mirror of
https://github.com/MBCProject/mbc-markdown
synced 2026-06-08 11:36:36 +00:00
Compare commits
135 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| e5b31bdd5b | |||
| 949209d597 | |||
| 1e42433220 | |||
| 00afb1d6b0 | |||
| 344da4eaea | |||
| 9937ebd631 | |||
| fa9f508370 | |||
| d5791ce5fe | |||
| a6096cb8df | |||
| 2f6093b0b9 | |||
| 503105dcd0 | |||
| dbf98ecfb7 | |||
| 5fc453ab53 | |||
| 9d267f438a | |||
| 389c9023ef | |||
| 99e472ad90 | |||
| 69055744bf | |||
| b3096ed9f2 | |||
| a1f14b90a8 | |||
| d107a3d89e | |||
| e677acfe93 | |||
| 5392791edc | |||
| 4c3cc0125f | |||
| 999696ad26 | |||
| 3f897ca2bb | |||
| 01df10e1cb | |||
| 580fadedcf | |||
| b3a7a36a27 | |||
| 9b8672cfe4 | |||
| 7dd6670274 | |||
| da26628e86 | |||
| 1410cd6076 | |||
| 22ac38a876 | |||
| 643fefd7b3 | |||
| 7168b1040a | |||
| 9d2dc7d065 | |||
| ff05de6422 | |||
| 804b913cb4 | |||
| d9e84725bf | |||
| 7c70e41d7b | |||
| a2b581728a | |||
| 7c769c8e3c | |||
| e5b8278174 | |||
| 61b5dfb051 | |||
| 950cfca2cc | |||
| 4d7c7f6dad | |||
| 79b42cba12 | |||
| 2a9bcd3ab5 | |||
| 1ed65e2692 | |||
| ddfc129ba1 | |||
| 40db622ee7 | |||
| 017d263ebb | |||
| 3e16f10c35 | |||
| 6d560ed105 | |||
| ac3e8b6859 | |||
| c2500c8f3f | |||
| 9932beb512 | |||
| 0ed931a0d8 | |||
| 34c87921d5 | |||
| f0f0235353 | |||
| 5e3a5cedf7 | |||
| a5a31f2f63 | |||
| ff57a87f7f | |||
| 24dca9d9c9 | |||
| 30f31bd245 | |||
| 7fe9a48518 | |||
| d8ba02ab00 | |||
| cd7b66d5b9 | |||
| c544962577 | |||
| a13dceeb1d | |||
| 19be37cdd4 | |||
| 95b1f2e854 | |||
| 42520d3108 | |||
| a1efa1509c | |||
| 98b2fe9c8a | |||
| a7fe0c17eb | |||
| a6624a0eef | |||
| 10d4eaf12d | |||
| c5b4a95793 | |||
| 3e49062c21 | |||
| b2502e69eb | |||
| bf7da3f24f | |||
| b934db3501 | |||
| ff5678fddd | |||
| a9b6502475 | |||
| b921f533e3 | |||
| 64864b7c86 | |||
| e0b0e039c7 | |||
| c8114ef336 | |||
| 486c764c1b | |||
| a4e9e9ec12 | |||
| a040511b06 | |||
| 9a4629884f | |||
| 9463964215 | |||
| 34e355110a | |||
| e07e00f4d4 | |||
| 48a1f3615d | |||
| 52b3e23281 | |||
| 2a6cb7a397 | |||
| cbceef7c44 | |||
| 0966565798 | |||
| f71ff004fa | |||
| 9e473ed965 | |||
| 0db4607e2f | |||
| 286c0106c4 | |||
| 7287afb877 | |||
| f6d2f58b7c | |||
| fb9882c0b9 | |||
| b6b1a12db1 | |||
| 9791a68096 | |||
| 975c21c7bc | |||
| 5a57d01e4e | |||
| 8092d86ae3 | |||
| ff62030726 | |||
| e1b1756c93 | |||
| 4e6d8a44aa | |||
| ce6453a692 | |||
| c648c032a3 | |||
| cb553d3681 | |||
| 40ddc39e3c | |||
| 556c01f636 | |||
| 67c9b4d30c | |||
| 08b41c057f | |||
| 2524861df3 | |||
| 2f87c60a47 | |||
| dcdc71c325 | |||
| 7375cf16c6 | |||
| 8b97ca31cd | |||
| af0350ec08 | |||
| f97bfd8794 | |||
| af8df39833 | |||
| ee207f35a3 | |||
| 6449769ac2 | |||
| 077d21c73c | |||
| 813557e591 |
@@ -1,5 +1,5 @@
|
||||
# <a name="mbc"></a>Malware Behavior Catalog v2.2 #
|
||||
The Malware Behavior Catalog (MBC) is a catalog of malware objectives and behaviors, created to support malware analysis-oriented use cases, such as labeling, similarity analysis, and standardized reporting. Please see the [FAQ](./yfaq/README.md) page for answers to common questions.
|
||||
The Malware Behavior Catalog (MBC) is a catalog of malware objectives and behaviors, created to support malware analysis-oriented use cases, such as labeling, similarity analysis, and standardized reporting. Please see the [FAQ](./yfaq/README.md) page for answers to common questions, and read the [newsletters](./ynewsletters/README.md) for information on the most recent MBC updates and activity.
|
||||
|
||||
Check out the MBC presentations:
|
||||
|
||||
@@ -9,7 +9,7 @@ Check out the MBC presentations:
|
||||
We've also mapped MBC (and ATT&CK) to two open-source malware analysis tools:
|
||||
|
||||
* [Cuckoo community signatures](https://github.com/MBCProject/community)
|
||||
* [capa rules](https://github.com/fireeye/capa-rules)
|
||||
* [capa rules](https://github.com/fireeye/capa-rules) - see the [mapping distribution](./capa.md)
|
||||
|
||||
To join the **MBC mailing list**, please send a request to mbc@mitre.org.
|
||||
|
||||
@@ -28,7 +28,7 @@ Note that a method cannot be used without a behavior.
|
||||
Some malware behaviors are low-level, support many objectives and other behaviors, and aren't necessarily malicious. For example, a TCP socket may be created, or a string may be checked for some condition. Because such behaviors are often noted in malware analysis, they are captured in MBC. See [Micro-behaviors](./micro-behaviors/README.md) for details.
|
||||
|
||||
### <a name="ids"></a>Identifiers ###
|
||||
As shown below, the letter of an identifier relays information about a behavior. Note that letters used in MBC 2.0 are changed from previous versions.
|
||||
As shown below, the letter of an identifier relays information about a behavior. Note that letters used in MBC v2 are changed from MBC v1.
|
||||
|
||||
|**Letter**|**Example**|**Description**|
|
||||
|---|---|---|
|
||||
@@ -45,42 +45,100 @@ Two letters of an identifier relay information about an objective.
|
||||
|**OB**|*OB0001*|An MBC objective.|
|
||||
|**OC**|*OC0003*|An MBC micro-objective.|
|
||||
|
||||
Identifiers of methods are formatted in the same say as ATT&CK sub-techniques. If MBC defines a new method for an existing ATT&CK technique, the identifier is changed from "T" to "E" and an "m" identifier is added (e.g., a method added to T1234 would be denoted *E1234.m01* and is different than *T1234.001*, although both refer to the T1234 ATT&CK technique). Method identifiers of "B", "C", and "F" behaviors are defined without the "m" (e.g., *B0008.009*; *C0005.002*; *F0001.005*).
|
||||
Identifiers of methods are formatted in the same way as ATT&CK sub-techniques. If MBC defines a new method for an existing ATT&CK technique, the identifier is changed from "T" to "E" and an "m" identifier is added (e.g., a method added to T1234 would be denoted *E1234.m01* and is different than *T1234.001*, although both refer to the T1234 ATT&CK technique). Method identifiers of "B", "C", and "F" behaviors are defined without the "m" (e.g., *B0008.009*; *C0005.002*; *F0001.005*).
|
||||
|
||||
When two or more MBC behaviors refine the same ATT&CK technique, each is given an MBC identifier and each references the ATT&CK identifier. When a new ATT&CK technique is defined *after* an MBC behavior has been defined, the preexisting MBC identifier is preserved and the new ATT&CK identifier is referenced.
|
||||
|
||||
In cases where an MBC behavior enhances a technique/sub-technique that is defined in both ATT&CK Mobile and Enterprise, the "E" identifier used in MBC corresponds to the Enterprise identifier. For example, the Obfuscated Files or Information technique has identifier <a href="https://attack.mitre.org/techniques/T1027/">T1027</a> in Enterprise, identifier <a href="https://attack.mitre.org/techniques/T1406/">T1406</a> in Mobile, and identifier <a href="./defense-evasion/obfuscated-files-or-information.md">E1027</a> in MBC.
|
||||
|
||||
### Canonical Representation ###
|
||||
The canonical representation for MBC content is **OBJECTIVE::Behavior::Method**. For example, *ANTI-BEHAVIORAL ANALYSIS::Debugger Detection::Process Environment Block*.
|
||||
|
||||
Objectives and behaviors can be used alone, but a method *must* be associated with a behavior.
|
||||
|
||||
### Example Malware ###
|
||||
The MBC also contains a collection of [example malware](./xample-malware/README.md) that are characterized with malware behaviors.
|
||||
### Navigator View ###
|
||||
This visual representation of the MBC Matrix is based on the ATT&CK Navigator. Two views are available:
|
||||
|
||||
* <a href="https://raw.githubusercontent.com/MBCProject/mbc-markdown/master/yfaq/mbc_matrix_with_ids.svg" target="_blank">Matrix with identifiers</a>
|
||||
* <a href="https://raw.githubusercontent.com/MBCProject/mbc-markdown/master/yfaq/mbc_matrix_without_ids.svg" target="_blank">Matrix without identifiers</a>
|
||||
|
||||
### Malware Corpus ###
|
||||
The MBC contains a [malware corpus](./xample-malware/README.md) where each malware entry is decomposed into behaviors that are mapped to ATT&CK and MBC. The mappings are based on open source malware analysis reports.
|
||||
|
||||
## Micro-behavior Objectives ##
|
||||
[Micro-behaviors](./micro-behaviors/README.md) and their associated objectives are under development.
|
||||
|
||||
## Malware Objective Descriptions ##
|
||||
Malware objectives are defined in the table below. Follow the links to view associated behaviors. A visual representation of the MBC Matrix is also available (opens in a new window). There is another version under [FAQ](./yfaq/) with behavior ids.
|
||||
|
||||
<img src="https://raw.githubusercontent.com/MBCProject/mbc-markdown/master/yfaq/mbc_matrix_without_ids.svg" alt="mbc matrix without ids">
|
||||
Malware objectives are defined in the table below. Follow the links to view associated behaviors.
|
||||
|
||||
|**Objective**|**Description**|
|
||||
|---|---|
|
||||
|[**Anti-Behavioral Analysis**](./anti-behavioral-analysis/README.md)|Malware aims to prevent, obstruct, or evade behavioral analysis done in a sandbox, debugger, etc.|
|
||||
|[**Anti-Static Analysis**](./anti-static-analysis/README.md)|Malware aims to prevent static analysis or make it more difficult. Simpler static analysis identifies features such as embedded strings, executable header information, hash values, and file metadata. More involved static analysis involves the disassembly of the binary code.|
|
||||
|[**Collection**](./collection/README.md)|Malware aims to identify and gather information, such as sensitive files, from a target network prior to exfiltration. This objective includes locations on a system or network where the malware may look for information to exfiltrate.|
|
||||
|[**Command and Control**](./command-and-control/README.md)|Malware aims to communicate (receive and/or execute remotely submitted commands) with controlling or controlled systems within a target network (C2 servers, bots, etc.).|
|
||||
|[**Credential Access**](./credential-access/README.md)|Malware aims to obtain credential access, allowing it or its underlying threat actor to assume control of an account, with the associated system and network permissions.|
|
||||
|[**Defense Evasion**](./defense-evasion/README.md)|Malware aims to evade detection or avoid other cybersecurity defenses.|
|
||||
|[**Discovery**](./discovery/README.md)|Malware aims to gain knowledge about the system and internal network.|
|
||||
|[**Execution**](./execution/README.md)|Malware aims to execute its code on a system to achieve a variety of goals.|
|
||||
|[**Exfiltration**](./exfiltration/README.md)|Malware aims to steal data from the system on which it executes. This includes stored data (e.g., files) as well as data input into applications (e.g., web browser).|
|
||||
|[**Impact**](./impact/README.md)|Malware aims to achieve its mission of manipulating, interrupting, or destroying systems and data.|
|
||||
|[**Lateral Movement**](./lateral-movement/README.md)|Malware aims to propagate through the infection of a system or is able to infect a file after executing on a system. The malware may infect actively (e.g., gain access to a machine directly) or passively (e.g., send malicious email).|
|
||||
|[**Persistence**](./persistence/README.md)|Malware aims to remain on a system regardless of system events.|
|
||||
|[**Privilege Escalation**](./privilege-escalation/README.md)|Malware aims to obtain a higher level of privilege for execution.|
|
||||
|[**Anti-Behavioral Analysis**](./anti-behavioral-analysis/README.md)|Malware aims to prevent, obstruct, or evade behavioral analysis, such as analysis done using a sandbox or debugger.|
|
||||
|[**Anti-Static Analysis**](./anti-static-analysis/README.md)|Malware aims to prevent static analysis or make it more difficult.|
|
||||
|[**Collection**](./collection/README.md)|Malware aims to identify and gather information from a machine or network.|
|
||||
|[**Command and Control**](./command-and-control/README.md)|Malware aims to communicate with compromised systems to control them.|
|
||||
|[**Credential Access**](./credential-access/README.md)|Malware aims to steal account names and passwords.|
|
||||
|[**Defense Evasion**](./defense-evasion/README.md)|Malware aims to evade detection.|
|
||||
|[**Discovery**](./discovery/README.md)|Malware aims to gain knowledge about the environment.|
|
||||
|[**Execution**](./execution/README.md)|Malware aims to execute code on a system.|
|
||||
|[**Exfiltration**](./exfiltration/README.md)|Malware aims to steal data.|
|
||||
|[**Impact**](./impact/README.md)|Malware aims to manipulate, interrupt, or destroy systems or data.|
|
||||
|[**Lateral Movement**](./lateral-movement/README.md)|Malware aims to propagate or otherwise move through an environment. Lateral movement may be active, happening via direct machine access, or may be passive (for example, done via malicious email).|
|
||||
|[**Persistence**](./persistence/README.md)|Malware aims to remain on a system.|
|
||||
|[**Privilege Escalation**](./privilege-escalation/README.md)|Malware aims to obtain higher level permissions.|
|
||||
|
||||
## MBC Behaviors ##
|
||||
The table below lists MBC behaviors and related ATT&CK techniques. In most cases, related ATT&CK techniques were defined *after* the MBC behavior was defined.
|
||||
|
||||
**Copyright 2021 The MITRE Corporation. [Terms of Use](./tou.md)**
|
||||
|**ID**|**Objective(s)**|**Behavior**|**Related ATT&CK Technique**|
|
||||
|---|---|---|---|
|
||||
|**B0001**|ANTI-BEHAVIORAL ANALYSIS|**Debugger Detection**|*none*|
|
||||
|**B0002**|ANTI-BEHAVIORAL ANALYSIS|**Debugger Evasion**|Debugger Evasion ([T1622](https://attack.mitre.org/techniques/T1622))|
|
||||
|**B0003**|ANTI-BEHAVIORAL ANALYSIS|**Dynamic Analysis Evasion**|Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/techniques/T1497),[T1633](https://attack.mitre.org/techniques/T1633))|
|
||||
|**B0004**|ANTI-BEHAVIORAL|**Emulator Detection**|*none*|
|
||||
|**B0005**|ANTI-BEHAVIORAL|**Emulator Evasion**|*none*|
|
||||
|**B0006**|ANTI-BEHAVIORAL|**Memory Dump Evasion**|*none*|
|
||||
|**B0007**|ANTI-BEHAVIORAL|**Sandbox Detection**|Virtualization/Sandbox Evasion: System Checks ([T1497.001](https://attack.mitre.org/techniques/T1497/001),[T1633.001](https://attack.mitre.org/techniques/T1633/001)); Virtualization/Sandbox Evasion: User Activity Based Checks ([T1497.002](https://attack.mitre.org/techniques/T1497/002))|
|
||||
|**B0008**|ANTI-BEHAVIORAL ANALYSIS, ANTI-STATIC ANALYSIS|**Executable Code Virtualization**|*none*|
|
||||
|**B0009**|ANTI-BEHAVIORAL ANALYSIS|**Virtual Machine Detection**|Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/techniques/T1497),[T1633](https://attack.mitre.org/techniques/T1633))|
|
||||
|**B0010**|ANTI-STATIC ANALYSIS|**Call Graph Generation Evasion**|*none*|
|
||||
|**B0011**|EXECUTION|**Remote Commands**|Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/techniques/T1497),[T1633](https://attack.mitre.org/techniques/T1633))|
|
||||
|**B0012**|ANTI-STATIC ANALYSIS|**Disassembler Evasion**|*none*|
|
||||
|**B0013**|DISCOVERY|**Analysis Tool Discovery**|*none*|
|
||||
|**B0014**|DISCOVERY|**SMTP Connection Discovery**|*none*|
|
||||
|**B0015**|*not defined*|---|---|
|
||||
|**B0016**|IMPACT|**Compromise Data Integrity**|Data Manipulation: Stored Data Manipulation ([T1565.001](https://attack.mitre.org/techniques/T1565/001))|
|
||||
|**B0017**|IMPACT|**Destroy Hardware**|*none*|
|
||||
|**B0018**|IMPACT|**Resource Hijacking**|Resource Hijacking ([T1496](https://attack.mitre.org/techniques/T1496))|
|
||||
|**B0019**|IMPACT|**Manipulate Network Traffic**|Data Manipulation: Transmitted Data Manipulation ([T1565.002](https://attack.mitre.org/techniques/T1565/002))|
|
||||
|**B0020**|EXECUTION, LATERAL MOVEMENT|**Send Email**|Phishing ([T1566](https://attack.mitre.org/techniques/T1566))|
|
||||
|**B0021**|EXECUTION, LATERAL MOVEMENT|**Send Poisoned Email**|*none*|
|
||||
|**B0022**|IMPACT, PERSISTENCE|**Remote Access**|*none*|
|
||||
|**B0023**|EXECUTION|**Install Additional Program**|*none*|
|
||||
|**B0024**|EXECUTION|**Prevent Concurrent Execution**|*none*|
|
||||
|**B0025**|ANTI-BEHAVIORAL ANALYSIS//EXECUTION|**Conditional Execution**|Execution Guardrails ([T1480](https://attack.mitre.org/techniques/T1480))|
|
||||
|**B0026**|LATERAL MOVEMENT, PERSISTENCE|**Malicious Network Driver**|*none*|
|
||||
|**B0027**|DEFENSE EVASION|**Alternative Installation Location**|*none*|
|
||||
|**B0028**|CREDENTIAL ACCESS|**Cryptocurrency**|*none*|
|
||||
|**B0029**|DEFENSE EVASION|**Polymorphic Code**|*none*|
|
||||
|**B0030**|COMMAND AND CONTROL|**Command and Control Communication**|*none*|
|
||||
|**B0031**|COMMAND AND CONTROL|**Domain Name Generation**|Dynamic Resolution: Domain Name Generation ([T1568.002](https://attack.mitre.org/techniques/T1568/002))|
|
||||
|**B0032**|ANTI-STATIC ANALYSIS|**Executable Code Obfuscation**|*none*|
|
||||
|**B0033**|IMPACT|**Denial of Service**|Network Denial of Service ([T1498](https://attack.mitre.org/techniques/T1498))|
|
||||
|**B0034**|ANTI-STATIC ANALYSIS|**Executable Code Obfuscation**|*none*|
|
||||
|**B0035**|PERSISTENCE|**Shutdown Event**|*none*|
|
||||
|**B0036**|ANTI-BEHAVIORAL ANALYSIS|**Capture Evasion**|*none*|
|
||||
|**B0037**|DEFENSE EVASION|**Bypass Data Execution Prevention**|*none*|
|
||||
|**B0038**|DISCOVERY|**Self Discovery**|*none*|
|
||||
|**B0039**|IMPACT|**Spamming**|*none*|
|
||||
|**B0040**|DEFENSE EVASION|**Covert Location**|*none*|
|
||||
|**B0041**|*not defined*|---|---|
|
||||
|**B0042**|IMPACT|**Modify Hardware**|*none*|
|
||||
|**B0043**|DISCOVERY|**Taskbar Discovery**|*none*|
|
||||
|**B0044**|EXECUTION|**Execution Dependency**|*none*|
|
||||
|**B0045**|ANTI-STATIC ANALYSIS|**Data Flow Analysis Evasion**|*none*|
|
||||
|**B0046**|DISCOVERY|**Code Discovery**|*none*|
|
||||
|**B0047**|DEFENSE EVASION, PERSISTENCE|**Install Insecure or Malicious Code**|*none*|
|
||||
|
||||
**Copyright 2022 The MITRE Corporation. [Terms of Use.](./tou.md)**
|
||||
|
||||
|
||||
@@ -1,24 +1,26 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**OB0001**|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>OB0001</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
# Anti-Behavioral Analysis
|
||||
Behaviors that prevent, obstruct, or evade behavioral analysis (sandbox, debugger, etc). Because the underlying methods differ, separate "detection" and "evasion" behaviors are defined for some anti-behavioral analysis areas (e.g., anti-debugger).
