkit targeting Award BIOS. [[1]](#1)|
References
----------
<a name="1">[1]</a> https://www.webroot.com/blog/2011/09/13/mebromi-the-first-bios-rootkit-in-the-wild/
+58
View File
@@ -0,0 +1,58 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>F0013</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../defense-evasion">Defense Evasion</a>, <a href="../persistence">Persistence</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>Pre-OS Boot: Bootkit (<a href="https://attack.mitre.org/techniques/T1542/003">T1542.003</a>)</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>1 August 2019</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>28 April 2024</b></td>
</tr>
</table>
# Bootkit
The boot sectors of a hard drive are modified (e.g., Master Boot Record (MBR)). ATT&CK associates bootkits with the Persistence. See ATT&CK: **Pre-OS Boot: Bootkit ([T1542.003](https://attack.mitre.org/techniques/T1542/003/))**.
The MBC also associates the Bootkit behavior with Defense Evasion because the malware may execute before or external to the system's kernel or hypervisor (e.g., through the BIOS), making it more difficult to detect. (As of 2020, ATT&CK also associates the technique with Persistence.)
## Use in Malware
|Name|Date|Method|Description|
|---|---|---|---|
|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|The malware is an MBR bootkit and a BIOS bootkit targeting Award BIOS. [[1]](#1)|
|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|The malware can implement malicious code into firmware, allowing read, write, and/or erasure of the UEFI/BIOS firmware. [[2]](#24)|
## Detection
|Tool: CAPE|Mapping|APIs|
|---|---|---|
|[accesses_primary_patition](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/bootkit.py)|Bootkit (F0013)|--|
|[bootkit](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/bootkit.py)|Bootkit (F0013)|NtSetInformationFile, NtClose, DeviceIoControl, NtCreateFile, NtDuplicateObject, NtOpenFile, NtWriteFile, NtDeviceIoControlFile|
|[direct_hdd_access](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/bootkit.py)|Bootkit (F0013)|--|
|[enumerates_physical_drives](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/bootkit.py)|Bootkit (F0013)|--|
|[physical_drive_access](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/bootkit.py)|Bootkit (F0013)|--|
|[suspicious_ioctl_scsipassthough](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/bootkit.py)|Bootkit (F0013)|DeviceIoControl, NtDeviceIoControlFile|
## References
<a name="1">[1]</a> https://www.webroot.com/blog/2011/09/13/mebromi-the-first-bios-rootkit-in-the-wild/
<a name="2">[2]</a> https://eclypsium.com/wp-content/uploads/TrickBot-Now-Offers-TrickBoot-Persist-Brick-Profit.pdf
@@ -0,0 +1,47 @@
<table>
<tr>
<td><b>ID</b></td>
<td><b>B0037</b></td>
</tr>
<tr>
<td><b>Objective(s)</b></td>
<td><b><a href="../defense-evasion">Defense Evasion</a></b></td>
</tr>
<tr>
<td><b>Related ATT&CK Techniques</b></td>
<td><b>None</b></td>
</tr>
<tr>
<td><b>Version</b></td>
<td><b>2.2</b></td>
</tr>
<tr>
<td><b>Created</b></td>
<td><b>14 August 2020</b></td>
</tr>
<tr>
<td><b>Last Modified</b></td>
<td><b>28 April 2024</b></td>
</tr>
</table>
# Bypass Data Execution Prevention
Malware may bypass Data Execution Prevention (DEP).
## Methods
|Name|ID|Description|
|---|---|---|
|**ROP Chains**|B0037.001|Return-Oriented Programming can be used to bypass DEP. It can also be used to bypass code signing. [[1]](#1)|
## Detection
|Tool: CAPE|Mapping|APIs|
|---|---|---|
|[dep_bypass](https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/dep_bypass.py)|Bypass Data Execution Prevention (B0037)|VirtualProtectEx, NtProtectVirtualMemory|
## References
<a name="1">[1]</a> https://medium.com/cybersecurityservices/dep-bypass-using-rop-chains-garima-chopra-e8b3361e50ce
-12
View File
@@ -1,12 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1088**|
|**Objective(s)**| [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion), [Privilege Escalation](https://github.com/MBCProject/mbc-markdown/tree/master/privilege-escalation)|
|**Related ATT&CK Technique**|[Bypass User Account Control](https://attack.mitre.org/techniques/T1088)|
Bypass User Account Control
===========================
Malware bypasses Windows User Account Control.
See ATT&CK: [**Bypass User Account Control**](https://attack.mitre.org/techniques/T1088).

Some files were not shown because too many files have changed in this diff Show More