|
||||
Behaviors that prevent, obstruct, or evade behavioral analysis of malware--for example, analysis done using a sandbox or debugger. Because the underlying methods differ, separate "detection" and "evasion" behaviors are defined for some anti-behavioral analysis areas.
|
||||
|
||||
* **Capture Evasion** [B0036](../anti-behavioral-analysis/evade-capture.md)
|
||||
* **Conditional Execution** [B0025](../execution/conditional-execute.md)
|
||||
* **Debugger Detection** [B0001](../anti-behavioral-analysis/detect-debugger.md)
|
||||
* **Debugger Evasion** [B0002](../anti-behavioral-analysis/evade-debugger.md)
|
||||
* **Dynamic Analysis Evasion** [B0003](../anti-behavioral-analysis/evade-dynamic-analysis.md)
|
||||
* **Emulator Detection** [B0004](../anti-behavioral-analysis/detect-emulator.md)
|
||||
* **Emulator Evasion** [B0005](../anti-behavioral-analysis/evade-emulator.md)
|
||||
* **Executable Code Virtualization** [B0008](../anti-static-analysis/exe-code-virtualize.md)
|
||||
* **Hooking** [F0003](../credential-access/hooking.md)
|
||||
* **Memory Dump Evasion** [B0006](../anti-behavioral-analysis/evade-memory-dump.md)
|
||||
* **Sandbox Detection** [B0007](../anti-behavioral-analysis/detect-sandbox.md)
|
||||
* **Capture Evasion** [B0036](../anti-behavioral-analysis/capture-evasion.md)
|
||||
* **Conditional Execution** [B0025](../execution/conditional-execution.md)
|
||||
* **Debugger Detection** [B0001](../anti-behavioral-analysis/debugger-detection.md)
|
||||
* **Debugger Evasion** [B0002](../anti-behavioral-analysis/debugger-evasion.md)
|
||||
* **Dynamic Analysis Evasion** [B0003](../anti-behavioral-analysis/dynamic-analysis-evasion.md)
|
||||
* **Emulator Detection** [B0004](../anti-behavioral-analysis/emulator-detection.md)
|
||||
* **Emulator Evasion** [B0005](../anti-behavioral-analysis/emulator-evasion.md)
|
||||
* **Executable Code Virtualization** [B0008](../anti-static-analysis/executable-code-virtualization.md)
|
||||
* **Hijack Execution Flow** [F0015](../defense-evasion/hijack-execution-flow.md)
|
||||
* **Memory Dump Evasion** [B0006](../anti-behavioral-analysis/memory-dump-evasion.md)
|
||||
* **Sandbox Detection** [B0007](../anti-behavioral-analysis/sandbox-detection.md)
|
||||
* **Software Packing** [F0001](../anti-static-analysis/software-packing.md)
|
||||
* **Virtual Machine Detection** [B0009](../anti-behavioral-analysis/detect-vm.md)
|
||||
* **Virtual Machine Detection** [B0009](../anti-behavioral-analysis/virtual-machine-detection.md)
|
||||
|
||||
References
|
||||
----------
|
||||
|
||||
+15
-5
@@ -1,8 +1,18 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0036**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](../anti-behavioral-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0036</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Capture Evasion
|
||||
+27
-7
@@ -1,8 +1,18 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0001**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](../anti-behavioral-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0001</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Debugger Detection
|
||||
@@ -18,11 +28,11 @@ Methods
|
||||
|**API Hook Detection**|B0001.001|Module bounds based [[7]](#7).|
|
||||
|**Anti-debugging Instructions**|B0001.034|Malware code contains mnemonics related to anti-debugging (e.g., rdtsc, icebp).|
|
||||
|**CheckRemoteDebuggerPresent**|B0001.002|The kernel32!CheckRemoteDebuggerPresent function calls NtQueryInformationProcess with ProcessInformationClass parameter set to 7 (ProcessDebugPort constant).|
|
||||
|**Check Processes**|B0001.038|The malware may check running processes for specific strings such as "malw" to detect a analysis environment.|
|
||||
|**CloseHandle**|B0001.003|(NtClose); If an invalid handle is passed to the CloseHandle function and a debugger is present, then an EXCEPTION_INVALID_HANDLE (0xC0000008) exception will be raised. [[7]](#7)|
|
||||
|**Debugger Artifacts**|B0001.004|Malware may detect a debugger by its artifact (window title, device driver, exports, etc.).|
|
||||
|**Hardware Breakpoints**|B0001.005|(SEH/GetThreadContext); Debug registers will indicate the presence of a debugger. See [[7]](#7) for details.|
|
||||
|**Interrupt 0x2d**|B0001.006|If int 0x2d is mishandled by the debugger, it can cause a single-byte instruction to be inadvertently skipped, which can be detected by malware.|
|
||||
|**Interrupt 1**|B0001.007|[[7]](#7)|
|
||||
|**Interruption**|B0001.006|If an interruption is mishandled by the debugger, it can cause a single-byte instruction to be inadvertently skipped, which can be detected by malware. Examples include Interrupt 0x2d and Interrupt 1 [7].|
|
||||
|**IsDebuggerPresent**|B0001.008|The kernel32!IsDebuggerPresent API function call checks the PEB BeingDebugged flag to see if the calling process is being debugged. It returns 1 if the process is being debugged, 0 otherwise. This is one of the most common ways of debugger detection.|
|
||||
|**Memory Breakpoints**|B0001.009|(PAGE_GUARD); Guard pages trigger an exception the first time they are accessed and can be used to detect a debugger. See [[7]](#7) for details.|
|
||||
|**Memory Write Watching**|B0001.010|[[7]](#7)|
|
||||
@@ -58,6 +68,10 @@ Malware Examples
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Redhip**](../xample-malware/redhip.md)|January 2011|Redhip uses general approaches to detecting user level debuggers (e.g., Process Environment Block 'Being Debugged' field), as well as specific checks for kernel level debuggers like SOFTICE. [[4]](#4)|
|
||||
|[**Gamut**](../xample-malware/gamut.md)|2014|The malware detects debuggers using an INT 03h trap and IsDebuggerPresent[[8]](#8)|
|
||||
|[**Rombertik**](../xample-malware/rombertik.md)|2015|an anti-analysis function within the packer is called to check the username and filename of the executing process for strings like “malwar”, “sampl”, “viru”, and “sandb”. [[9]](#9)|
|
||||
|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|Poison Ivy Variant checks for breakpoints and exits immediately if found [[10]](#10)|
|
||||
|
||||
|
||||
References
|
||||
----------
|
||||
@@ -74,3 +88,9 @@ References
|
||||
<a name="6">[6]</a> Nicolas Falliere, Symantec, "Windows Anti-Debug Reference," 11 September 2007. https://www.symantec.com/connect/articles/windows-anti-debug-reference.
|
||||
|
||||
<a name="7">[7]</a> Anti Debugging Tricks, Al-Khaser. https://github.com/LordNoteworthy/al-khaser/wiki/Anti-Debugging-Tricks
|
||||
|
||||
<a name="8">[8]</a> https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/gamut-spambot-analysis/
|
||||
|
||||
<a name="9">[9]</a> https://blogs.cisco.com/security/talos/rombertik
|
||||
|
||||
<a name="10">[10]</a> https://www.mandiant.com/sites/default/files/2021-09/rpt-poison-ivy.pdf
|
||||
+17
-5
@@ -1,8 +1,18 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0002**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](../anti-behavioral-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0002</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Debugger Evasion (<a href="https://attack.mitre.org/techniques/T1622/">T1622</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Debugger Evasion
|
||||
@@ -11,6 +21,8 @@ Behaviors that make debugging difficult.
|
||||
|
||||
A thorough reference for anti-debugging, both detection and evasion, is given in [[1]](#1).
|
||||
|
||||
The related **Debugger Evasion ([T1622](https://attack.mitre.org/techniques/T1622/))** ATT&CK technique was defined subsequent to this MBC behavior.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
+27
-6
@@ -1,21 +1,35 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0003**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](../anti-behavioral-analysis)|
|
||||
|**Related ATT&CK Technique**|[Virtualization/Sandbox Evasion](https://attack.mitre.org/techniques/T1497/)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0003</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Virtualization/Sandbox Evasion (<a href="https://attack.mitre.org/techniques/T1497/">T1497</a>, <a href="https://attack.mitre.org/techniques/T1633/">T1633</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Dynamic Analysis Evasion
|
||||
========================
|
||||
Malware may obstruct dynamic analysis in a sandbox, emulator, or virtual machine.
|
||||
|
||||
See [Emulator Evasion](../anti-behavioral-analysis/evade-emulator.md) for an emulator-specific evasion behavior, and see [Execution Guardrails](../anti-behavioral-analysis/execution-guardrails.md) for a behavior that constrains dynamic execution based on environmental conditions.
|
||||
See **Emulator Evasion ([B0004](../anti-behavioral-analysis/emulator-evasion.md))** for an emulator-specific evasion behavior, and see **Conditional Execution ([B0025](../anti-behavioral-analysis/execution-guardrails.md))** for a behavior that constrains dynamic execution based on environmental conditions.
|
||||
|
||||
The related **Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/techniques/T1497/), [T1633](https://attack.mitre.org/techniques/T1633/))** ATT&CK techniques were defined subsequent to this MBC behavior.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Alternative ntdll.dll**|B0003.001|A copy of ntdll.dll is dropped to the filesystem and then loaded. This alternative DLL is used to execute function calls to evade sandboxes which use hooking in the operating system's ntdll.dll.|
|
||||
|**API Hammering**|B0003.012|Uses of a huge number of calls to Windows APIs as a form of extended sleep to evade analysis in sandbox environments.|
|
||||
|**Code Integrity Check**|B0003.011|Compares memory-based and disk-based versions of itself. If differences are detected, the malware alters its execution, possibly acting destructively.|
|
||||
|**Data Flood**|B0003.002|Overloads a sandbox by generating a flood of meaningless behavioral data. [[1]](#1)|
|
||||
|**Delayed Execution**|B0003.003|Stalling code is typically executed before any malicious behavior. The malware's aim is to delay the execution of the malicious activity long enough so that an automated dynamic analysis system fails to extract the interesting malicious behavior. This method is very similar to ATT&CK's [Virtualization/Sandbox Evasion: Time Based Evasion](https://attack.mitre.org/techniques/T1497/003/) sub-technique.|
|
||||
|**Demo Mode**|B0003.004|Inclusion of a demo binary/mode that is executed when token is absent or not privileged enough.|
|
||||
@@ -36,6 +50,9 @@ Malware Examples
|
||||
|**Nap**|2013|Trojan Nap (tied to the Kelihos Botnet) uses extended sleep calls to evade sandbox analysis. [[3]](#3)|
|
||||
|**Smokeloader**|2019|Smokeloader drops a copy of ntdll.dll to %APPDATA%\Local\Temp\ [[4]](#4)|
|
||||
|[**WebCobra**](../xample-malware/webcobra.md)|2018|Evades dynamic analysis.)|
|
||||
|[**Rombertik**](../xample-malware/rombertik.md)|2015|The malware stalls by writing a byte of random data to memory 960 million times which complicates analysis. It also calls specific Windows API functions [[5]](#5)|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Uses numerous printf loops to delay the execution process and overload the sandbox with junk data (API Hammering) [[6]](#6)|
|
||||
|
||||
|
||||
References
|
||||
----------
|
||||
@@ -46,3 +63,7 @@ References
|
||||
<a name="3">[3]</a> https://www.fireeye.com/content/dam/fireeye-www/current-threats/pdfs/pf/file/fireeye-hot-knives-through-butter.pdf
|
||||
|
||||
<a name="4">[4]</a> https://research.checkpoint.com/2019-resurgence-of-smokeloader/
|
||||
|
||||
<a name="5">[5]</a> https://blogs.cisco.com/security/talos/rombertik
|
||||
|
||||
<a name="6">[6]</a> https://www.joesecurity.org/blog/498839998833561473
|
||||
+25
-5
@@ -1,8 +1,18 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0004**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](../anti-behavioral-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0004</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Emulator Detection
|
||||
@@ -18,6 +28,16 @@ Methods
|
||||
|**Check for WINE Version**|B0004.002|Checks for WINE via the `get_wine_version` function from WINE's `ntdll.dll`.|
|
||||
|**Failed Network Connections**|B0004.004|Some emulated systems fail to handle some network communications; such failures will indicate the emulated environment.|
|
||||
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|Stuxnet checks for specific operating systems on 32-bit machines, registry keys, and dates to profile a potential target machine before execution. If the conditions are not met to be considered a viable target, it will exit execution [[2]](#2)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://search.unprotect.it/map/sandbox-evasion/
|
||||
|
||||
<a name="2">[2]</a> https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en
|
||||
+15
-5
@@ -1,8 +1,18 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0005**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](../anti-behavioral-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0005</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Emulator Evasion
|
||||
+15
-5
@@ -1,8 +1,18 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0006**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](../anti-behavioral-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0006</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Memory Dump Evasion
|
||||
+28
-11
@@ -1,29 +1,39 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0007**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](../anti-behavioral-analysis)|
|
||||
|**Related ATT&CK Sub-techniques**|[Virtualization/Sandbox Evasion: System Checks](https://attack.mitre.org/techniques/T1497/001/), [Virtualization/Sandbox Evasion: User Activity Based Checks](https://attack.mitre.org/techniques/T1497/002/)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0007</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Virtualization/Sandbox Evasion Checks (<a href="https://attack.mitre.org/techniques/T1497/001/">T1497.001</a>, <a href="https://attack.mitre.org/techniques/T1633/001/">T1633.001</a>), Virtualization/Sandbox Evasion: User Activity Based Checks (<a href="https://attack.mitre.org/techniques/T1497/002/">T1497.002</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
Sandbox Detection
|
||||
=================
|
||||
Detects whether the malware instance is being executed inside an instrumented sandbox environment (e.g., Cuckoo Sandbox). If so, conditional execution selects a benign execution path.
|
||||
|
||||
The Sandbox Detection behavior relates to anti-analysis, whereas a related ATT&CK technique relates to [Defense Evasion](../defense-evasion): for details, see the ATT&CK [**Virtualization/Sandbox Evasion**](https://attack.mitre.org/techniques/T1497/) technique and its sub-techniques.
|
||||
|
||||
The related **Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/techniques/T1497/), [T1633](https://attack.mitre.org/techniques/T1633/))** ATT&CK techniques were defined subsequent to this MBC behavior.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Check Clipboard Data**|B0007.001|Checks clipboard data which can be used to detect whether execution is inside a sandbox.|
|
||||
|**Check Files**|B0007.002|Sandboxes create files on the file system. Malware can check the different folders to find sandbox artifacts.|
|
||||
|**Human User Check**|B0007.003|Detects whether there is any "user" activity on the machine, such as the movement of the mouse cursor, non-default wallpaper, or recently opened Office files. Directories or file might be counted. If there is no human activity, the machine is suspected to be a virtualized machine and/or sandbox. Other items used to detect a user: mouse clicks (single/double), DialogBox, scrolling, color of background pixel [[3]](#3). This method is very similar to ATT&CK's [Virtualization/Sandbox Evasion: User Activity Based Checks](https://attack.mitre.org/techniques/T1497/002/) sub-technique.|
|
||||
|**Human User Check**|B0007.003|Detects whether there is any "user" activity on the machine, such as the movement of the mouse cursor, non-default wallpaper, or recently opened Office files. Directories or file might be counted. If there is no human activity, the machine is suspected to be a virtualized machine and/or sandbox. Other items used to detect a user: mouse clicks (single/double), DialogBox, scrolling, color of background pixel [[3]](#3). This method is similar to ATT&CK's [Virtualization/Sandbox Evasion: User Activity Based Checks](https://attack.mitre.org/techniques/T1497/002/) sub-technique.|
|
||||
|**Injected DLL Testing**|B0007.004|Testing for the name of a particular DLL that is known to be injected by a sandbox for API hooking is a common way of detecting sandbox environments. This can be achieved through the kernel32!GetModuleHandle API call and other means.|
|
||||
|**Product Key/ID Testing**|B0007.005|Checking for a particular product key/ID associated with a sandbox environment (commonly associated with the Windows host OS used in the environment) can be used to detect whether a malware instance is being executed in a particular sandbox. This can be achieved through several means, including testing for the Key/ID in the Windows registry.|
|
||||
|**Screen Resolution Testing**|B0007.006|Sandboxes aren't used in the same manner as a typical user environment, so most of the time the screen resolution stays at the minimum 800x600 or lower. No one is actually working on a such small screen. Malware could potentially detect the screen resolution to determine if it's a user machine or a sandbox.|
|
||||
|**Self Check**|B0007.007|Malware may check its own characteristics to determine whether it's running in a sandbox. For example, a malicious Office document might check its file name or VB project name.|
|
||||
|**Timing/Date Check**|B0007.008|Calling GetSystemTime or equiv and only executing code if the current date/hour/minute/second passes some check. Often this is for running only after or only until a specific date. This behavior can be mitigated in non-automated analysis environments.|
|
||||
|**Timing/Uptime Check**|B0007.009|Comparing single GetTickCount with some value to see if system has been started at least *X* amount ago. This behavior can be mitigated in non-automated analysis environments.|
|
||||
|**Test API Routines**|B0007.010|Calls Windows API routines with invalid arguments to identify error supression.|
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
@@ -33,8 +43,11 @@ Malware Examples
|
||||
|[**Rombertik**](../xample-malware/rombertik.md)|May 2015|[[2]](#2)|
|
||||
|[**Terminator**](../xample-malware/terminator.md)|May 2013|The Terminator rat evades a sandbox by not executing until after a reboot. Most sandboxes don't reboot during an analysis. [[4]](#4)|
|
||||
|[**Ursnif**](../xample-malware/ursnif.md)|2016|Ursnif uses malware macros to evade sandbox detection.|
|
||||
|[**GotBotKR**](../xample-malware/gotbotkr.md)|2019|GoBotKR performs several checks on the compromised machine to avoid being emulated or executed in a sandbox. [[5]](#5)|
|
||||
|[**Rombertik**](../xample-malware/rombertik.md)|2015|The malware check for sandboxes that suppress errors returned from API routine calls the using ZwGetWriteWatch routine. [[6]](#6)|
|
||||
|
||||
Code Snippets
|
||||
|
||||
<a name="snippet"><a/>Code Snippets
|
||||
-------------
|
||||
**Sandbox Detection::Product Key/ID Testing** (B0007.005) - the value 55274-640-2673064-23950 corresponds to Joe Sandbox.
|
||||
```asm
|
||||
@@ -70,8 +83,12 @@ References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
|
||||
|
||||
<a name="2">[2]</a> http://labs.lastline.com/exposing-rombertik-turning-the-tables-on-evasive-malware
|
||||
<a name="2">[2]</a> https://blogs.cisco.com/security/talos/rombertik
|
||||
|
||||
<a name="3">[3]</a> https://github.com/LordNoteworthy/al-khaser
|
||||
|
||||
<a name="4">[4]</a> https://www.fireeye.com/content/dam/fireeye-www/current-threats/pdfs/pf/file/fireeye-hot-knives-through-butter.pdf
|
||||
|
||||
<a name="5">[5]</a> https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/
|
||||
|
||||
<a name="6">[6]</a> https://blogs.cisco.com/security/talos/rombertik
|
||||
+22
-7
@@ -1,15 +1,25 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0009**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](../anti-behavioral-analysis)|
|
||||
|**Related ATT&CK Technique**|[Virtualization/Sandbox Evasion](https://attack.mitre.org/techniques/T1497/)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0009</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Virtualization/Sandbox Evasion (<a href="https://attack.mitre.org/techniques/T1497/">T1497</a>, <a href="https://attack.mitre.org/techniques/T1633/">T1633</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Virtual Machine Detection
|
||||
=========================
|
||||
Detects whether the malware instance is being executed in a virtual machine (VM), such as VMWare. If so, conditional execution selects a benign execution path. [[1]](#1)
|
||||
|
||||
The Virtual Machine Detection behavior relates to anti-analysis, whereas a related ATT&CK technique relates to [Defense Evasion](../defense-evasion): for details, see the ATT&CK [**Virtualization/Sandbox Evasion**](https://attack.mitre.org/techniques/T1497/) technique and its sub-techniques.
|
||||
The related **Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/techniques/T1497/), [T1633](https://attack.mitre.org/techniques/T1633/))** ATT&CK techniques were defined subsequent to this MBC behavior.
|
||||
|
||||
Methods
|
||||
-------
|
||||
@@ -54,6 +64,7 @@ Methods
|
||||
|**Unique Hardware/Firmware Check - I/O Communication Port**|B0009.025|Malware may check for hardware characteristics unique to being virtualized, allowing the malware to detect the virtual environment. VMware uses virtual I/O ports for communication between the virtual machine and the host operating system to support functionality like copy and paste between the two systems. The port can be queried and compared with a magic number VMXh to identify the use of VMware.|
|
||||
|**Unique Hardware/Firmware Check - MAC Address**|B0009.028|Malware may check for hardware characteristics unique to being virtualized, allowing the malware to detect the virtual environment. VMware uses specific virtual MAC address that can be detected. The usual MAC address used started with the following numbers: "00:0C:29", "00:1C:14", "00:50:56", "00:05:69". Virtualbox uses specific virtual MAC address that can be detected by Malware. The usual MAC address used started with the following numbers: 08:00:27. [[2]](#2)|
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
@@ -61,6 +72,9 @@ Malware Examples
|
||||
|[**GravityRAT**](../xample-malware/gravity-rat.md)|May 2018|GravityRAT checks system temperature by recording thermal readings for detecting VMs. Heat levels indicate whether the system is a VM. [[3]](#3)|
|
||||
|[**WebCobra**](../xample-malware/webcobra.md)|2018|WebCobra injects malicious code to svchost.exe and uses an infinite loop to check all open windows and to compare each window’s title bar text with a set of strings to determine whether it is running in an isolated, malware analysis environment [[4]](#4)|
|
||||
|[**Redhip**](../xample-malware/redhip.md)|2011|Redhip detects VMWare, Virtual PC and Virtual Box. It also detects VM environments in general by considering timing lapses. [[6]](#6)|
|
||||
|[**Emotet**](../xample-malware/emotet.md)|2018|Emotet checks for various processes that are associated with various virtual machines by comparing hash values of the process names with the hash values of the list of running process names [[7]](#7)|
|
||||
|
||||
|
||||
|
||||
Code Snippets
|
||||
-------------
|
||||
@@ -99,7 +113,6 @@ jmp short loc_401CBB
|
||||
```
|
||||
|
||||
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
|
||||
@@ -113,3 +126,5 @@ References
|
||||
<a name="5">[5]</a> https://github.com/LordNoteworthy/al-khaser
|
||||
|
||||
<a name="6">[6]</a> https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
|
||||
|
||||
<a name="7">[7]</a> https://securelist.com/the-banking-trojan-emotet-detailed-analysis/69560/
|
||||
@@ -1,18 +1,21 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**OB0002**|
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>OB0002</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
# Anti-Static Analysis
|
||||
Behaviors and code characteristics that prevent static analysis or make it more difficult. Simple static analysis identifies features such as embedded strings, header information, hash values, and file metadata (e.g., creation date). More involved static analysis involves the disassembly of the binary code.
|
||||
Behaviors and code characteristics that prevent or hinder static analysis of the malware. Simple static analysis identifies features such as embedded strings, header information, or file metadata. More involved static analysis involves the disassembly of the binary code.
|
||||
|
||||
* **Call Graph Generation Evasion** [B0010](../anti-static-analysis/evade-call-graph.md)
|
||||
* **Disassembler Evasion** [B0012](../anti-static-analysis/evade-disassembler.md)
|
||||
* **Data Flow Analysis Evasion** [B0045](../anti-static-analysis/evade-data-flow-analysis.md)
|
||||
* **Executable Code Obfuscation** [B0032](../anti-static-analysis/exe-code-obfuscate.md)
|
||||
* **Executable Code Optimization** [B0034](../anti-static-analysis/exe-code-optimize.md)
|
||||
* **Executable Code Virtualization** [B0008](../anti-static-analysis/exe-code-virtualize.md)
|
||||
* **Obfuscated Files or Information** [E1027](../defense-evasion/obfuscate-files.md)
|
||||
* **Call Graph Generation Evasion** [B0010](../anti-static-analysis/call-graph-generation-evasion.md)
|
||||
* **Disassembler Evasion** [B0012](../anti-static-analysis/disassembler-evasion.md)
|
||||
* **Data Flow Analysis Evasion** [B0045](../anti-static-analysis/data-flow-analysis-evasion.md)
|
||||
* **Executable Code Obfuscation** [B0032](../anti-static-analysis/executable-code-obfuscation.md)
|
||||
* **Executable Code Optimization** [B0034](../anti-static-analysis/executable-code-optimization.md)
|
||||
* **Executable Code Virtualization** [B0008](../anti-static-analysis/executable-code-virtualization.md)
|
||||
* **Obfuscated Files or Information** [E1027](../defense-evasion/obfuscated-files-or-information.md)
|
||||
* **Software Packing** [F0001](../anti-static-analysis/software-packing.md)
|
||||
|
||||
References
|
||||
|
||||
+15
-5
@@ -1,8 +1,18 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0010**|
|
||||
|**Objective(s)**|[Anti-Static Analysis](../anti-static-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0010</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-static-analysis">Anti-Static Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Call Graph Generation Evasion
|
||||
+15
-5
@@ -1,8 +1,18 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0045**|
|
||||
|**Objective(s)**|[Anti-Static Analysis](../anti-static-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0045</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-static-analysis">Anti-Static Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Data Flow Analysis Evasion
|
||||
+15
-5
@@ -1,8 +1,18 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0012**|
|
||||
|**Objective(s)**|[Anti-Static Analysis](../anti-static-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0012</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-static-analysis">Anti-Static Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Disassembler Evasion
|
||||
+33
-6
@@ -1,15 +1,25 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0032**|
|
||||
|**Objective(s)**|[Anti-Static Analysis](../anti-static-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0032</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-static-analysis">Anti-Static Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Executable Code Obfuscation
|
||||
===========================
|
||||
Executable code can be obfuscated to hinder disassembly and static code analysis. This behavior is specific to a malware sample's executable code (data and text sections).
|
||||
|
||||
For encryption and encoding characteristics of malware samples, as well as malware obfuscation behaviors related to non-malware-sample files and information, see [**Obfuscated Files or Information**](../defense-evasion/obfuscate-files.md).
|
||||
For encryption and encoding characteristics of malware samples, as well as malware obfuscation behaviors related to non-malware-sample files and information, see **Obfuscated Files or Information ([E1027](../defense-evasion/obfuscated-files-or-information.md))**.
|
||||
|
||||
Methods
|
||||
-------
|
||||
@@ -34,6 +44,7 @@ Methods
|
||||
|**Symbol Obfuscation**|B0032.018|Remove or rename symbolic information commonly inserted by compilers for debugging purposes.|
|
||||
|**Thunk Code Insertion**|B0032.006|Variation on Jump Insertion. Used by some compilers for user-generated functions.|
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
@@ -41,6 +52,12 @@ Malware Examples
|
||||
|[**Heriplor**](../xample-malware/heriplor.md)|March 2019|The Heriplor Trojan uses API Hashing. [[1]](#1)|
|
||||
|[**Emotet**](../xample-malware/emotet.md)|2018|Emotet macros are heavily obfuscated with junk functions and string substitutions. [[2]](#2)|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
|[**Rombertik**](../anti-static-analysis/executable-code-obfuscation.md)|2015|Most of the malware file consists of unnecessary code or unnecessary data [[4]](#4)|
|
||||
|[**Ursnif**](../anti-static-analysis/executable-code-obfuscation.md)|2016|Creates an encrypted Registry key called TorClient to store its data [[5]](#5)|
|
||||
|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|Poison Ivy variant encrypts all its strings [[6]](#6)|
|
||||
|[**SamSam**](../xample-malware/samsam.md)|2015|SamSam obfuscates functions, class names and strings, including the list of targeted file extensions, the help file contents and environment variables using DES encryption with a fixed hard-coded key and the IV [[7]](#7)|
|
||||
|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|The configuration data block is encoded with a NOT XOR 0xFF operation [[8]](#8)|
|
||||
|
||||
|
||||
Code Snippets
|
||||
-------------
|
||||
@@ -103,3 +120,13 @@ References
|
||||
<a name="2">[2]</a> https://cofense.com/recent-geodo-malware-campaigns-feature-heavily-obfuscated-macros/
|
||||
|
||||
<a name="3">[3]</a> Rob Simmons, "Comparing Malicious Files," BSides, 2019. http://www.irongeek.com/i.php?page=videos/bsidescharm2019/2-04-comparing-malicious-files-robert-simmons
|
||||
|
||||
<a name="4">[4]</a> https://blogs.cisco.com/security/talos/rombertik
|
||||
|
||||
<a name="5">[5]</a> https://www.proofpoint.com/us/threat-insight/post/ursnif-variant-dreambot-adds-tor-functionality
|
||||
|
||||
<a name="6">[6]</a> https://www.mandiant.com/sites/default/files/2021-09/rpt-poison-ivy.pdf
|
||||
|
||||
<a name="7">[7]</a> https://blog.talosintelligence.com/2018/01/samsam-evolution-continues-netting-over.html
|
||||
|
||||
<a name="8">[8]</a> https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en
|
||||
+15
-5
@@ -1,8 +1,18 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0034**|
|
||||
|**Objective(s)**|[Anti-Static Analysis](../anti-static-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0034</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-static-analysis">Anti-Static Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Executable Code Optimization
|
||||
+16
-6
@@ -1,15 +1,25 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0008**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](../anti-behavioral-analysis), [Anti-Static Analysis](../anti-static-analysis)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0008</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a>, <a href="../anti-static-analysis">Anti-Static Analysis</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Executable Code Virtualization
|
||||
==============================
|
||||
Original executable code is virtualized by translating the code into a special format that only a special virtual machine (VM) can run; the VM uses a customized virtual instruction set. A "stub" function calls the VM when the code is run. Virtualized code makes static analysis and reverse engineering more difficult; dumped code won’t run without the VM.
|
||||
|
||||
Virtualized code is a software protection technique. Themida is a commercial tool; WPProtect is an open source tool. [[1]](#1)
|
||||
Virtualized code is a software protection technique. Themida is a commercial tool; VMProtect is an open source tool. [[1]](#1)
|
||||
|
||||
Methods
|
||||
-------
|
||||
@@ -1,14 +1,24 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**F0001**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](../anti-behavioral-analysis), [Anti-Static Analysis](../anti-static-analysis), [Defense Evasion](../defense-evasion)|
|
||||
|**Related ATT&CK Sub-Technique**|[Obfuscated Files or Information: Software Packing](https://attack.mitre.org/techniques/T1027/002)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>F0001</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a>, <a href="../anti-static-analysis">Anti-Static Analysis</a>, <a href="../defense-evasion">Defense Evasion</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Obfuscated Files or Information: Software Packing (<a href="https://attack.mitre.org/techniques/T1027/002/">T1027.002</a>, <a href="https://attack.mitre.org/techniques/T1406/002/">T1406.002</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
Software Packing
|
||||
================
|
||||
This code characteristic - Software Packing - can make static and behavioral analysis difficult and includes packing with software protectors, such as Themida and Armadillo [[1]](#1). Methods related to anti-analysis are below. This behavior covers both characteristics of the malware (i.e., how it is packed) as well as behaviors of the malware (e.g., the malware packs another executable file).
|
||||
|
||||
This description refines the ATT&CK [**Obfuscated Files or Information: Software Packing**](https://attack.mitre.org/techniques/T1027/002) sub-technique.
|
||||
This description refines the ATT&CK **Obfuscated Files or Information: Software Packing ([T1027.002](https://attack.mitre.org/techniques/T1027/002/), [T1406.002](https://attack.mitre.org/techniques/T1406/002/))** techniques.
|
||||
|
||||
Methods
|
||||
-------
|
||||
@@ -33,6 +43,11 @@ Malware Examples
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Redhip**](../xample-malware/redhip.md)|2011|Redhip samples are packed with different custom packers. [[3]](#3)|
|
||||
|[**Kovter**](../xample-malware/kovter.md)|2016|The malware comes packed by a crypter/FUD [[4]](#4)|
|
||||
|[**Conficker**](../xample-malware/conficker.md)|2008|Conficker is propagated as a DLL which has been backed using the UPX packer [[5]](#5)|
|
||||
|[**DarkComet**](../xample-malware/dark-comet.md)|2008|Has the option to compress its payload using UPX or MPRESS [[6]](#6)|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Has a custom packer to obfuscate itself [[7]](#7)|
|
||||
|[**Emotet**](../xample-malware/emotet.md)|2018|Emotet uses custom packers which first decrypt the loaders and the loaders decrypt and load Emotet's main payloads [[8]](#8)|
|
||||
|
||||
References
|
||||
----------
|
||||
@@ -41,3 +56,13 @@ References
|
||||
<a name="2">[2]</a> Jiang Ming et al, Towards Paving the Way for Large-Scale Windows Malware Analysis: Generic Binary Unpacking with Orders-of-Magnitude Performance Boost, October 2018, https://dl.acm.org/citation.cfm?id=3243771.
|
||||
|
||||
<a name="3">[3]</a> https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html
|
||||
|
||||
<a name="4">[4]</a> https://www.bleepingcomputer.com/virus-removal/remove-kovter-trojan
|
||||
|
||||
<a name="5">[5]</a> http://www.csl.sri.com/users/vinod/papers/Conficker/
|
||||
|
||||
<a name="6">[6]</a> https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/
|
||||
|
||||
<a name="7">[7]</a> https://www.securityartwork.es/wp-content/uploads/2017/07/Trickbot-report-S2-Grupo.pdf
|
||||
|
||||
<a name="8">[8]</a> https://documents.trendmicro.com/assets/white_papers/ExploringEmotetsActivities_Final.pdf
|
||||
|
||||
@@ -0,0 +1,448 @@
|
||||
# capa Rule Distribution #
|
||||
15 August 2022
|
||||
|
||||
## Histograms ##
|
||||
Histograms showing the number of capa rules mapped into each ATT&CK tactic, MBC objective, and MBC micro-objective are shown below. Details of the tactics and objectives follow.
|
||||
|
||||
### ATT&CK Mapping Histogram ###
|
||||
|
||||
| **TACTIC** | **Number** | |
|
||||
|-----|-----|-----|
|
||||
|Reconnaissance |0| |
|
||||
|Resource Development|0| |
|
||||
|Initial Access |0| |
|
||||
|**Execution**|8| **XXXXXXXX** |
|
||||
|**Persistence**|13| **XXXXXXXXXXXXX** |
|
||||
|**Privilege Escalation**|1 | **X** |
|
||||
|**Defense Evasion**|32| **XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX** |
|
||||
|**Credential Access**|4| **XXXX** |
|
||||
|**Discovery**|17| **XXXXXXXXXXXXXXXXX** |
|
||||
|Lateral Movement|0| |
|
||||
|**Collection**|7| **XXXXXXX** |
|
||||
|**Command and Control**|1| **X** |
|
||||
|Exfiltration|0| |
|
||||
|**Impact**|5| **XXXXX** |
|
||||
|
||||
### MBC Mapping Histogram (Objectives) ###
|
||||
|
||||
| **OBJECTIVE** | **Number** | |
|
||||
|-----|-----|-----|
|
||||
|**Anti-Behavioral Analysis** |20| **XXXXXXXXXXXXXXXXXXXX**|
|
||||
|**Anti-Static Analysis**|9| **XXXXXXXXX** |
|
||||
|**Collection**|4| **XXXX** |
|
||||
|**Command and Control**|3| **XXX** |
|
||||
|Credential Access|0| |
|
||||
|**Defense Evasion**|13| **XXXXXXXXXXXXX** |
|
||||
|**Discovery**|6| **XXXXXX** |
|
||||
|**Execution**|1| **X** |
|
||||
|Exfiltration|0| |
|
||||
|**Impact**|5| **XXXXX** |
|
||||
|Lateral Movement|0| |
|
||||
|Persistence|0| |
|
||||
|Privilege Escalation|0 | |
|
||||
|
||||
### MBC Mapping Histogram (Micro-Objectives) ###
|
||||
|
||||
| **MICRO-OBJECTIVE** | **Number** | |
|
||||
|-----|-----|-----|
|
||||
|**Communication** |34| **XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX**|
|
||||
|**Cryptography**|16| **XXXXXXXXXXXXXXXX** |
|
||||
|**Data**|15| **XXXXXXXXXXXXXXX** |
|
||||
|**File System**|11| **XXXXXXXXXXX** |
|
||||
|**Hardware**|4| **XXXX** |
|
||||
|**Memory**|2| **XX** |
|
||||
|**Operating System**|11| **XXXXXXXXXXX** |
|
||||
|**Process**|14| **XXXXXXXXXXXXXX** |
|
||||
|
||||
|
||||
## ATT&CK MAPPINGS ##
|
||||
|
||||
### Collection: ###
|
||||
num: 7
|
||||
- Archive Collected Data::Archive via Library [T1560.002]
|
||||
- Clipboard Data [T1115]
|
||||
- Video Capture [T1125]
|
||||
- Input Capture::Keylogging [T1056.001]
|
||||
- Data from Information Repositories [T1213]
|
||||
- Audio Capture [T1123]
|
||||
- Screen Capture [T1113]
|
||||
|
||||
### Command and Control: ###
|
||||
num: 1
|
||||
- Ingress Tool Transfer [T1105]
|
||||
|
||||
### Credential Access: ###
|
||||
num: 4
|
||||
- Credentials from Password Stores::Windows Credential Manager [T1555.004]
|
||||
- Credentials from Password Stores::Password Managers [T1555.005]
|
||||
- Credentials from Password Stores [T1555]
|
||||
- Credentials from Password Stores::Credentials from Web Browsers [T1555.003]
|
||||
|
||||
### Defense Evasion: ###
|
||||
num: 32
|
||||
- Obfuscated Files or Information::Software Packing [T1027.002]
|
||||
- Virtualization/Sandbox Evasion::System Checks [T1497.001]
|
||||
- Impair Defenses::Disable or Modify Tools [T1562.001]
|
||||
- Virtualization/Sandbox Evasion::User Activity Based Checks [T1497.002]
|
||||
- Virtualization/Sandbox Evasion [T1497]
|
||||
- Indicator Removal on Host [T1070]
|
||||
- Impair Defenses::Disable Windows Event Logging [T1562.002]
|
||||
- Process Injection [T1055]
|
||||
- Access Token Manipulation::Parent PID Spoofing [T1134.004]
|
||||
- Indicator Removal on Host::Clear Windows Event Logs [T1070.001]
|
||||
- Indicator Removal on Host::File Deletion [T1070.004]
|
||||
- Indicator Removal on Host::Timestomp [T1070.006]
|
||||
- Obfuscated Files or Information [T1027]
|
||||
- Obfuscated Files or Information::Indicator Removal from Tools [T1027.005]
|
||||
- Deobfuscate/Decode Files or Information [T1140]
|
||||
- Obfuscated Files or Information [T1027.002]
|
||||
- Subvert Trust Controls::Mark-of-the-Web Bypass [T1553.005]
|
||||
- File and Directory Permissions Modification [T1222]
|
||||
- Hide Artifacts::Hidden Window [T1564.003]
|
||||
- Hide Artifacts [T1564]
|
||||
- "Process Injection::Process Doppelg\xE4nging [T1055.013]"
|
||||
- Process Injection::Portable Executable Injection [T1055.002]
|
||||
- Process Injection::Dynamic-link Library Injection [T1055.001]
|
||||
- Process Injection::Thread Execution Hijacking [T1055.003]
|
||||
- Process Injection::Asynchronous Procedure Call [T1055.004]
|
||||
- Process Injection::Process Hollowing [T1055.012]
|
||||
- Modify Registry [T1112]
|
||||
- Impair Defenses::Safe Mode Boot [T1562.009]
|
||||
- Subvert Trust Controls::Code Signing Policy Modification [T1553.006]
|
||||
- Abuse Elevation Control Mechanism::Bypass User Account Control [T1548.002]
|
||||
- Hijack Execution Flow [T1574]
|
||||
- BITS Jobs [T1197]
|
||||
|
||||
### Discovery: ###
|
||||
num: 17
|
||||
|
||||
- File and Directory Discovery [T1083]
|
||||
- System Information Discovery [T1082]
|
||||
- Process Discovery [T1057]
|
||||
- System Location Discovery::System Language Discovery [T1614.001]
|
||||
- System Service Discovery [T1007]
|
||||
- Application Window Discovery [T1010]
|
||||
- System Owner/User Discovery [T1033]
|
||||
- Account Discovery [T1087]
|
||||
- Query Registry [T1012]
|
||||
- Software Discovery::Security Software Discovery [T1518.001]
|
||||
- Software Discovery [T1518]
|
||||
- System Network Configuration Discovery::Internet Connection Discovery [T1016.001]
|
||||
- System Network Configuration Discovery [T1016]
|
||||
- Network Sniffing [T1040]
|
||||
- System Location Discovery [T1614]
|
||||
- Group Policy Discovery [T1615]
|
||||
- Domain Trust Discovery [T1482]
|
||||
|
||||
### Execution: ###
|
||||
num: 8
|
||||
|
||||
- Command and Scripting Interpreter [T1059]
|
||||
- Windows Management Instrumentation [T1047]
|
||||
- System Services::Service Execution [T1569.002]
|
||||
- Command and Scripting Interpreter::PowerShell [T1059.001]
|
||||
- Shared Modules [T1129]
|
||||
- Command and Scripting Interpreter::Python [T1059.006]
|
||||
- Command and Scripting Interpreter::Unix Shell [T1059.004]
|
||||
- Command and Scripting Interpreter::Windows Command Shell [T1059.003]
|
||||
|
||||
### Exfiltration: ###
|
||||
num: 0
|
||||
|
||||
### Impact: ###
|
||||
num: 5
|
||||
|
||||
- Endpoint Denial of Service [T1499]
|
||||
- System Shutdown/Reboot [T1529]
|
||||
- Data Manipulation::Transmitted Data Manipulation [T1565.002]
|
||||
- Inhibit System Recovery [T1490]
|
||||
- Disk Wipe::Disk Structure Wipe [T1561.002]
|
||||
|
||||
### Initial Access: ###
|
||||
num: 0
|
||||
|
||||
### Lateral Movement: ###
|
||||
num: 0
|
||||
|
||||
### Persistence: ###
|
||||
num: 13
|
||||
|
||||
- Create or Modify System Process::Windows Service [T1543.003]
|
||||
- Event Triggered Execution::Unix Shell Configuration Modification [T1546.004]
|
||||
- Boot or Logon Autostart Execution::XDG Autostart Entries [T1547.013]
|
||||
- Server Software Component::IIS Components [T1505.004]
|
||||
- Modify Authentication Process [T1556]
|
||||
- Modify Authentication Process::Password Filter DLL [T1556.002]
|
||||
- Boot or Logon Initialization Scripts::RC Scripts [T1037.004]
|
||||
- Scheduled Task/Job::Scheduled Task [T1053.005]
|
||||
- Boot or Logon Autostart Execution::Active Setup [T1547.014]
|
||||
- Event Triggered Execution::AppInit DLLs [T1546.010]
|
||||
- Event Triggered Execution [T1546]
|
||||
- Boot or Logon Autostart Execution::Winlogon Helper DLL [T1547.004]
|
||||
- Boot or Logon Autostart Execution::Registry Run Keys / Startup Folder [T1547.001]
|
||||
|
||||
### Privilege Escalation: ###
|
||||
num: 1
|
||||
|
||||
- Access Token Manipulation [T1134]
|
||||
|
||||
### Reconnaissance: ###
|
||||
num: 0
|
||||
|
||||
### Resource Development: ###
|
||||
num: 0
|
||||
|
||||
|
||||
|
||||
## MBC MAPPINGS ##
|
||||
|
||||
### Anti-Behavioral Analysis: ###
|
||||
num: 20
|
||||
|
||||
- Emulator Detection [B0004]
|
||||
- Virtual Machine Detection [B0009]
|
||||
- Virtual Machine Detection::Human User Check [B0009.012]
|
||||
- Sandbox Detection::Product Key/ID Testing [B0007.005]
|
||||
- Debugger Detection [B0001]
|
||||
- Debugger Detection::Software Breakpoints [B0001.025]
|
||||
- Debugger Detection::Process Environment Block BeingDebugged [B0001.035]
|
||||
- Debugger Detection::Timing/Delay Check GetTickCount [B0001.032]
|
||||
- Debugger Detection::SetHandleInformation [B0001.024]
|
||||
- Debugger Detection::OutputDebugString [B0001.016]
|
||||
- Debugger Detection::Memory Write Watching [B0001.010]
|
||||
- Debugger Detection::Timing/Delay Check QueryPerformanceCounter [B0001.033]
|
||||
- Debugger Detection::Hardware Breakpoints [B0001.005]
|
||||
- Debugger Detection::NtQueryInformationProcess [B0001.012]
|
||||
- Debugger Detection::CheckRemoteDebuggerPresent [B0001.002]
|
||||
- Debugger Detection::Process Environment Block NtGlobalFlag [B0001.036]
|
||||
- Debugger Detection::Anti-debugging Instructions [B0001.034]
|
||||
- Conditional Execution::Runs as Service [B0025.007]
|
||||
- Debugger Detection::Process Environment Block [B0001.019]
|
||||
- Dynamic Analysis Evasion::Delayed Execution [B0003.003]
|
||||
|
||||
### Anti-Static Analysis: ###
|
||||
num: 9
|
||||
|
||||
- Disassembler Evasion [B0012]
|
||||
- Software Packing [F0001]
|
||||
- Software Packing::Themida [F0001.011]
|
||||
- Software Packing::VMProtect [F0001.010]
|
||||
- Software Packing::Standard Compression [F0001.002]
|
||||
- Software Packing::Confuser [F0001.009]
|
||||
- Software Packing::UPX [F0001.008]
|
||||
- Executable Code Obfuscation [B0032]
|
||||
- Disassembler Evasion::Argument Obfuscation [B0012.001]
|
||||
|
||||
### Collection: ###
|
||||
num: 4
|
||||
|
||||
- Keylogging::Polling [F0002.002]
|
||||
- Keylogging::Application Hook [F0002.001]
|
||||
- Screen Capture::WinAPI [E1113.m01]
|
||||
- Screen Capture [E1113]
|
||||
|
||||
### Command and Control: ###
|
||||
num: 3
|
||||
|
||||
- C2 Communication::Send Data [B0030.001]
|
||||
- C2 Communication::Receive Data [B0030.002]
|
||||
- C2 Communication::Server to Client File Transfer [B0030.003]
|
||||
|
||||
### Credential Access: ###
|
||||
num: 0
|
||||
|
||||
### Defense Evasion: ###
|
||||
num: 13
|
||||
|
||||
- Disable or Evade Security Tools::Heavens Gate [F0004.008]
|
||||
- Disable or Evade Security Tools::Modify Policy [F0004.005]
|
||||
- Process Injection::Patch Process Command Line [E1055.m04]
|
||||
- Self Deletion::COMSPEC Environment Variable [F0007.001]
|
||||
- Obfuscated Files or Information::Encryption [E1027.m04]
|
||||
- Obfuscated Files or Information::Encryption-Standard Algorithm [E1027.m05]
|
||||
- Obfuscated Files or Information::Encoding-Standard Algorithm [E1027.m02]
|
||||
- Disable or Evade Security Tools::Bypass Windows File Protection [F0004.007]
|
||||
- Process Injection [E1055]
|
||||
- Disable or Evade Security Tools::Disable Code Integrity [F0004.009]
|
||||
- Hijack Execution Flow::Abuse Windows Function Calls [F0015.006]
|
||||
- Process Injection::Injection via Windows Fibers [E1055.m05]
|
||||
- Hijack Execution Flow::Import Address Table (IAT) Hooking [F0015.003]
|
||||
|
||||
### Discovery: ###
|
||||
num: 6
|
||||
|
||||
- Analysis Tool Discovery::Process detection [B0013.001]
|
||||
- Application Window Discovery::Window Text [E1010.m01]
|
||||
- Taskbar Discovery [B0043]
|
||||
- File and Directory Discovery::Log File [E1083.m01]
|
||||
- Code Discovery::Enumerate PE Sections [B0046.001]
|
||||
- Code Discovery::Inspect Section Memory Permissions [B0046.002]
|
||||
|
||||
### Execution: ###
|
||||
num: 1
|
||||
|
||||
- Install Additional Program [B0023]
|
||||
|
||||
### Exfiltration: ###
|
||||
num: 0
|
||||
|
||||
### Impact: ###
|
||||
num: 5
|
||||
|
||||
- Modify Hardware::Mouse [B0042.002]
|
||||
- Modify Hardware::CDROM [B0042.001]
|
||||
- Clipboard Modification [E1510]
|
||||
- Data Destruction::Delete Shadow Copies [E1485.m04]
|
||||
- Remote Access::Reverse Shell [B0022.001]
|
||||
|
||||
### Lateral Movement: ###
|
||||
num: 0
|
||||
|
||||
### Persistence: ###
|
||||
num: 0
|
||||
|
||||
### Privilege Escalation: ###
|
||||
num: 0
|
||||
|
||||
|
||||
## MBC MICRO-BEHAVIOR MAPPINGS ##
|
||||
|
||||
### Communication: ###
|
||||
num: 34
|
||||
|
||||
- DNS Communication::Resolve [C0011.001]
|
||||
- HTTP Communication::Read Header [C0002.014]
|
||||
- HTTP Communication::WinHTTP [C0002.008]
|
||||
- HTTP Communication::IWebBrowser [C0002.010]
|
||||
- HTTP Communication::Set Header [C0002.013]
|
||||
- HTTP Communication::Start Server [C0002.018]
|
||||
- HTTP Communication::Receive Request [C0002.015]
|
||||
- HTTP Communication::Send Response [C0002.016]
|
||||
- HTTP Communication::Get Response [C0002.017]
|
||||
- HTTP Communication::Send Request [C0002.003]
|
||||
- HTTP Communication::Download URL [C0002.006]
|
||||
- HTTP Communication::Create Request [C0002.012]
|
||||
- HTTP Communication::Send Data [C0002.005]
|
||||
- HTTP Communication::Open URL [C0002.004]
|
||||
- HTTP Communication::Connect to Server [C0002.009]
|
||||
- HTTP Communication::Extract Body [C0002.011]
|
||||
- Socket Communication::Start TCP Server [C0001.005]
|
||||
- Socket Communication::TCP Client [C0001.008]
|
||||
- Interprocess Communication::Create Pipe [C0003.001]
|
||||
- Interprocess Communication::Write Pipe [C0003.004]
|
||||
- Interprocess Communication::Connect Pipe [C0003.002]
|
||||
- Interprocess Communication::Read Pipe [C0003.003]
|
||||
- FTP Communication::Send File [C0004.001]
|
||||
- DNS Communication::Server Connect [C0011.002]
|
||||
- Socket Communication::Get Socket Status [C0001.012]
|
||||
- Socket Communication::Set Socket Config [C0001.001]
|
||||
- Socket Communication::Initialize Winsock Library [C0001.009]
|
||||
- Socket Communication::Connect Socket [C0001.004]
|
||||
- Socket Communication::Create TCP Socket [C0001.011]
|
||||
- Socket Communication::Send TCP Data [C0001.014]
|
||||
- Socket Communication::Create UDP Socket [C0001.010]
|
||||
- Socket Communication::Send Data [C0001.007]
|
||||
- Socket Communication::Receive Data [C0001.006]
|
||||
- ICMP Communication::Echo Request [C0014.002]
|
||||
|
||||
### Cryptography: ###
|
||||
num: 16
|
||||
|
||||
- Encryption Key::Import Public Key [C0028.001]
|
||||
- Decrypt Data [C0031]
|
||||
- Encryption Key [C0028]
|
||||
- Decrypt Data::AES [C0031.001]
|
||||
- Encrypt Data [C0027]
|
||||
- Encrypt Data::RC4 [C0027.009]
|
||||
- Cryptographic Hash [C0029]
|
||||
- Cryptographic Hash::Tiger [C0029.005]
|
||||
- Cryptographic Hash::SHA1 [C0029.002]
|
||||
- Cryptographic Hash::SHA256 [C0029.003]
|
||||
- Cryptographic Hash::MD5 [C0029.001]
|
||||
- Cryptographic Hash::SHA224 [C0029.004]
|
||||
- Hashed Message Authentication Code [C0061]
|
||||
- Generate Pseudo-random Sequence::Use API [C0021.003]
|
||||
- Generate Pseudo-random Sequence::Mersenne Twister [C0021.005]
|
||||
- Crypto Library [C0059]
|
||||
|
||||
### Data: ###
|
||||
num: 15
|
||||
|
||||
- Checksum::CRC32 [C0032.001]
|
||||
- Checksum::Luhn [C0032.002]
|
||||
- Checksum::Adler [C0032.005]
|
||||
- Non-Cryptographic Hash::MurmurHash [C0030.001]
|
||||
- Non-Cryptographic Hash::FNV [C0030.005]
|
||||
- Non-Cryptographic Hash [C0030]
|
||||
- Encode Data::Base64 [C0026.001]
|
||||
- Decompress Data::aPLib [C0025.003]
|
||||
- Decompress Data::IEncodingFilterFactory [C0025.002]
|
||||
- Compress Data [C0024]
|
||||
- Decompress Data::QuickLZ [C0025.001]
|
||||
- Decompress Data [C0025]
|
||||
- Check String [C0019]
|
||||
- Modulo [C0058]
|
||||
- Compression Library [C0060]
|
||||
|
||||
### File System: ###
|
||||
num: 11
|
||||
|
||||
- Set File Attributes [C0050]
|
||||
- Create Directory [C0046]
|
||||
- Delete File [C0047]
|
||||
- Delete Directory [C0048]
|
||||
- Get File Attributes [C0049]
|
||||
- Move File [C0063]
|
||||
- Writes File [C0052]
|
||||
- Copy File [C0045]
|
||||
- Read File [C0051]
|
||||
- Read Virtual Disk [C0056]
|
||||
- Create File [C0016]
|
||||
|
||||
### Hardware: ###
|
||||
num: 4
|
||||
|
||||
- Simulate Hardware::Ctrl-Alt-Del [C0057.001]
|
||||
- Install Driver [C0037]
|
||||
- Install Driver::Minifilter [C0037.001]
|
||||
- Load Driver::Minifilter [C0023.001]
|
||||
|
||||
### Memory: ###
|
||||
num: 2
|
||||
|
||||
- Free Memory [C0044]
|
||||
- Allocate Memory [C0007]
|
||||
|
||||
### Operating System: ###
|
||||
num: 11
|
||||
|
||||
- Environment Variable::Set Variable [C0034.001]
|
||||
- Environment Variable::Get Variable [C0034.002]
|
||||
- Wallpaper [C0035]
|
||||
- Console [C0033]
|
||||
- Registry::Set Registry Key [C0036.001]
|
||||
- Registry::Create Registry Key [C0036.004]
|
||||
- Registry::Open Registry Key [C0036.003]
|
||||
- Registry::Query Registry Key [C0036.005]
|
||||
- Registry::Query Registry Value [C0036.006]
|
||||
- Registry::Delete Registry Key [C0036.002]
|
||||
- Registry::Delete Registry Value [C0036.007]
|
||||
|
||||
### Process: ###
|
||||
num: 14
|
||||
|
||||
- Create Thread [C0038]
|
||||
- Suspend Thread [C0055]
|
||||
- Terminate Thread [C0039]
|
||||
- Resume Thread [C0054]
|
||||
- Enumerate Threads [C0064]
|
||||
- Create Mutex [C0042]
|
||||
- Check Mutex [C0043]
|
||||
- Allocate Thread Local Storage [C0040]
|
||||
- Set Thread Local Storage Value [C0041]
|
||||
- Create Process [C0017]
|
||||
- Create Process::Create Suspended Process [C0017.003]
|
||||
- Terminate Process [C0018]
|
||||
- Open Process [C0065]
|
||||
- Open Thread [C0066]
|
||||
|
||||
@@ -1,13 +1,16 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**OB0003**|
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>OB0003</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
# Collection #
|
||||
Behaviors that identify and gather information, such as sensitive files, from a target network prior to exfiltration. This objective includes locations on a system or network where the malware may look for information to exfiltrate.
|
||||
Behaviors that enable malware to identify and gather information, such as sensitive files, from a machine or network. Sources often targeted include drives, browsers, audio/video, and email. Often the malware's next objective is to exfiltrate the information gathered.
|
||||
|
||||
* **Cryptocurrency** [B0028](../collection/cryptocurrency.md)
|
||||
* **Hooking** [F0003](../credential-access/hooking.md)
|
||||
* **Hijack Execution Flow** [F0015](../defense-evasion/hijack-execution-flow.md)
|
||||
* **Input Capture** [E1056](../collection/input-capture.md)
|
||||
* **Keylogging** [F0002](../collection/keylogging.md)
|
||||
* **Screen Capture** [E1113](../collection/screen-capture.md)
|
||||
|
||||
@@ -1,8 +1,18 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0028**|
|
||||
|**Objective(s)**|[Collection](../collection), [Credential Access](../credential-access)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0028</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../collection">Collection</a>, <a href="../credential-access">Credential Access</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Cryptocurrency
|
||||
|
||||
@@ -1,15 +1,25 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1056**|
|
||||
|**Objective(s)**|[Collection](../collection), [Credential Access](../credential-access)|
|
||||
|**Related ATT&CK Technique**|[Input Capture](https://attack.mitre.org/techniques/T1056)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1056</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../collection">Collection</a>, <a href="../credential-access">Credential Access</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Input Capture (<a href="https://attack.mitre.org/techniques/T1056">T1056</a>, <a href="https://attack.mitre.org/techniques/T1417/">T1417</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Input Capture
|
||||
=============
|
||||
Malware captures user input.
|
||||
|
||||
**See ATT&CK:** [**Input Capture**](https://attack.mitre.org/techniques/T1056).
|
||||
See ATT&CK: **Input Capture ([T1056](https://attack.mitre.org/techniques/T1056), [T1417](https://attack.mitre.org/techniques/T1417/))**.
|
||||
|
||||
Methods
|
||||
-------
|
||||
@@ -21,4 +31,17 @@ Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|Captures input.|
|
||||
|[**Rombertik**](../xample-malware/rombertik.md)|2015|The malware injects itself into a browser and captures user input data [[1]](#1)|
|
||||
|[**Ursnif**](../xample-malware/ursnif.md)|2016|Injects HTML into browser session to collect sensitive online banking information when the victim performs their online banking [[2]](#2)|
|
||||
|[**DarkComet**](../xample-malware/dark-comet.md)|2008|Can capture audio and video [[3]](#3)|
|
||||
|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|Can capture audio and video [[4]](#4)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://blogs.cisco.com/security/talos/rombertik
|
||||
|
||||
<a name="2">[2]</a> https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/BKDR_URSNIF.SM?_ga=2.129468940.1462021705.1559742358-1202584019.1549394279
|
||||
|
||||
<a name="3">[3]</a> https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/
|
||||
|
||||
<a name="4">[4]</a> https://www.cyber.nj.gov/threat-center/threat-profiles/trojan-variants/poison-ivy
|
||||
|
||||
@@ -1,15 +1,25 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**F0002**|
|
||||
|**Objective(s)**|[Collection](../collection), [Credential Access](../credential-access)|
|
||||
|**Related ATT&CK Sub-Technique**|[Input Capture: Keylogging](https://attack.mitre.org/techniques/T1056/001)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>F0002</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../collection">Collection</a>, <a href="../credential-access">Credential Access</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Input Capture: Keylogging (<a href="https://attack.mitre.org/techniques/T1056/001">T1056.001</a>, <a href="https://attack.mitre.org/techniques/T1417/001/">T1417.001</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Keylogging
|
||||
==========
|
||||
Malware captures user keyboard input.
|
||||
|
||||
**See ATT&CK:** [**Input Capture: Keylogging**](https://attack.mitre.org/techniques/T1056/001).
|
||||
See ATT&CK: **Input Capture: Keylogging ([T1056.001](https://attack.mitre.org/techniques/T1056/001), [T1417.001](https://attack.mitre.org/techniques/T1417/001/))**
|
||||
|
||||
Methods
|
||||
-------
|
||||
@@ -17,3 +27,26 @@ Methods
|
||||
|---|---|---|
|
||||
|**Application Hook**|F0002.001|Keystrokes are captured with an application hook.|
|
||||
|**Polling**|F0002.002|Keystrokes are captured via polling (e.g., user32.GetAsyncKeyState, user32.GetKeyState).|
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Hupigon**](../xample-malware/hupigon.md)|2013|Certain variants of the malware may have keylogging functionality [[1]](#1)|
|
||||
|[**UP007**](../xample-malware/up007.md)|2016|The malware logs keystrokes to a file [[2]](#2)|
|
||||
|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|Keylogger plugin allows for collection of keystrokes [[3]](#3)|
|
||||
|[**DarkComet**](../xample-malware/dark-comet.md)|2008|DarkComet can capture keystrokes [[4]](#4)|
|
||||
|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|Can capture keystrokes [[5]](#5)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.f-secure.com/v-descs/backdoor_w32_hupigon.shtml
|
||||
|
||||
<a name="2">[2]</a> https://citizenlab.ca/2016/04/between-hong-kong-and-burma/
|
||||
|
||||
<a name="3">[3]</a> https://securelist.com/be2-custom-plugins-router-abuse-and-target-profiles/67353/
|
||||
|
||||
<a name="4">[4]</a> https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/
|
||||
|
||||
<a name="5">[5]</a> https://www.cyber.nj.gov/threat-center/threat-profiles/trojan-variants/poison-ivy
|
||||
|
||||
@@ -1,18 +1,45 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1113**|
|
||||
|**Objective(s)**|[Collection](../collection), [Credential Access](../credential-access)|
|
||||
|**Related ATT&CK Technique**|[Screen Capture](https://attack.mitre.org/techniques/T1113/)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1113</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../collection">Collection</a>, <a href="../credential-access">Credential Access</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Screen Capture (<a href="https://attack.mitre.org/techniques/T1113/">T1113</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Screen Capture
|
||||
=============
|
||||
Malware takes screen captures of the desktop.
|
||||
|
||||
**See ATT&CK:** [**Screen Capture**](https://attack.mitre.org/techniques/T1113/).
|
||||
See ATT&CK: **Screen Capture ([T1113](https://attack.mitre.org/techniques/T1113/))**.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**WinAPI**|E1113.m01|Screen is captured using WinAPI functions (e.g., user32.GetDesktopWindow).|
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**GotBotKR**](../xample-malware/gotbotkr.md)|2019| GoBotKR is capable of capturing screenshots. [[1]](#1)|
|
||||
|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|Screenshot plugin allows for collection of screenshots [[2]](#2)|
|
||||
|[**DarkComet**](../xample-malware/dark-comet.md)|2008|Can take screenshots of victim's computer [[3]](#3)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/
|
||||
|
||||
<a name="2">[2]</a> https://securelist.com/be2-custom-plugins-router-abuse-and-target-profiles/67353/
|
||||
|
||||
<a name="3">[3]</a> https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/
|
||||
|
||||
@@ -1,11 +1,25 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**OB0004**|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>OB0004</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
# Command and Control
|
||||
Behaviors malware may use to communicate with systems under its control within a target network. There are many ways malware can establish command and control with various levels of covertness, depending on system configuration and network topology. Behaviors may relate to C2 servers or a bot that is part of a botnet. As "server" and "client" are confusing terminology in this context, we use the terms **controller** and **implant**. The controller is the software running on adversary-controlled infrastructure and used to send commands to the implant. The implant is the software running on victim-controlled infrastructure that receives commands from the adversary, executes those commands on the victim, and optionally sends the results back to the adversary.
|
||||
Behaviors that enable malware to communicate with systems such as C2 servers or bots. Malware can establish command and control with various levels of covertness, depending on system configuration and network topology.
|
||||
|
||||
* **Command and Control Communication** [B0030](../command-and-control/command-control-comm.md)
|
||||
* **Domain Name Generation** [B0031](../command-and-control/domain-name-generate.md)
|
||||
* **Remote File Copy** [E1105](../command-and-control/remote-file-copy.md)
|
||||
* **Command and Control Communication** [B0030](../command-and-control/c2-communication.md)
|
||||
* **Domain Name Generation** [B0031](../command-and-control/domain-name-generation.md)
|
||||
* **Ingress Tool Transfer** [E1105](../command-and-control/ingress-tool-transfer.md)
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**TrickBot**](../command-and-control/README.md)|2016| new email addresses are collected automatically from the victim's address books [[1]](#1)|
|
||||
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.bitdefender.com/blog/labs/trickbot-is-dead-long-live-trickbot/
|
||||
|
||||
+50
-8
@@ -1,24 +1,36 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0030**|
|
||||
|**Objective(s)**|[Command and Control](../command-and-control)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0030</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../command-and-control">Command and Control</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
C2 Communication
|
||||
================
|
||||
All command and control malware use implant/controller communication. The methods listed below can be used to capture explicit communication details. Remote file copy behavior is captured separately, as is done in ATT&CK - see [Remote File Copy](../command-and-control/remote-file-copy.md).
|
||||
All command and control malware use implant/controller communication. The methods listed below can be used to capture explicit communication details. Remote file copy behavior is captured separately, as is done in ATT&CK - see **Ingress Tool Transfer ([E1105](../command-and-control/ingress-tool-transfer.md))**.
|
||||
|
||||
Command and Control Communication relates to *autonomous* communications, not explicit, on-demand commands that malware provides to an adversary (such commands should be captured with [Remote Commands](../execution/remote-commands.md) under the Execution objective).
|
||||
|
||||
As "server" and "client" are confusing terminology, we use the terms "controller" and "implant". The controller is the software running on adversary-controlled infrastructure and used to send commands to the implant. The implant is the software running on victim-controlled infrastructure that receives commands from the adversary, executes those commands on the victim, and optionally sends the results back to the adversary.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Authenticate**|B0030.011|Implant may authenticate itself to the controller, controller may authenticate itself to implant, or both. This is often at or near the start of communication. Examples include but are not limited to a simple shared secret (e.g. password), challenge-response with symmetric encryption, or challenge-response with asymmetric encryption.|
|
||||
|**Check for Payload**|B0030.005|Check for payload.|
|
||||
|**Check for Payload**|B0030.005|An implant may check with the controller for additional payloads or instructions, sometimes at a regular interval. This is also known as beaconing.|
|
||||
|**Directory Listing**|B0030.012|Controller requests a directory listing from the implant, optionally from a given path, optionally recursive.|
|
||||
|**Execute File**|B0030.013|Execute/run/open the file using default operating system functionality, optionally with provided command-line arguments. The file may or may not already exist on the victim.|
|
||||
|**Execute File**|B0030.013|Execute/run/open the file using default operating system functionality, optionally with provided command-and-scripting-interpreter arguments. The file may or may not already exist on the victim.|
|
||||
|**Execute Shell Command**|B0030.014|Execute/run the given command using a built-in program (e.g. cmd.exe, PowerShell, bash). This differs from Start Interactive Shell because the shell process is started only for the received command or set of commands and then exits. There is no loop looking for additional commands while the shell process is still running.|
|
||||
|**File search**|B0030.015|Controller requests the implant to search for a given filename pattern, often a [glob](https://en.wikipedia.org/wiki/Glob_(programming)).|
|
||||
|**Implant to Controller File Transfer**|B0030.004|File is transferred from implant to controller.|
|
||||
@@ -32,6 +44,20 @@ Methods
|
||||
|**Server to Client File Transfer**|B0030.003|File is transferred from controller to implant.|
|
||||
|**Start Interactive Shell**|B0030.016|Start an interactive shell using a built-in program (e.g. cmd.exe, PowerShell, bash). This is often implemented with polling the network connection from the controller for text commands to redirect to the shell's stdin and polling the shell's stdout and stderr to redirect over the network to the controller. This differs from Execute Shell Command because the shell process runs across multiple iterations of the recv-command(s)-send-result loop.|
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**CryptoWall**](../xample-malware/cryptowall.md)|2014|The malware sends a hash value generated from system information [[1]](#1)|
|
||||
|[**GotBotKR**](../xample-malware/gotbotkr.md)|2019|GoBotKR receives data from the C2 [[2]](#2)|
|
||||
|[**Terminator**](../xample-malware/terminator.md)|2013|The malware sends data to C2 [[3]](#3)|
|
||||
|[**UP007**](../xample-malware/up007.md)|2016|The malware receives payloads [[4]](#4)|
|
||||
|[**YiSpecter**](../xample-malware/yispecter.md)|2015|Connects to the command and control server using HTTP to send device information [[5]](#5)|
|
||||
|[**Ursnif**](../xample-malware/ursnif.md)|2016|Ursnif variant Dreambot authenticates and encrypts traffic to C2 server using TOR [[6]](#6)|
|
||||
|[**Emotet**](../xample-malware/emotet.md)|2018|New email addresses are collected automatically from the victim's address books [[7]](#7)|
|
||||
|
||||
|
||||
Code Snippets
|
||||
-------------
|
||||
**C2 Communication::Receive Data** (B0030.02)
|
||||
@@ -50,3 +76,19 @@ call recv
|
||||
jmp short loc_4019A2
|
||||
```
|
||||
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://news.sophos.com/en-us/2015/12/17/the-current-state-of-ransomware-cryptowall/
|
||||
|
||||
<a name="2">[2]</a> https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/
|
||||
|
||||
<a name="3">[3]</a> https://www.mandiant.com/resources/hot-knives-through-butter-evading-file-based-sandboxes
|
||||
|
||||
<a name="4">[4]</a> https://citizenlab.ca/2016/04/between-hong-kong-and-burma/
|
||||
|
||||
<a name="5">[5]</a> http://researchcenter.paloaltonetworks.com/2015/10/yispecter-first-ios-malware-attacks-non-jailbroken-ios-devices-by-abusing-private-apis/
|
||||
|
||||
<a name="6">[6]</a> https://www.proofpoint.com/us/threat-insight/post/ursnif-variant-dreambot-adds-tor-functionality
|
||||
|
||||
<a name="7">[7]</a> https://securelist.com/the-banking-trojan-emotet-detailed-analysis/69560/
|
||||
@@ -1,27 +0,0 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0031**|
|
||||
|**Objective(s)**|[Command and Control](../command-and-control)|
|
||||
|**Related ATT&CK Sub-Technique**|[Dynamic Resolution: Domain Generation Algorithms](https://attack.mitre.org/techniques/T1568/002/)|
|
||||
|
||||
|
||||
Domain Name Generation
|
||||
======================
|
||||
Malware generates the domain name of the controller to which it connects. Access to on the fly domains enables C2 to operate as domains and IP addresses are blocked. The algorithm can be complicated in more advanced implants; understanding the details so that names can be predicted can be useful in mitigation and response. [[1]](#1)
|
||||
|
||||
The subsequently defined ATT&CK sub-technique [Dynamic Resolution: Domain Generation Algorithms](https://attack.mitre.org/techniques/T1568/002/), which is oriented toward an adversary perspective (although its examples include malware), is related to this MBC behavior.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Kraken**](../xample-malware/kraken.md)|April 2008|Kraken uses a domain generating algorithm to provide new domains. [[2]](#2)|
|
||||
|[**Conficker**](../xample-malware/conficker.md)|November 2008|Conficker uses a domain name generator. [[3]](#3)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://blog.malwarebytes.com/security-world/2016/12/explained-domain-generating-algorithm/
|
||||
|
||||
<a name="2">[2]</a> http://blog.threatexpert.com/2008/04/kraken-changes-tactics.html
|
||||
|
||||
<a name="3">[3]</a> https://en.wikipedia.org/wiki/Conficker
|
||||
@@ -0,0 +1,43 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0031</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../command-and-control">Command and Control</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Dynamic Resolution: Domain Generation Algorithms (<a href="https://attack.mitre.org/techniques/T1568/002/">T1568.002</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Domain Name Generation
|
||||
======================
|
||||
Malware generates the domain name of the controller to which it connects. Access to on the fly domains enables C2 to operate as domains and IP addresses are blocked. The algorithm can be complicated in more advanced implants; understanding the details so that names can be predicted can be useful in mitigation and response. [[1]](#1)
|
||||
|
||||
The related **Dynamic Resolution: Domain Generation Algorithms ([T1568.002](https://attack.mitre.org/techniques/T1568/002/))** ATT&CK sub-technique (oriented toward an adversary perspective with examples that include malware) was defined subsequent to this MBC behavior.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Kraken**](../xample-malware/kraken.md)|April 2008|Kraken uses a domain generating algorithm to provide new domains. [[2]](#2)|
|
||||
|[**Conficker**](../xample-malware/conficker.md)|November 2008|Conficker uses a domain name generator. [[3]](#3)|
|
||||
|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|The malware sends a hash value generated from system information [[4]](#4|
|
||||
|[**Ursnif**](../xample-malware/ursnif.md)|2016|Ursnif has used a Domain name generation algorithm in the past [[5]](#5)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://blog.malwarebytes.com/security-world/2016/12/explained-domain-generating-algorithm/
|
||||
|
||||
<a name="2">[2]</a> http://blog.threatexpert.com/2008/04/kraken-changes-tactics.html
|
||||
|
||||
<a name="3">[3]</a> https://en.wikipedia.org/wiki/Conficker
|
||||
|
||||
<a name="4">[4]</a> https://www.secureworks.com/research/cryptolocker-ransomware
|
||||
|
||||
<a name="5">[5]</a> https://www.proofpoint.com/us/threat-insight/post/ursnif-variant-dreambot-adds-tor-functionality
|
||||
@@ -0,0 +1,47 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1105</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../command-and-control">Command and Control</a>, <a href="../lateral-movement">Lateral Movement</a>, <a href="../persistence">Persistence</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Ingress Tool Transfer (<a href="https://attack.mitre.org/techniques/T1105/">T1105</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Ingress Tool Transfer
|
||||
================
|
||||
Malware may copy files from an external system to a system on a compromised network.
|
||||
|
||||
Note that this behavior is separate from possible execution (installation) of the file, which is covered by the **Install Additional Program ([B0023](../execution/install-additional-program.md))** behavior.
|
||||
|
||||
See ATT&CK: **Ingress Tool Transfer ([T1105](https://attack.mitre.org/techniques/T1105/))**.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|After the Poison-Ivy implant is running on the target machine, the attacker can use a Windows GUI controller to control the target computer. [[1]](#1)|
|
||||
|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|The malware receives a public key from the C2 [[2]](#2)|
|
||||
|[**Gamut**](../xample-malware/gamut.md)|2014|The malware receives data from C2 [[3]](#3)|
|
||||
|[**DarkComet**](../xample-malware/dark-comet.md)|2008|Can download files from remote repository upon instruction [[4]](#4)|
|
||||
|[**Shamoon**](../xample-malware/shamoon.md)|2012|Creates a folder on remote computers and then copies its executables (Shamoon and Filerase) into that directory [[5]](#5)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
|
||||
|
||||
<a name="2">[2]</a> https://www.secureworks.com/research/cryptolocker-ransomware
|
||||
|
||||
<a name="3">[3]</a> https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/gamut-spambot-analysis/
|
||||
|
||||
<a name="4">[4]</a> https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/
|
||||
|
||||
<a name="5">[5]</a> https://www.mcafee.com/blogs/other-blogs/mcafee-labs/shamoon-attackers-employ-new-tool-kit-to-wipe-infected-systems/
|
||||
@@ -1,25 +0,0 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1105**|
|
||||
|**Objective(s)**|[Command and Control](../command-and-control), [Lateral Movement](../lateral-movement), [Persistence](../persistence)|
|
||||
|**Related ATT&CK Technique**|[Ingress Tool Transfer](https://attack.mitre.org/techniques/T1105/)|
|
||||
|
||||
|
||||
Remote File Copy
|
||||
================
|
||||
Malware may copy files from one system to another.
|
||||
|
||||
Note that this behavior is separate from possible execution (installation) of the file, which is covered by the [Install Additional Program](../execution/install-prog.md) behavior.
|
||||
|
||||
**See ATT&CK:** [**Ingress Tool Transfer**](https://attack.mitre.org/techniques/T1105/).
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|After the Poison-Ivy implant is running on the target machine, the attacker can use a Windows GUI controller to control the target computer. [[1]](#1)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
|
||||
@@ -1,13 +1,14 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**OB0005**|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>OB0006</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
# Credential Access
|
||||
Behaviors to obtain credential access, allowing it or its underlying threat actor to assume control of an account, with the associated system and network permissions.
|
||||
Behaviors to obtain credential access, allowing it or its underlying threat actor to assume control of an account with the associated system and network permissions.
|
||||
|
||||
* **Cryptocurrency** [B0028](../collection/cryptocurrency.md)
|
||||
* **Hooking** [F0003](../credential-access/hooking.md)
|
||||
* **Input Capture** [E1056](../collection/input-capture.md)
|
||||
* **Keylogging** [F0002](../collection/keylogging.md)
|
||||
* **Screen Capture** [E1113](../collection/screen-capture.md)
|
||||
|
||||
@@ -1,42 +0,0 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**F0003**|
|
||||
|**Objective(s)**|[Anti-Behavioral Analysis](../anti-behavioral-analysis), [Collection](../collection), [Credential Access](../credential-access), [Defense Evasion](../defense-evasion), [Persistence](../persistence), [Privilege Escalation](../privilege-escalation)|
|
||||
|**Related ATT&CK Sub-Technique**|[Input Capture: Credential API Hooking](https://attack.mitre.org/techniques/T1056/004/)|
|
||||
|
||||
|
||||
Hooking
|
||||
=======
|
||||
Malware alters API behavior or redirects execution to a malicious API version for a variety of purposes. Malware may use hooking to load and execute code within the context of another process, hiding execution and gaining elevated privileges and access to the process's memory. Methods related to anti-behavioral analysis are below. For example, hooking can be used to prevent memory dumps - see also [Memory Dump Evasion](../anti-behavioral-analysis/evade-memory-dump.md).
|
||||
|
||||
For discussion related to the Credential Access and Collection objectives, see ATT&CK: [**Input Capture: Credential API Hooking**](https://attack.mitre.org/techniques/T1056/004/).
|
||||
|
||||
Note that in MBC, Hooking is also associated with the [Defense Evasion](../defense-evasion), [Persistence](../persistence), [Privilege Escalation](../privilege-escalation), and [Anti-Behavioral Analysis](../anti-behavioral-analysis) objectives.
|
||||
|
||||
For hooking related to memory dump evasion, see [Memory Dump Evasion](../anti-behavioral-analysis/evade-memory-dump.md).
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Procedure Hooking**|F0003.003|Intercepts and executes designated code in response to events such as messages, keystrokes, and mouse inputs. [[1]](#1)|
|
||||
|**Inline Patching**|F0003.002|Overwrites the first bytes in an API function to redirect code flow.|
|
||||
|**Export Address Table (EAT) Hooking**|F0003.006|Hooks the export address table (EAT).|
|
||||
|**Import Address Table (IAT) Hooking**|F0003.001|Modifies a process's import address table (IAT), which stores pointers to imported API functions.|
|
||||
|**System Service Dispatch Table Hooking**|F0003.004|Hooks the system service dispatch table (SSDT), also called the system service descriptor table. The SSDT contains information about the service tables used by the operating system for dispatching system calls. Hooking the SSDT enables malware to hide files, registry keys, and network connections.|
|
||||
|**Shadow SDT Hooking**|F0003.005|Hooks the Shadow SSDT similarly to how the SSDT and IAT are hooked. The target of the hooking with the Shadow SSDT is the Windows subsystem (win32k.sys).|
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|**Kronos**|June 2014|Kronos hooks the API of processes to prevent detection. [[2]](#2)|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://docs.microsoft.com/en-us/windows/win32/winmsg/about-hooks?redirectedfrom=MSDN#hook-procedures
|
||||
|
||||
<a name="2">[2]</a> https://blog.malwarebytes.com/cybercrime/2017/08/inside-kronos-malware/
|
||||
|
||||
|
||||
+19
-17
@@ -1,28 +1,30 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**OB0006**|
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>OB0006</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
# Defense Evasion #
|
||||
Behaviors that evade detection or avoid other defenses.
|
||||
Behaviors that enable malware to evade detection.
|
||||
|
||||
* **Alternative Installation Location** [B0027](../defense-evasion/alter-install-location.md)
|
||||
* **Bootkit** [F0013](../defense-evasion/boot-sector-mod.md)
|
||||
* **Bypass DEP** [B0037](../defense-evasion/bypass-dep.md)
|
||||
* **Alternative Installation Location** [B0027](../defense-evasion/alternative-installation-location.md)
|
||||
* **Bootkit** [F0013](../defense-evasion/bootkit.md)
|
||||
* **Bypass DEP** [B0037](../defense-evasion/bypass-data-execution-prevention.md)
|
||||
* **Component Firmware** [F0009](../persistence/component-firmware.md)
|
||||
* **Conditional Execution** [B0025](../execution/conditional-execute.md)
|
||||
* **Conditional Execution** [B0025](../execution/conditional-execution.md)
|
||||
* **Covert Location** [B0040](../defense-evasion/covert-location.md)
|
||||
* **Disable or Evade Security Tools** [F0004](../defense-evasion/disable-security-tools.md)
|
||||
* **Disable or Evade Security Tools** [F0004](../defense-evasion/disable-or-evade-security-tools.md)
|
||||
* **Hide Artifacts** [E1564](../defense-evasion/hide-artifacts.md)
|
||||
* **Hidden Files and Directories** [F0005](../defense-evasion/hidden-files.md)
|
||||
* **Hijack Execution Flow** [E1574](../defense-evasion/hijack-execution-flow.md)
|
||||
* **Hooking** [F0003](../credential-access/hooking.md)
|
||||
* **Hidden Files and Directories** [F0005](../defense-evasion/hidden-files-and-directories.md)
|
||||
* **Hijack Execution Flow** [F0015](../defense-evasion/hijack-execution-flow.md)
|
||||
* **Indicator Blocking** [F0006](../defense-evasion/indicator-blocking.md)
|
||||
* **Install Insecure or Malicious Configuration** [E1478](../defense-evasion/config-mod.md)
|
||||
* **Modify Registry** [E1112](../defense-evasion/modify-reg.md)
|
||||
* **Obfuscated Files or Information** [E1027](../defense-evasion/obfuscate-files.md)
|
||||
* **Install Insecure or Malicious Configuration** [B0047](../defense-evasion/install-insecure-or-malicious-configuration.md)
|
||||
* **Modify Registry** [E1112](../defense-evasion/modify-registry.md)
|
||||
* **Obfuscated Files or Information** [E1027](../defense-evasion/obfuscated-files-or-information.md)
|
||||
* **Polymorphic Code** [B0029](../defense-evasion/polymorphic-code.md)
|
||||
* **Process Injection** [E1055](../defense-evasion/process-inject.md)
|
||||
* **Rootkit** [E1014](../defense-evasion/rootkit-behavior.md)
|
||||
* **Process Injection** [E1055](../defense-evasion/process-injection.md)
|
||||
* **Rootkit** [E1014](../defense-evasion/rootkit.md)
|
||||
* **Self Deletion** [F0007](../defense-evasion/self-deletion.md)
|
||||
* **Software Packing** [F0001](../anti-static-analysis/software-packing.md)
|
||||
|
||||
+18
-5
@@ -1,8 +1,18 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0027**|
|
||||
|**Objective(s)**|[Defense Evasion](../defense-evasion)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0027</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../defense-evasion">Defense Evasion</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Alternative Installation Location
|
||||
@@ -21,7 +31,10 @@ Malware Examples
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Kovter**](../xample-malware/kovter.md)|2016|Stores malware files in the Registry instead of the hard drive. [[1]](#1)|
|
||||
|[**SYNfulKnock**](../xample-malware/synful-knock.md)|2015|100 memory-resident modules can be installed [[2]](#2)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.bleepingcomputer.com/virus-removal/remove-kovter-trojan
|
||||
|
||||
<a name="2">[2]</a> https://www.mandiant.com/resources/synful-knock-acis
|
||||
@@ -1,22 +0,0 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**F0013**|
|
||||
|**Objective(s)**|[Defense Evasion](../defense-evasion), [Persistence](../persistence)|
|
||||
|**Related ATT&CK Sub-Technique**|[Pre-OS Boot: Bootkit](https://attack.mitre.org/techniques/T1542/003)|
|
||||
|
||||
|
||||
Bootkit
|
||||
=======
|
||||
The boot sectors of a hard drive are modified (e.g., Master Boot Record (MBR)). ATT&CK associates bootkits with the Persistence. See ATT&CK: [**Pre-OS Boot: Bootkit**](https://attack.mitre.org/techniques/T1067/).
|
||||
|
||||
The MBC also associates the Bootkit behavior with Defense Evasion because the malware may execute before or external to the system's kernel or hypervisor (e.g., through the BIOS), making it more difficult to detect. (As of 2020, ATT&CK also associates the technique with Persistence.)
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Mebromi**](../xample-malware/mebromi.md)|2011|An MBR bootkit and a BIOS bootkit targeting Award BIOS. [[1]](#1)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.webroot.com/blog/2011/09/13/mebromi-the-first-bios-rootkit-in-the-wild/
|
||||
@@ -0,0 +1,35 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>F0013</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../defense-evasion">Defense Evasion</a>, <a href="../persistence">Persistence</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Pre-OS Boot: Bootkit (<a href="https://attack.mitre.org/techniques/T1542/003">T1542.003</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Bootkit
|
||||
=======
|
||||
The boot sectors of a hard drive are modified (e.g., Master Boot Record (MBR)). ATT&CK associates bootkits with the Persistence. See ATT&CK: **Pre-OS Boot: Bootkit ([T1067](https://attack.mitre.org/techniques/T1067/))**.
|
||||
|
||||
The MBC also associates the Bootkit behavior with Defense Evasion because the malware may execute before or external to the system's kernel or hypervisor (e.g., through the BIOS), making it more difficult to detect. (As of 2020, ATT&CK also associates the technique with Persistence.)
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Mebromi**](../xample-malware/mebromi.md)|2011|An MBR bootkit and a BIOS bootkit targeting Award BIOS. [[1]](#1)|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Can implement malicious code into firmware, allowing read, write, and/or erasure of the UEFI/BIOS firmware [[2]](#24)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.webroot.com/blog/2011/09/13/mebromi-the-first-bios-rootkit-in-the-wild/
|
||||
|
||||
<a name="2">[2]</a> https://eclypsium.com/wp-content/uploads/2020/12/TrickBot-Now-Offers-TrickBoot-Persist-Brick-Profit.pdf
|
||||
@@ -0,0 +1,38 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0037</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../defense-evasion">Defense Evasion</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Bypass Data Execution Prevention
|
||||
================================
|
||||
Malware may bypass Data Execution Prevention (DEP).
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**ROP Chains**|B0037.001|Return-Oriented Programming can be used to bypass DEP. It can also be used to bypass code signing. [[1]](#1)|
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|TrickBot has come with a signed downloader component [[2]](#2)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://medium.com/cybersecurityservices/dep-bypass-using-rop-chains-garima-chopra-e8b3361e50ce
|
||||
|
||||
<a name="2">[2]</a> https://www.cybereason.com/blog/research/dropping-anchor-from-a-trickbot-infection-to-the-discovery-of-the-anchor-malware
|
||||
@@ -1,20 +0,0 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0037**|
|
||||
|**Objective(s)**|[Defense Evasion](../defense-evasion)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
|
||||
Bypass Data Execution Prevention
|
||||
================================
|
||||
Malware may bypass Data Execution Prevention (DEP).
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**ROP Chains**|B0037.001|Return-Oriented Programming can be used to bypass DEP. It can also be used to bypass code signing. [[1]](#1)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://medium.com/cybersecurityservices/dep-bypass-using-rop-chains-garima-chopra-e8b3361e50ce
|
||||
@@ -1,12 +0,0 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1478**|
|
||||
|**Objective(s)**|[Defense Evasion](../defense-evasion), [Persistence](../persistence)|
|
||||
|**Related ATT&CK Technique**|[Install Insecure or Malicious Configuration](https://attack.mitre.org/techniques/T1478)|
|
||||
|
||||
|
||||
Install Insecure or Malicious Configuration
|
||||
===========================================
|
||||
Malware may install malicious configuration settings or may modify existing configuration settings. This MBC behavior extends the related ATT&CK technique to all platforms and to the Persistence objective.
|
||||
|
||||
See ATT&CK: [**Install Insecure or Malicious Configuration**](https://attack.mitre.org/techniques/T1478).
|
||||
@@ -1,8 +1,18 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0040**|
|
||||
|**Objective(s)**|[Defense Evasion](../defense-evasion)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0040</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../defense-evasion">Defense Evasion</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Covert Location
|
||||
@@ -14,4 +24,4 @@ Methods
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Hide Data in Registry**|B0040.001|Malware may use a registry key to store a long sequence of bytes.|
|
||||
|**Steganography**|B0040.002|Malware may store information in an image.|
|
||||
|**Steganography**|B0040.002|Malware may store information in an image. See related ATT&CK techniques: Data Obfuscation: Steganography [T1001.002](https://attack.mitre.org/techniques/T1001/002), Obfuscated Files or Information: Steganography ([T1027.003](https://attack.mitre.org/techniques/T1027/003), [T1406.001](https://attack.mitre.org/techniques/T1406/001)).|
|
||||
|
||||
+17
-7
@@ -1,8 +1,18 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**F0004**|
|
||||
|**Objective(s)**|[Defense Evasion](../defense-evasion)|
|
||||
|**Related ATT&CK Sub-Technique**|[Impair Defenses: Disable or Modify Tools](https://attack.mitre.org/techniques/T1562/001/)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>F0004</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../defense-evasion">Defense Evasion</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Impair Defenses: Disable or Modify Tools (<a href="https://attack.mitre.org/techniques/T1562/001">T1562.001</a>, <a href="https://attack.mitre.org/techniques/T1629/003/">T1629.003</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Disable or Evade Security Tools
|
||||
@@ -11,7 +21,7 @@ Malware may disable or evade security tools to avoid detection. Security tools i
|
||||
|
||||
Malware-related methods extending ATT&CK's definition are below.
|
||||
|
||||
See ATT&CK: [**Impair Defenses: Disable or Modify Tools**](https://attack.mitre.org/techniques/T1562/001).
|
||||
See ATT&CK: **Impair Defenses: Disable or Modify Tools ([T1562.001](https://attack.mitre.org/techniques/T1562/001), [T1629.003](https://attack.mitre.org/techniques/T1629/003/))**.
|
||||
|
||||
Methods
|
||||
-------
|
||||
@@ -22,7 +32,7 @@ Methods
|
||||
|**Disable System File Overwrite Protection**|F0004.002|Disables system file overwrite protection mechanisms such as Windows file protection, thereby enabling system files to be modified or replaced.|
|
||||
|**Force Lazy Writing**|F0004.006|Some operating systems will sometimes use a form of "lazy writing" for disk I/O, which may obscure the true provenance of the write operation. This method occurs when code intentionally forces the operating system to perform a lazy writing operation. For example, in Windows, a file may be opened, memory mapped, and closed, but the memory map will still exist and can be written to, which will cause a lazy write that looks like it is coming from the System process. [[3]](#3)|
|
||||
|**Heavens Gate**|F0004.008|Malware evades endpoint security products by invoking 64-bit code in 32-bit processes, effectively bypassing user-mode hooks. [[4]](#4)|
|
||||
|**Modify Policy**|F0004.005|Malware may modify policies to make software less effective.|
|
||||
|**Modify Policy**|F0004.005|Malware may modify policies to make software less effective. This is similar to ATT&CK's Subvert Trust Controls: Code Signing Policy Modification ([T1553.006](https://attack.mitre.org/techniques/T1553/006/), [T1632.001](https://attack.mitre.org/techniques/T1632/001/))|
|
||||
|**Unhook APIs**|F0004.003|Security products may hook APIs to monitor the behavior of malware. To avoid being found, malware may load DLLs in memory and overwrite their bytes.|
|
||||
|**Bypass Windows File Protection**|F0004.007|Malware bypasses Windows file protection.|
|
||||
|**Disable Code Integrity**|F0004.009|Malware disables Code Integrity driver.|
|
||||
@@ -0,0 +1,45 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>F0005</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../defense-evasion">Defense Evasion</a>, <a href="../persistence">Persistence</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Hide Artifacts: Hidden Files and Directories (<a href="https://attack.mitre.org/techniques/T1564/001/">T1564.001</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Hidden Files and Directories
|
||||
============================
|
||||
Malware may hide files and folders to avoid detection and/or to persist on the system. See potential methods below.
|
||||
|
||||
See ATT&CK: **Hide Artifacts: Hidden Files and Directories ([T1564.001](https://attack.mitre.org/techniques/T1564/001/))**.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Attribute**|F0005.003|Malware may change or choose an attribute to hide a file or directory.|
|
||||
|**Extension**|F0005.001|Malware may change or use a particular file extension to hide a file.|
|
||||
|**Location**|F0005.002|Malware may change or choose the location of itself, another file, or a directory to prevent detection.|
|
||||
|**Timestamp**|F0005.004|Malware may change the timestamp on a file to prevent detection.|
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**GotBotKR**](../xample-malware/gotbotkr.md)|2019| GoBotKR stores itself in a file with Hidden and System attributes. [[1]](#1)|
|
||||
|[**Shamoon**](../xample-malware/shamoon.md)|2012|Modifies target files' time to August 2012 as an antiforensic trick [[2]](#2)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/
|
||||
|
||||
<a name="2">[2]</a> https://www.mcafee.com/blogs/other-blogs/mcafee-labs/shamoon-returns-to-wipe-systems-in-middle-east-europe/
|
||||
@@ -1,22 +0,0 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**F0005**|
|
||||
|**Objective(s)**|[Defense Evasion](../defense-evasion), [Persistence](../persistence)|
|
||||
|**Related ATT&CK Sub-Technique**|[Hide Artifacts: Hidden Files and Directories](https://attack.mitre.org/techniques/T1564/001/)|
|
||||
|
||||
|
||||
Hidden Files and Directories
|
||||
============================
|
||||
Malware may hide files and folders to avoid detection and/or to persist on the system. See potential methods below.
|
||||
|
||||
See ATT&CK: [**Hide Artifacts: Hidden Files and Directories**](https://attack.mitre.org/techniques/T1564/001/).
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Attribute**|F0005.003|Malware may change or choose an attribute to hide a file or directory.|
|
||||
|**Extension**|F0005.001|Malware may change or use a particular file extension to hide a file.|
|
||||
|**Location**|F0005.002|Malware may change or choose the location of itself, another file, or a directory to prevent detection.|
|
||||
|**Timestamp**|F0005.004|Malware may change the timestamp on a file to prevent detection.|
|
||||
|
||||
@@ -1,15 +1,25 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1564**|
|
||||
|**Objective(s)**|[Defense Evasion](../defense-evasion), [Persistence](../persistence)|
|
||||
|**Related ATT&CK Technique**|[Hide Artifacts](https://attack.mitre.org/techniques/T1564)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1564</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../defense-evasion">Defense Evasion</a>, <a href="../persistence">Persistence</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Hide Artifacts (<a href="https://attack.mitre.org/techniques/T1564/">T1564</a>, <a href="https://attack.mitre.org/techniques/T1628/">T1628</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Hidden Artifacts
|
||||
================
|
||||
Hide Artifacts
|
||||
==============
|
||||
Malware may hide artifacts to evade detection and/or to persist on the system. See potential methods related to malware below.
|
||||
|
||||
See ATT&CK: [**Hide Artifacts**](https://attack.mitre.org/techniques/T1564/).
|
||||
See ATT&CK: **Hide Artifacts ([T1564](https://attack.mitre.org/techniques/T1564/), [T1628](https://attack.mitre.org/techniques/T1628/))**.
|
||||
|
||||
Methods
|
||||
-------
|
||||
@@ -21,3 +31,16 @@ Methods
|
||||
|**Hidden Processes**|E1564.m03|Hides processes used by the adversary or malware instance. This can involve techniques such as process list unlinking.|
|
||||
|**Hidden Services**|E1564.m04|Hides any system services that the malware instance creates or injects itself into. Services can be hidden by hiding associated registry keys.|
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**YiSpecter**](../xample-malware/yispecter.md)|2015|Hides icons from iOS's SpringBoard as well as use the same name and logos of system apps to trick iOS power users [[1]](#1)|
|
||||
|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|Stuxnet intercepts IRP requests (reads, writes) to devices (NFTS, FAT, CD-ROM). It monitors directory control IRPs, in particular directory query notifications such that when an application requests the list of files, it returns a Stuxnet-specified subset of the true items. These filters hide the files used by Stuxnet to spread through removalbe drives [[2]](#2)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> http://researchcenter.paloaltonetworks.com/2015/10/yispecter-first-ios-malware-attacks-non-jailbroken-ios-devices-by-abusing-private-apis/
|
||||
|
||||
<a name="2">[2]</a> https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en
|
||||
|
||||
@@ -1,15 +1,31 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**F0015**|
|
||||
|**Objective(s)**|[Defense Evasion](../defense-evasion), [Persistence](../persistence), [Privilege Escalation](../privilege-escalation)|
|
||||
|**Related ATT&CK Technique**|[Hijack Execution Flow](https://attack.mitre.org/techniques/T1574/)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>F0015</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a>, <a href="../collection">Collection</a>, <a href="../credential-access">Credential Access</a>, <a href="../defense-evasion">Defense Evasion</a>, <a href="../persistence">Persistence</a>, <a href="../privilege-escalation">Privilege Escalation</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Hijack Execution Flow (<a href="https://attack.mitre.org/techniques/T1574">T1574</a>, <a href="https://attack.mitre.org/techniques/T1625">T1625</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Hijack Execution Flow
|
||||
=====================
|
||||
Malware may execute by hijacking the way operating systems run programs. Malware (e.g. rootkit) alters API behavior or redirects execution to a malicious API version for a variety of purposes. Malware may use hooking to load and execute code within the context of another process, hiding execution and gaining elevated privileges and access to the process's memory. Different types of hooking are defined as methods below.
|
||||
Malware may execute by hijacking the way operating systems run programs. Malware (e.g. rootkit) alters API behavior or redirects execution (i.e., hooking) to a malicious API version for a variety of purposes. Malware may use hooking to load and execute code within the context of another process, hiding execution and gaining elevated privileges and access to the process's memory. Different types of hooking are defined as methods below.
|
||||
|
||||
See ATT&CK: [**Hijack Execution Flow**](https://attack.mitre.org/techniques/T1574/).
|
||||
Note that in MBC, Hooking is also associated with the [Defense Evasion](../defense-evasion), [Persistence](../persistence), [Privilege Escalation](../privilege-escalation), and [Anti-Behavioral Analysis](../anti-behavioral-analysis) objectives.
|
||||
|
||||
For discussion related to the Credential Access and Collection objectives, see **Input Capture: Credential API Hooking ([T1056.004](https://attack.mitre.org/techniques/T1056/004/))**.
|
||||
|
||||
For hooking related to memory dump evasion, see **Memory Dump Evasion ([B0006](../anti-behavioral-analysis/memory-dump-evasion.md))**.
|
||||
|
||||
See ATT&CK: **Hijack Execution Flow ([T1574](https://attack.mitre.org/techniques/T1574), [T1625](https://attack.mitre.org/techniques/T1625))**.
|
||||
|
||||
Methods
|
||||
-------
|
||||
@@ -18,10 +34,23 @@ Methods
|
||||
|**Abuse Windows Function Calls**|F0015.006|Malware abuses native Windows function calls to transfer execution to shellcode that it loads into memory. A pointer to the callback function is used to supply the memory address of the shellcode. Functions that can be abused include EnumResourceTypesA and EnumUILanguagesW. [[4]](#4)|
|
||||
|**Export Address Table (EAT) Hooking**|F0015.001|Malware (e.g. rootkit) hooks the export address table (EAT).|
|
||||
|**Import Address Table (IAT) Hooking**|F0015.003|Malware (e.g. rootkit) modifies a process's import address table (IAT), which stores pointers to imported API functions.[[1]](#1)|
|
||||
|**Inline Patching**|F0015.002|Inline patching (inline hooking) is done by modifying the beginning of a function in order to redirect the execution flow to custom code (i.e. redirecting code flow) before jumping back to the original function.[[2]](#2)|
|
||||
|**Inline Patching**|F0015.002|Inline patching (inline hooking) is done by modifying the beginning of a function (e.g., first bytes) in order to redirect the execution flow to custom code (i.e. redirecting code flow) before jumping back to the original function.[[2]](#2)|
|
||||
|**Procedure Hooking**|F0015.007|Intercepts and executes designated code in response to events such as messages, keystrokes, and mouse inputs. [[5]](#5)|
|
||||
|**Shadow System Service Dispatch Table Hooking**|F0015.004|The Shadow System Service Dispatch Table (SSDT) can be hooked similarly to how the SSDT and IAT are hooked. The target of the hooking with the Shadow SSDT is the Windows subsystem (win32k.sys).[[3]](#3)|
|
||||
|**System Service Dispatch Table Hooking**|F0015.005|Malware (e.g. rootkit, malicious drivers) may hook the system service dispatch table (SSDT), also called the system service descriptor table. The SSDT contains information about the service tables used by the operating system for dispatching system calls. Hooking the SSDT enables malware to hide files, registry keys, and network connections.[[3]](#3)|
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|**Kronos**|June 2014|Kronos hooks the API of processes to prevent detection. [[6]](#6)|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
|[**Ursnif**](../xample-malware/ursnif.md)|2016|Hooks various DLL exported functions when the component is loaded in their respective Browser application process is running to monitor network traffic [[7]](#7)|
|
||||
|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018| Abuses Microsoft's Dynamic Data Exchange (DDE) protocol [[8]](#8)|
|
||||
|[**SYNfulKnock**](../xample-malware/synful-knock.md)|2015|Hooks IOS functions to call and initialize the malware [[9]](#9)|
|
||||
|[**Shamoon**](../xample-malware/shamoon.md)|2012|Escalates privilege by impersonating the token. First uses LogonUser and ImpersonateLoggedOnUser, then ImpersonateNamedPipeClient. [[10]](#10)|
|
||||
|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|Stuxnet hooks ntdll.dll to monitor for requests to load specially crafted file names which are mapped to a location specified by Stuxnet. [[11]](#11)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.sans.org/media/score/checklists/rootkits-investigation-procedures.pdf
|
||||
@@ -32,3 +61,16 @@ References
|
||||
|
||||
<a name="4">[4]</a> http://ropgadget.com/posts/abusing_win_functions.html
|
||||
|
||||
<a name="5">[5]</a> https://docs.microsoft.com/en-us/windows/win32/winmsg/about-hooks?redirectedfrom=MSDN#hook-procedures
|
||||
|
||||
<a name="6">[6]</a> https://blog.malwarebytes.com/cybercrime/2017/08/inside-kronos-malware/
|
||||
|
||||
<a name="7">[7]</a> https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/PE_URSNIF.A2?_ga=2.131425807.1462021705.1559742358-1202584019.1549394279
|
||||
|
||||
<a name="8">[8]</a> https://blog.talosintelligence.com/2018/04/gravityrat-two-year-evolution-of-apt.html
|
||||
|
||||
<a name="9">[9]</a> https://www.mandiant.com/resources/synful-knock-acis
|
||||
|
||||
<a name="10">[10]</a> https://www.mcafee.com/blogs/other-blogs/mcafee-labs/shamoon-returns-to-wipe-systems-in-middle-east-europe/
|
||||
|
||||
<a name="11">[11]</a> https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en
|
||||
|
||||
@@ -1,18 +1,48 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**F0006**|
|
||||
|**Objective(s)**|[Defense Evasion](../defense-evasion)|
|
||||
|**Related ATT&CK Sub-Technique**|[Impair Defenses: Indicator Blocking](https://attack.mitre.org/techniques/T1562/006/)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>F0006</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../defense-evasion">Defense Evasion</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Impair Defenses: Indicator Blocking (<a href="https://attack.mitre.org/techniques/T1562/006/">T1562.006</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Indicator Blocking
|
||||
==================
|
||||
Malware blocks indicators or events that would indicate malicious activity. Methods relevant to the malware domain are below.
|
||||
|
||||
See ATT&CK: [**Impair Defenses: Indicator Blocking**](https://attack.mitre.org/techniques/T1562/006/).
|
||||
See ATT&CK: **Impair Defenses: Indicator Blocking ([T1562.006](https://attack.mitre.org/techniques/T1562/006/))**.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Remove SMS Warning Messages**|F0006.001|Malware captures the message body of incoming SMS messages and aborts displaying messages that meets a certain criteria.|
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|Clears windows event logs and removes the watermark associated with enabling the TESTSIGNING boot configuration option by removing the relevent strings in the user32.dll.mui of the system [[1]](#1)|
|
||||
|[**Conficker**](../xample-malware/conficker.md)|2008|Terminates various services related to system security and Windows and prevents network access to various websites related to antivirus software [[2]](#2)|
|
||||
|[**DarkComet**](../xample-malware/dark-comet.md)|2008|Can disable security center functions like anti-virus and firewall [[3]](#3)|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Terminates the following anti-malware services: Window Defender, MBamService (Malwarebytes), SAVService (Sophos AV) [[4]](#4)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://blog-assets.f-secure.com/wp-content/uploads/2019/10/15163408/BlackEnergy_Quedagh.pdf
|
||||
|
||||
<a name="2">[2]</a> https://en.wikipedia.org/wiki/Conficker
|
||||
|
||||
<a name="3">[3]</a> https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/
|
||||
|
||||
<a name="4">[4]</a> https://www.trendmicro.com/en_us/research/18/k/trickbot-shows-off-new-trick-password-grabber-module.html
|
||||
|
||||
@@ -0,0 +1,30 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0047</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../defense-evasion">Defense Evasion</a>, <a href="../persistence">Persistence</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Install Insecure or Malicious Configuration
|
||||
===========================================
|
||||
Malware may install malicious configuration settings or may modify existing configuration settings. For example, malware may change configuration settings associated with security mechanisms to make it difficult to detect or change configuration settings to maintain a foothold on the network.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Black Energy**](../xample-malware/blackenergy.md)|2007|Configures the system to the TESTSIGNING boot configuration option to load its unsigned driver component [[1]](#1)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://blog-assets.f-secure.com/wp-content/uploads/2019/10/15163408/BlackEnergy_Quedagh.pdf
|
||||
@@ -1,23 +0,0 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1112**|
|
||||
|**Objective(s)**|[Defense Evasion](../defense-evasion), [Persistence](../persistence)|
|
||||
|**Related ATT&CK Technique**|[Modify Registry](https://attack.mitre.org/techniques/T1112)|
|
||||
|
||||
|
||||
Modify Registry
|
||||
===============
|
||||
Malware may make changes to the Windows Registry to hide execution or to persist on the system (note that ATT&CK does not extend this behavior to the Persistence objective).
|
||||
|
||||
See ATT&CK: [**Modify Registry**](https://attack.mitre.org/techniques/T1112).
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[1]](#1)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
|
||||
@@ -0,0 +1,49 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1112</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../defense-evasion">Defense Evasion</a>, <a href="../persistence">Persistence</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Modify Registry<a href="https://attack.mitre.org/techniques/T1112">T1112</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Modify Registry
|
||||
===============
|
||||
Malware may make changes to the Windows Registry to hide execution or to persist on the system (note that ATT&CK does not extend this behavior to the Persistence objective).
|
||||
|
||||
|
||||
See ATT&CK: **Modify Registry ([T1112](https://attack.mitre.org/techniques/T1112/))**.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[1]](#1)|
|
||||
|[**GotBotKR**](../xample-malware/gotbotkr.md)|2019|GoBotKR can modify registry keys to disable Task Manager, Registry Editor and Command Prompt. [[2]](#2)|
|
||||
|[**Hupigon**](../xample-malware/hupigon.md)|2013|The malware adds many entries to the registry [[3]](#3)|
|
||||
|[**Gamut**](../xample-malware/gamut.md)|2014|The malware adds a registry key [[4]](#4)|
|
||||
|[**Kovter**](../xample-malware/kovter.md)|2016|The malware modifies the registry during execution [[5]](#5)|
|
||||
|[**Shamoon**](../xample-malware/shamoon.md)|2012|Disables remote user account control by enabling the registry key LocalAccountTokenFilterPolicy [[6]](#6)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
|
||||
|
||||
<a name="2">[2]</a> https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/
|
||||
|
||||
<a name="3">[3]</a> https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/HUPIGON
|
||||
|
||||
<a name="4">[4]</a> https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/gamut-spambot-analysis/
|
||||
|
||||
<a name="5">[5]</a> https://blog.malwarebytes.com/threat-analysis/2016/07/untangling-kovter/
|
||||
|
||||
<a name="6">[6]</a> https://www.mcafee.com/blogs/other-blogs/mcafee-labs/shamoon-returns-to-wipe-systems-in-middle-east-europe/
|
||||
+26
-8
@@ -1,19 +1,29 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1027**|
|
||||
|**Objective(s)**|[Anti-Static Analysis](../anti-static-analysis), [Defense Evasion](../defense-evasion)|
|
||||
|**Related ATT&CK Technique**|[Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1027</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../anti-static-analysis">Anti-Static Analysis</a>, <a href="../defense-evasion">Defense Evasion</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Obfuscated Files or Information (<a href="https://attack.mitre.org/techniques/T1027/">T1027</a>, <a href="https://attack.mitre.org/techniques/T1406/">T1406</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Obfuscated Files or Information
|
||||
===============================
|
||||
Malware may make files or information difficult to discover or analyze by encoding, encrypting, or otherwise obfuscating the content. In addition, a malware sample itself can be encoded or encrypted (i.e., encoding/encryption is a code characteristic).
|
||||
|
||||
A related MBC behavior (code characteristic), associated explicitly with executable code and making its analysis more difficult, is [Executable Code Obfuscation](../anti-static-analysis/exe-code-obfuscate.md).
|
||||
A related MBC behavior (code characteristic), associated explicitly with executable code and making its analysis more difficult, is **Executable Code Obfuscation ([B0032](../anti-static-analysis/executable-code-obfuscation.md))**.
|
||||
|
||||
Another related MBC behavior (code characteristic), is [Software Packing](../anti-static-analysis/software-packing.md) which has methods capturing specific packers and types of compression.
|
||||
Another related MBC behavior (code characteristic), is **Software Packing ([F0001](../anti-static-analysis/software-packing.md))** which has methods capturing specific packers and types of compression.
|
||||
|
||||
See ATT&CK: [**Obfuscated Files or Information**](https://attack.mitre.org/techniques/T1027/).
|
||||
See ATT&CK: **Obfuscated Files or Information ([T1027](https://attack.mitre.org/techniques/T1027/), [T1406](https://attack.mitre.org/techniques/T1406/))**.
|
||||
|
||||
Instead of being listed alphabetically, methods have been grouped to better faciliate labeling and mapping.
|
||||
|
||||
@@ -38,3 +48,11 @@ Malware Examples
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|Obfuscates files.|
|
||||
|[**WebCobra**](../xample-malware/webcobra.md)|2018|Obfuscates files.|
|
||||
|[**GotBotKR**](../xample-malware/gotbotkr.md)|2019|GoBotKR uses base64 to obfuscate strings, commands and files. [[1]](#1)|
|
||||
|[**Kovter**](../xample-malware/kovter.md)|2016|The malware will use a key to decrypt text from a URL to create more malicious code [[2]](#2)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/
|
||||
|
||||
<a name="2">[2]</a> https://www.bleepingcomputer.com/virus-removal/remove-kovter-trojan
|
||||
@@ -1,8 +1,18 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0029**|
|
||||
|**Objective(s)**|[Defense Evasion](../defense-evasion)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0029</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../defense-evasion">Defense Evasion</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Polymorphic Code
|
||||
|
||||
@@ -1,15 +1,25 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1055**|
|
||||
|**Objective(s)**|[Defense Evasion](../defense-evasion), [Privilege Escalation](../privilege-escalation)|
|
||||
|**Related ATT&CK Technique**|[Process Injection](https://attack.mitre.org/techniques/T1055)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1055</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../defense-evasion">Defense Evasion</a>, <a href="../privilege-escalation">Privilege Escalation</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Process Injection (<a href="https://attack.mitre.org/techniques/T1055">T1055</a>, <a href="https://attack.mitre.org/techniques/T1631/">T1631</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Process Injection
|
||||
=================
|
||||
Malware may execute code in the address space of a separate process.
|
||||
|
||||
See ATT&CK: [**Process Injection**](https://attack.mitre.org/techniques/T1055). Notes on ATT&CK's sub-techniques in the context of [[1]](#1) are as follows:
|
||||
See ATT&CK: **Process Injection ([T1055](https://attack.mitre.org/techniques/T1055/), [T1631](https://attack.mitre.org/techniques/T1631/))**. Notes on ATT&CK's sub-techniques in the context of [[1]](#1) are as follows:
|
||||
|
||||
|ID|ATT&CK Sub-Technique|Notes|
|
||||
|---|---|---|
|
||||
@@ -40,6 +50,10 @@ Malware Examples
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[2]](#2)|
|
||||
|[**WebCobra**](../xample-malware/webcobra.md)|2018|Injects minor code into a running process.|
|
||||
|[**CryptoWall**](../xample-malware/cryptowall.md)|2014| [[6]](#6)|
|
||||
|[**Hupigon**](../xample-malware/hupigon.md)|2013|The malware injects itself into processes such as cmd.exe, notepad.exe [[7]](#7)|
|
||||
|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|Bypasses UAC using a Shim Database instructing SndVol.exe to execute cmd.exe instead, allowing for elevated execution [[8]](#8)|
|
||||
|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|Stuxnet injects the entire DLL into another process and then just calls the particular export [[9]](#9)|
|
||||
|
||||
References
|
||||
----------
|
||||
@@ -52,3 +66,11 @@ References
|
||||
<a name="4">[4]</a> https://citizenlab.ca/2016/04/between-hong-kong-and-burma/
|
||||
|
||||
<a name="5">[5]</a> https://www.ired.team/offensive-security/code-injection-process-injection/executing-shellcode-with-createfiber
|
||||
|
||||
<a name="6">[6]</a> https://news.sophos.com/en-us/2015/12/17/the-current-state-of-ransomware-cryptowall/
|
||||
|
||||
<a name="7">[7]</a> https://www.f-secure.com/v-descs/backdoor_w32_hupigon.shtml
|
||||
|
||||
<a name="8">[8]</a> https://blog-assets.f-secure.com/wp-content/uploads/2019/10/15163408/BlackEnergy_Quedagh.pdf
|
||||
|
||||
<a name="9">[9]</a> https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en
|
||||
@@ -1,15 +1,26 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1014**|
|
||||
|**Objective(s)**|[Defense Evasion](../defense-evasion)|
|
||||
|**Related ATT&CK Technique**|[Rootkit](https://attack.mitre.org/techniques/T1014)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1014</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../defense-evasion">Defense Evasion</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Rootkit (<a href="https://attack.mitre.org/techniques/T1014">T1014</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Rootkit
|
||||
=======
|
||||
Behaviors of a rootkit: "A rootkit is a collection of computer software, typically malicious, designed to enable access to a computer or areas of its software that is not otherwise allowed and often masks its existence or the existence of other software." [[1]](#1)
|
||||
|
||||
See ATT&CK: [**Rootkit**](https://attack.mitre.org/techniques/T1014).
|
||||
|
||||
See ATT&CK: **Rootkit ([T1014](https://attack.mitre.org/techniques/T1014/))**.
|
||||
|
||||
Rootkits may hide artifacts (kernel modules, services, threads, userspace libraries), prevent actions (API unhooking (prevents API hooks installed by the malware instance from being removed), file access (prevents access to the file system, including specific files and/or directories associated with the malware instance), file deletion (prevents files and/or directories associated with the malware instance from being deleted), memory access (prevents access to system memory where the malware instance stores code or data), native API hooking (prevents other software from hooking native system APIs), registry access (prevents access to the Windows registry, either entire registry or particular registry keys/values), registry deletion (prevents deletion of registry keys and/or values associated with the malware instance).
|
||||
|
||||
@@ -29,6 +40,9 @@ Malware Examples
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[2]](#2)|
|
||||
|[**Hupigon**](../xample-malware/hupigon.md)|2013| Certain variants of the malware may have rootkit functionality [[3]](#3)|
|
||||
|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|Stuxnet registers custom resource drives signed with a legitimate Realtek digital certificate [[4]](#4)|
|
||||
|
||||
|
||||
Detection
|
||||
---------
|
||||
@@ -41,3 +55,7 @@ References
|
||||
<a name="1">[1]</a> https://en.wikipedia.org/wiki/Rootkit
|
||||
|
||||
<a name="2">[2]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
|
||||
|
||||
<a name="3">[3]</a> https://www.f-secure.com/v-descs/backdoor_w32_hupigon.shtml
|
||||
|
||||
<a name="4">[4]</a> https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en
|
||||
@@ -1,18 +1,41 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**F0007**|
|
||||
|**Objective(s)**|[Defense Evasion](../defense-evasion)|
|
||||
|**Related ATT&CK Sub-Technique**|[Indicator Removal on Host: File Deletion](https://attack.mitre.org/techniques/T1070/004/)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>F0007</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../defense-evasion">Defense Evasion</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Indicator Removal on Host: Uninstall Malicious Application (<a href="https://attack.mitre.org/techniques/T1630/001/">T1630.001</a>), Indicator Removal on Host: File Deletion
|
||||
(<a href="https://attack.mitre.org/techniques/T1070/004/">T1070.004</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Self Deletion
|
||||
=============
|
||||
Malware may uninstall itself to avoid detection.
|
||||
|
||||
See ATT&CK: [**Indicator Removal on Host: File Deletion**](https://attack.mitre.org/techniques/T1070/004/).
|
||||
See ATT&CK: **Indicator Removal on Host: Uninstall Malicious Application ([T1630.001](https://attack.mitre.org/techniques/T1630/001/)), Indicator Removal on Host: File Deletion ([T1070.004](https://attack.mitre.org/techniques/T1070/004/))**.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**COMSPEC Environment Variable**|F0007.001|Uninstalls self via COMSPEC environment variable.|
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Terminator**](../xample-malware/terminator.md)|2013|Evades sandboxes by terminating and removing itself (DW20.exe) after installation. [[1]](#1)|
|
||||
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.mandiant.com/resources/hot-knives-through-butter-evading-file-based-sandboxes
|
||||
|
||||
+15
-12
@@ -1,16 +1,19 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**OB0007**|
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>OB0007</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
# Discovery #
|
||||
Behaviors that aim to gain knowledge about the system and internal network.
|
||||
Behaviors that enable malware to gain knowledge about the system and network.
|
||||
|
||||
* **Analysis Tool Discovery** [B0013](../discovery/analysis-tool-discover.md)
|
||||
* **Application Window Discovery** [E1010](../discovery/app-window-discover.md)
|
||||
* **Code Discovery** [B0046](../discovery/code-discover.md)
|
||||
* **File and Directory Discovery** [E1083](../discovery/file-discover.md)
|
||||
* **Self Discovery** [B0038](../discovery/self-discover.md)
|
||||
* **SMTP Connection Discovery** [B0014](../discovery/smtp-connect-discover.md)
|
||||
* **System Information Discovery** [E1082](../discovery/system-info-discover.md)
|
||||
* **Taskbar Discovery** [B0043](../discovery/taskbar-discover.md)
|
||||
* **Analysis Tool Discovery** [B0013](../discovery/anlaysis-tool-discovery.md)
|
||||
* **Application Window Discovery** [E1010](../discovery/application-window-discovery.md)
|
||||
* **Code Discovery** [B0046](../discovery/code-discovery.md)
|
||||
* **File and Directory Discovery** [E1083](../discovery/file-and-directory-discovery.md)
|
||||
* **Self Discovery** [B0038](../discovery/self-discovery.md)
|
||||
* **SMTP Connection Discovery** [B0014](../discovery/smtp-connection-discovery.md)
|
||||
* **System Information Discovery** [E1082](../discovery/system-information-discovery.md)
|
||||
* **Taskbar Discovery** [B0043](../discovery/taskbar-discovery.md)
|
||||
@@ -1,13 +1,23 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0013**|
|
||||
|**Objective(s)**|[Discovery](../discovery)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0013</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../discovery">Discovery</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Analysis Tool Discovery
|
||||
=======================
|
||||
Malware can employ various means to detect whether analysis tools are present or running on the system on which it is executing. Note that analysis tools are used to *analyze* malware whereas security software (see [Software Discovery: Security Software Discovery](https://attack.mitre.org/techniques/T1518/001/)) aims to *detect/mitigate* malware on a system or network.
|
||||
Malware can employ various means to detect whether analysis tools are present or running on the system on which it is executing. Note that analysis tools are used to *analyze* malware whereas security software (see **Software Discovery: Security Software Discovery ([T1518](https://attack.mitre.org/techniques/T1518/001/))** aims to *detect/mitigate* malware on a system or network.
|
||||
|
||||
This behavior corresponds to simple, general discovery of analysis tools. Behaviors to find specific analysis tools (e.g., debuggers or disassemblers) are defined under the [Anti-Behavioral Analysis](../anti-behavioral-analysis) objective.
|
||||
|
||||
@@ -17,6 +27,7 @@ Methods
|
||||
|---|---|---|
|
||||
|**Known File Location**|B0013.008|Malware may detect an analysis tool by the presence of a file in a known location.|
|
||||
|**Known Window**|B0013.009|Malware may detect an analysis tool via the presence of a known window.|
|
||||
|**Known Windows Class Name**|B0013.010|Running program windows are checked to see if any windows class name contains a string indicating that an analysis tool is running. For example, 'WinDbgFrameClass' is Windbg main window’s class name. [2]|
|
||||
|**Process detection**|B0013.001|Malware can scan for the process name associated with common analysis tools.|
|
||||
|**Process detection - Debuggers**|B0013.002|Malware can scan for the process name associated with common analysis tools. OllyDBG / ImmunityDebugger / WinDbg / IDA Pro|
|
||||
|**Process detection - PCAP Utilities**|B0013.004|Malware can scan for the process name associated with common analysis tools. Wireshark / Dumpcap|
|
||||
@@ -24,3 +35,16 @@ Methods
|
||||
|**Process detection - Process Utilities**|B0013.005|Malware can scan for the process name associated with common analysis tools. ProcessHacker / SysAnalyzer / HookExplorer / SysInspector|
|
||||
|**Process detection - Sandboxes**|B0013.007|Malware can scan for the process name associated with common analysis tools. Joe Sandbox, etc.|
|
||||
|**Process detection - SysInternals Suite Tools**|B0013.003|Malware can scan for the process name associated with common analysis tools. Process Explorer / Process Monitor / Regmon / Filemon, TCPView, Autoruns|
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Emotet**](../xample-malware/emotet.md)|2018|If it recieves a response from the c2 server stating a debugging-related tool is in the list of running processes, it recieves an "upgrade" command which calls the ShellExecuteW function and exits [[1]](#1)|
|
||||
|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|Poison Ivy Variant runs a threat to check if any analysis tools are running by creating specially named pipes that are created by various analysis tools. If one of the named pipes cannot be created, it means one fo the analysis tools is running. [[2]](#2)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.fortinet.com/blog/threat-research/deep-analysis-of-new-emotet-variant-part-1
|
||||
|
||||
<a name="2">[2]</a> https://www.mandiant.com/sites/default/files/2021-09/rpt-poison-ivy.pdf
|
||||
@@ -1,16 +0,0 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1010**|
|
||||
|**Objective(s)**|[Discovery](../discovery)|
|
||||
|**Related ATT&CK Technique**|[Application Window Discovery](https://attack.mitre.org/techniques/T1010/) |
|
||||
|
||||
|
||||
Application Window Discovery
|
||||
============================
|
||||
Malware may attempt to get a listing of open application windows.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Window Text**|E1010.m01|After finding an open application window, malware gets graphical window text.|
|
||||
@@ -0,0 +1,26 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1010</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../discovery">Discovery</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Application Window Discovery (<a href="https://attack.mitre.org/techniques/T1010/">T1010</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Application Window Discovery
|
||||
============================
|
||||
Malware may attempt to get a listing of open application windows.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Window Text**|E1010.m01|After finding an open application window, malware gets graphical window text.|
|
||||
@@ -1,8 +1,18 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0046**|
|
||||
|**Objective(s)**|[Discovery](../discovery)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0046</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../discovery">Discovery</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Code Discovery
|
||||
@@ -0,0 +1,43 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1083</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../discovery">Discovery</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>File and Directory Discovery (<a href="https://attack.mitre.org/techniques/T1083/">T1083</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
File and Directory Discovery
|
||||
============================
|
||||
Malware may enumerate files and directories or may search for specific files or in specific locations.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Log File**|E1083.m01|Malware may look for system log files.|
|
||||
|**Filter by Extension**|E1083.m02|Malware may filter by extension (common in ransomware).|
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**CryptoWall**](../xample-malware/cryptowall.md)|2014| [[1]](#1)|
|
||||
|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|The malware searches for user files before encrypting them [[2]](#2)|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Collects local files with specified file extensions and information from the victim's machine [[3]](#3)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://news.sophos.com/en-us/2015/12/17/the-current-state-of-ransomware-cryptowall/
|
||||
|
||||
<a name="2">[2]</a> https://www.secureworks.com/research/cryptolocker-ransomware
|
||||
|
||||
<a name="3">[3]</a> https://www.securityartwork.es/wp-content/uploads/2017/07/Trickbot-report-S2-Grupo.pdf
|
||||
@@ -1,16 +0,0 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1083**|
|
||||
|**Objective(s)**|[Discovery](../discovery)|
|
||||
|**Related ATT&CK Technique**|[File and Directory Discovery](https://attack.mitre.org/techniques/T1083/) |
|
||||
|
||||
|
||||
File and Directory Discovery
|
||||
============================
|
||||
Malware may enumerate files and directories or may search for specific files or in specific locations.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Log File**|E1083.m01|Malware may look for system log files.|
|
||||
@@ -1,10 +0,0 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0038**|
|
||||
|**Objective(s)**|[Discovery](../discovery)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
|
||||
Self Discovery
|
||||
==============
|
||||
Malware may gather information about itself, such as its filename or size on disk.
|
||||
@@ -0,0 +1,20 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0038</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../discovery">Discovery</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Self Discovery
|
||||
==============
|
||||
Malware may gather information about itself, such as its filename or size on disk.
|
||||
@@ -1,10 +0,0 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0014**|
|
||||
|**Objective(s)**|[Discovery](../discovery)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
|
||||
SMTP Connection Discovery
|
||||
=========================
|
||||
Malware may test whether an outgoing SMTP connection can be made from the system on which the malware instance is executing to some SMTP server, by sending a test SMTP transaction.
|
||||
@@ -0,0 +1,20 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0014</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../discovery">Discovery</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
SMTP Connection Discovery
|
||||
=========================
|
||||
Malware may test whether an outgoing SMTP connection can be made from the system on which the malware instance is executing to some SMTP server, by sending a test SMTP transaction.
|
||||
@@ -1,25 +0,0 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1082**|
|
||||
|**Objective(s)**|[Discovery](../discovery)|
|
||||
|**Related ATT&CK Technique**|[System Information Discovery](https://attack.mitre.org/techniques/T1082)|
|
||||
|
||||
|
||||
System Information Discovery
|
||||
============================
|
||||
Malware may attempt to get detailed information about the system.
|
||||
|
||||
See ATT&CK: [**System Information Discovery**](https://attack.mitre.org/techniques/T1082).
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Generate Windows Exception**|E1082.m01|Malware may trigger an exception as a way of gathering system details.|
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
|[**WebCobra**](../xample-malware/webcobra.md)|2018|Learns about the system so it can drop compatible miner software.|
|
||||
@@ -0,0 +1,52 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1082</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../discovery">Discovery</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>System Information Discovery (<a href="https://attack.mitre.org/techniques/T1082">T1082</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
System Information Discovery
|
||||
============================
|
||||
Malware may attempt to get detailed information about the system.
|
||||
|
||||
See ATT&CK: **System Information Discovery ([T1082](https://attack.mitre.org/techniques/T1082/))**.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Generate Windows Exception**|E1082.m01|Malware may trigger an exception as a way of gathering system details.|
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
|[**WebCobra**](../xample-malware/webcobra.md)|2018|Learns about the system so it can drop compatible miner software.|
|
||||
|[**Ursnif**](../xample-malware/ursnif.md)|2016|Uses windows command prompt commands to gather system info, task list, installed drivers, and installed programs [[1]](#1)|
|
||||
|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|uses Systeminfo to gather OS version, system configuration, BIOS, the motherboard, and processor [ [[2]](#2)|
|
||||
|[**DarkComet**](../xample-malware/darkcomet.md)|2008|Can collect information about the compter, resources, and operating system version [[3]](#3)|
|
||||
|[**Emotet**](../xample-malware/emotet.md)|2018|Collects information related to OS, processes, and sometimes mail client information and sends it to c2 [[4]](#4)|
|
||||
|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|Gathers information (OS version, workgroup status, computer name, domain/workgroup name, file name of infected project file) about each computer in the net to spread itself [[5]](#5)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/PE_URSNIF.A2?_ga=2.131425807.1462021705.1559742358-1202584019.1549394279
|
||||
|
||||
<a name="2">[2]</a> https://blog-assets.f-secure.com/wp-content/uploads/2019/10/15163408/BlackEnergy_Quedagh.pdf
|
||||
|
||||
<a name="3">[3]</a> https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/
|
||||
|
||||
<a name="4">[4]</a> https://documents.trendmicro.com/assets/white_papers/ExploringEmotetsActivities_Final.pdf
|
||||
|
||||
<a name="5">[5]</a> https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en
|
||||
@@ -1,10 +0,0 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0043**|
|
||||
|**Objective(s)**|[Discovery](../discovery)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
|
||||
Taskbar Discovery
|
||||
=================
|
||||
Malware may find the taskbar.
|
||||
@@ -0,0 +1,20 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0043</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../discovery">Discovery</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Taskbar Discovery
|
||||
=================
|
||||
Malware may find the taskbar.
|
||||
+14
-11
@@ -1,18 +1,21 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**OB0009**|
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>OB0009</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
# Execution #
|
||||
Behaviors that execute code on a system to achieve a variety of goals.
|
||||
Behaviors that enable malware to execute code on a system to achieve a variety of goals.
|
||||
|
||||
* **Command and Scripting Interpreter** [E1059](../execution/command-line.md)
|
||||
* **Conditional Execution** [B0025](../execution/conditional-execute.md)
|
||||
* **Command and Scripting Interpreter** [E1059](../execution/command-and-scripting-interpreter.md)
|
||||
* **Conditional Execution** [B0025](../execution/conditional-execution.md)
|
||||
* **Execution Dependency** [B0044](../execution/execution-dependency.md)
|
||||
* **Exploitation for Client Execution** [E1203](../execution/exploit-software.md)
|
||||
* **Install Additional Program** [B0023](../execution/install-prog.md)
|
||||
* **Prevent Concurrent Execution** [B0024](../execution/prevent-concurrent-exe.md)
|
||||
* **Exploitation for Client Execution** [E1203](../execution/exploitation-for-client-execution.md)
|
||||
* **Install Additional Program** [B0023](../execution/install-additional-program.md)
|
||||
* **Prevent Concurrent Execution** [B0024](../execution/prevent-concurrent-execution.md)
|
||||
* **Remote Commands** [B0011](../execution/remote-commands.md)
|
||||
* **Send Email** [B0020](../execution/send-email.md)
|
||||
* **Send Poisoned Text Message** [B0021](../execution/send-poison-text-msg.md)
|
||||
* **Send Poisoned Text Message** [B0021](../execution/send-poisoned-text-message.md)
|
||||
* **System Services** [E1569](../execution/system-services.md)
|
||||
* **User Execution** [E1204](../execution/user-interaction.md)
|
||||
* **User Execution** [E1204](../execution/user-execution.md)
|
||||
|
||||
@@ -0,0 +1,48 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1059</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../execution">Execution</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Command and Scripting Interpreter (<a href="https://attack.mitre.org/techniques/T1059">T1059</a>, <a href="https://attack.mitre.org/techniques/T1623">T1623</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Command and Scripting Interpreter
|
||||
=================================
|
||||
Malware may abuse command and script interpreters to execute commands, scripts, or binaries.
|
||||
|
||||
See ATT&CK: **Command and Scripting Interpreter ([T1059](https://attack.mitre.org/techniques/T1059), [T1623](https://attack.mitre.org/techniques/T1623))**.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[1]](#1)|
|
||||
|[**WebCobra**](../xample-malware/webcobra.md)|2018|From the command line, drops and unzips a password-protected Cabinet archive file. [[1]](#1)|
|
||||
|[**GotBotKR**](../xample-malware/gotbotkr.md)|2019|GoBotKR uses cmd.exe to execute commands. [[2]](#2)|
|
||||
|[**Kovter**](../xample-malware/kovter.md)|2016|The malware executes malicious javascript and powershell [[3]](#3)|
|
||||
|[**SamSam**](../xample-malware/samsam.md)|2015|SamSam uses a batch file for executing the malware and deleting certain components [[4]](#4)|
|
||||
|[**Shamoon**](../xample-malware/shamoon.md)|2012|The wiper component of Shamoon creates a service to run the driver with the command: sc create hdv_725x type= kernel start= demand binpath= WINDOWS\hdv_725x.sys 2>&1 >nul and sends an additional reboot command after completion [[5]](#5)|
|
||||
|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|Stuxnet will store and execute SQL code that will extract and execute Stuxnet from the saved CAB file using xp_cmdshell [[6]](#6)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
|
||||
|
||||
<a name="2">[2]</a> https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/
|
||||
|
||||
<a name="3">[3]</a> https://www.bleepingcomputer.com/virus-removal/remove-kovter-trojan
|
||||
|
||||
<a name="4">[4]</a> https://www.sophos.com/en-us/medialibrary/PDFs/technical-papers/SamSam-ransomware-chooses-Its-targets-carefully-wpna.pdf
|
||||
|
||||
<a name="5">[5]</a> https://www.mcafee.com/blogs/other-blogs/mcafee-labs/shamoon-returns-to-wipe-systems-in-middle-east-europe/
|
||||
|
||||
<a name="6">[6]</a> https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en
|
||||
@@ -1,23 +0,0 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1059**|
|
||||
|**Objective(s)**|[Execution](../execution)|
|
||||
|**Related ATT&CK Technique**|[Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059)|
|
||||
|
||||
|
||||
Command and Scripting Interpreter
|
||||
=================================
|
||||
Malware may abuse command and script interpreters to execute commands, scripts, or binaries.
|
||||
|
||||
**See ATT&CK Technique:** [**Command and Scripting Interpreter**](https://attack.mitre.org/techniques/T1059).
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[1]](#1)|
|
||||
|[**WebCobra**](../xample-malware/webcobra.md)|2018|From the command line, drops and unzips a password-protected Cabinet archive file. [[1]](#1)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
|
||||
@@ -1,24 +1,34 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0025**|
|
||||
|**Objective(s)**|[Execution](../execution), [Anti-Behavioral Analysis](../anti-behavioral-analysis), [Defense Evasion](../defense-evasion)|
|
||||
|**Related ATT&CK Technique**|[Execution Guardrails](https://attack.mitre.org/techniques/T1480)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0025</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../execution">Execution</a>, <a href="../anti-behavioral-analysis">Anti-Behavioral Analysis</a>, <a href="../defense-evasion">Defense Evasion</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Execution Guardrails (<a href="https://attack.mitre.org/techniques/T1480">T1480</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Conditional Execution
|
||||
=====================
|
||||
Malware checks system environment conditions or characteristics to determine execution path. For example, malware may not run or be dormant unless system conditions are right, or file that is dropped may vary according to execution environment. Conditional execution in malware happens autonomously, not because of an attacker's command.
|
||||
|
||||
This behavior is related to the [Evade Dynamic Analysis](../anti-behavioral-analysis/evade-dynamic-analysis.md) behavior that obstructs dynamic analysis in a sandbox, emulator, or virtual machine.
|
||||
This behavior is related to the **Dynamic Analysis Evasion ([B0003](../anti-behavioral-analysis/dynamic-analysis-evasion.md))** behavior that obstructs dynamic analysis in a sandbox, emulator, or virtual machine.
|
||||
|
||||
Conditional execution may also be referred to as "execution guardrails." **See ATT&CK:** [**Execution Guardrails**](https://attack.mitre.org/techniques/T1480) (which under ATT&CK does not pertain to anti-behavioral analysis behaviors).
|
||||
Some aspects of this Conditional Execution behavior are related to the [Execution Guardrails (T1480)](https://attack.mitre.org/techniques/T1480) ATT&CK technique; however the ATT&CK technique is not focused on anti-behavioral analysis behaviors.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Deposited Keys**|B0025.008|Parts of the code and/or data is encrypted or otherwise relies on data external to the file itself. For example, malware that contains code that is encrypted with a key that is downloaded from a server; malware that only runs if certain other software is installed on the system. Also see Environmental Keys Method.|
|
||||
|**Environmental Keys**|B0025.002|Malware reads certain attributes of the system (BIOS version string, hostname, MAC address, etc.) and encrypts/decrypts portions of its code or data using those attributes as input, thus preventing itself from being run on an unintended system (e.g., sandbox, emulator, etc.). Also see Deposited Keys Method.|
|
||||
|**Environmental Keys**|B0025.002|Malware reads certain attributes of the system (BIOS version string, hostname, MAC address, etc.) and encrypts/decrypts portions of its code or data using those attributes as input, thus preventing itself from being run on an unintended system (e.g., sandbox, emulator, etc.). Also see Deposited Keys Method. The subsequently defined ATT&CK sub-technique [Execution Guardrails: Environmental Keying (T1480.001)](https://attack.mitre.org/techniques/T1480/001/) is related to this MBC method. |
|
||||
|**GetVolumeInformation**|B0025.003|This Windows API call is used to get the GUID on a system drive. Malware compares it to a previous (targeted) GUID value and only executes maliciously if they match. This behavior can be mitigated in non-automated analysis environments.|
|
||||
|**Host Fingerprint Check**|B0025.004|Compare a previously computed host fingerprint(e.g., based on installed applications) to the current system's to determine if the malware instance is still executing on the same system. If not, execution stops, making debugging or sandbox analysis more difficult.|
|
||||
|**Runs as Service**|B0025.007|The malware must be run as a service, which can make behavioral analysis and debugging more difficult. The service may be set up by the malware. Alternatively, the malware may not contain any code to create a new service or modify an existing service, in which case, the service may be set up by another program or manually. [[2]](#2)|
|
||||
@@ -32,6 +42,8 @@ Malware Examples
|
||||
|---|---|---|
|
||||
|[**WebCobra**](../xample-malware/webcobra.md)|2018|Drops either Cryptonight or Claymore's Zcash miner, depending on system architecture. [[1]](#1)|
|
||||
|[**Conficker**](../xample-malware/conficker.md)|2008|A routine causes the process to suicide exit if the keyboard language is set to Ukranian.|
|
||||
|[**Ursnif**](../xample-malware/ursnif.md)|2016|Macros check if there are at least 50 running processes with a graphical interface, check if a list of blacklisted processes are running, and checks if the application is running in Australia and is NOT affiliated with a select group of networks (Security Research, Hospitals, Universities, Veterans, etc.) [1] [[3]](#3)|
|
||||
|[**Mebromi**](../xample-malware/mebromi.md)|2011|Malware only proceeds if it detects the BIOS ROM is Award BIOS [[4]](#4)|
|
||||
|
||||
References
|
||||
----------
|
||||
@@ -39,3 +51,7 @@ References
|
||||
|
||||
<a name="2">[2]</a>
|
||||
https://reverseengineering.stackexchange.com/questions/2019/debugging-malware-that-will-only-run-as-a-service
|
||||
|
||||
<a name="3">[3]</a> https://www.proofpoint.com/us/threat-insight/post/ursnif-banking-trojan-campaign-sandbox-evasion-techniques
|
||||
|
||||
<a name="4">[4]</a> https://www.webroot.com/blog/2011/09/13/mebromi-the-first-bios-rootkit-in-the-wild/
|
||||
@@ -1,10 +1,20 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0044**|
|
||||
|**Objective(s)**|[Execution](../execution)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0044</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../execution">Execution</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Execution Dependency
|
||||
====================
|
||||
Software may require certain run-time or library dependencies consistent with normal software development and deployment. For example, software may require the presence of a .NET or Java runtime or to be run by a webserver that supports PHP. Unlike in [Conditional Execution](../execution/conditional-execute.md) this dependency is not because of an explicit check coded into the malware by the author.
|
||||
Software may require certain run-time or library dependencies consistent with normal software development and deployment. For example, software may require the presence of a .NET or Java runtime or to be run by a webserver that supports PHP. Unlike in **Conditional Execution ([B0025](../execution/conditional-execution.md))** this dependency is not because of an explicit check coded into the malware by the author.
|
||||
|
||||
@@ -1,15 +1,25 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1203**|
|
||||
|**Objective(s)**|[Execution](../execution), [Impact](../impact)|
|
||||
|**Related ATT&CK Technique**|[Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1203</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../execution">Execution</a>, <a href="../impact">Impact</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Exploitation for Client Execution (<a href="https://attack.mitre.org/techniques/T1203">T1203</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Exploitation for Client Execution
|
||||
=================================
|
||||
Software is exploited - either because of a vulnerability or through its designed features - to gain access for malware. In general, exploitation may be done by a human attacker, but MBC focuses on software exploits implemented in code. Malware-specific details are below.
|
||||
|
||||
**See related ATT&CK Technique:** [**Exploitation for Client Execution**](https://attack.mitre.org/techniques/T1203).
|
||||
See ATT&CK: **Exploitation for Client Execution ([T1203](https://attack.mitre.org/techniques/T1203))**.
|
||||
|
||||
Methods
|
||||
-------
|
||||
@@ -1,15 +1,25 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0023**|
|
||||
|**Objective(s)**|[Execution](../execution)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0023</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../execution">Execution</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Install Additional Program
|
||||
==========================
|
||||
Installs another, different program on the system. The additional program can be any secondary module; examples include backdoors, malicious drivers, kernel modules, and OS X Apps.
|
||||
|
||||
Malware that installs another component is called a "dropper." If the code is contained in the malware, it's a "single stage" dropper; "two stage" droppers download the code from a remote location (the associated download behavior is covered by the [Remote File Copy](../command-and-control/remote-file-copy.md) behavior).
|
||||
Malware that installs another component is called a "dropper." If the code is contained in the malware, it's a "single stage" dropper; "two stage" droppers download the code from a remote location (the associated download behavior is covered by the **Ingress Tool Transfer ([E1105](../command-and-control/ingress-tool-transfer.md))** behavior.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
@@ -21,6 +31,7 @@ Malware Examples
|
||||
|[**MazarBot**](../xample-malware/mazarbot.md)|2016|Installs a backdoor.|
|
||||
|[**Mebromi**](../xample-malware/mebromi.md)|2011|A Trojan downloader.|
|
||||
|[**YiSpecter**](../xample-malware/yispecter.md)|2015|Can download and install arbitrary iOS apps.|
|
||||
|[**UP007**](../xample-malware/up007.md)|2016|The malware is a dropper that creates multiple files [[4]](#4)|
|
||||
|
||||
References
|
||||
----------
|
||||
@@ -29,3 +40,5 @@ References
|
||||
<a name="2">[2]</a> https://www.fortinet.com/blog/threat-research/deep-analysis-of-driver-based-mitm-malware-itranslator.html
|
||||
|
||||
<a name="3">[3]</a> https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/
|
||||
|
||||
<a name="4">[4]</a> https://citizenlab.ca/2016/04/between-hong-kong-and-burma/
|
||||
@@ -1,8 +1,18 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0024**|
|
||||
|**Objective(s)**|[Execution](../execution)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0024</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../execution">Execution</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Prevent Concurrent Execution
|
||||
@@ -1,13 +1,23 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0011**|
|
||||
|**Objective(s)**|[Execution](../execution)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0011</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../execution">Execution</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Remote Commands
|
||||
===============
|
||||
Malware may provide an attacker with explicit commands. This behavior differs from the [Remote Access](../impact/remote-access.md) behavior under the [Impact](../impact) objective in that *Impact: Remote Access* is potentially much broader and may include full remote access.
|
||||
Malware may provide an attacker with explicit commands. This behavior differs from the **Remote Access ([B0022](../impact/remote-access.md))** behavior under the [Impact](../impact) objective in that *Impact: Remote Access* is potentially much broader and may include full remote access.
|
||||
|
||||
Given an "execute" command, the attacker may choose to delete files or corrupt data, power-off the machine, or upload and execute other applications. The malware may also provide specific commands to the attacker (e.g., "delete file").
|
||||
|
||||
@@ -15,7 +25,7 @@ Commands provided by the malware can be captured with the methods defined below.
|
||||
|
||||
It may be useful to capture remote commands along with related behaviors because the associated descriptions could provide details of how the malware implements the command. For example, *Defense Evasion:File Deletion* could be used to provide details and context to *Execution:Remote Commands:Delete File*.
|
||||
|
||||
Autonomous behaviors - those done by the malware without an active attacker - should not be captured with *Execution:Remote Commands*. For example, malware that *automatically* destroys data would be tagged with the [Impact: Data Destruction](../impact/data-destruction.md) behavior.
|
||||
Autonomous behaviors - those done by the malware without an active attacker - should not be captured with *Execution:Remote Commands*. For example, malware that *automatically* destroys data would be tagged with the **Impact: Data Destruction ([E1485](../impact/data-destruction.md))** behavior.
|
||||
|
||||
Methods
|
||||
-------
|
||||
@@ -28,3 +38,20 @@ Methods
|
||||
|**Sleep**|B0011.005||
|
||||
|**Uninstall**|B0011.006||
|
||||
|**Upload File**|B0011.007||
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Ursnif**](../xample-malware/ursnif.md)|2016|Commands sent by a remote user can archive/upload files, capture screenshots, clear cookies, download execute other files, list running processes, reboot the affected system, steal certificates and cookies, update/download a configuration file, upload a log file which contains stolen information [[1]](#1)|
|
||||
|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|infected bots receive commands from botmaster to load plugins associated with botmaster's goals [[2]](#2)|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Receives various commands from c2 server. [[3]](#3)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/BKDR_URSNIF.SM?_ga=2.129468940.1462021705.1559742358-1202584019.1549394279
|
||||
|
||||
<a name="2">[2]</a> https://blog-assets.f-secure.com/wp-content/uploads/2019/10/15163408/BlackEnergy_Quedagh.pdf
|
||||
|
||||
<a name="3">[3]</a> https://www.cybereason.com/blog/research/dropping-anchor-from-a-trickbot-infection-to-the-discovery-of-the-anchor-malware
|
||||
|
||||
+19
-6
@@ -1,15 +1,25 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0020**|
|
||||
|**Objective(s)**|[Execution](../execution), [Lateral Movement](../lateral-movement)|
|
||||
|**Related ATT&CK Technique**|[Phishing](https://attack.mitre.org/techniques/T1566/)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0020</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../execution">Execution</a>, <a href="../lateral-movement">Lateral Movement</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Phishing (<a href="https://attack.mitre.org/techniques/T1566/">T1566</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Send Email
|
||||
==========
|
||||
Sends an email message from the system on which the malware is executing to one or more recipients, mostly commonly for the purpose of spamming or for distributing a malicious attachment or URL (malspamming).
|
||||
|
||||
**See related ATT&CK Techniques:** [**Phishing**](https://attack.mitre.org/techniques/T1566/). This technique is defined in PRE-ATT&CK, which being related to initial access, is not included in MBC.
|
||||
This behavior is related to the **Phishing ([T1566](https://attack.mitre.org/techniques/T1566/))** ATT&CK technique defined under ATT&CK's Initial Access tactic.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
@@ -18,9 +28,12 @@ Malware Examples
|
||||
|[**Gamut**](../xample-malware/gamut.md)|2014|Gamut probes the infected system's SMTP port 25 by sending a test SMTP transaction to mail.ru and hotmail.com. If port 25 is open, the bot requests the spam template and email list, which it uses to send spam. [[1]](#1)|
|
||||
|[**Bagle**](../xample-malware/bagle.md)|2004|Bagle uses its own SMTP engine to mass-mail itself as an attachment from an infected computer. [[2]](#2)|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
|[**Emotet**](../xample-malware/emotet.md)|2018|spam email with the Emotet loader is sent automatically [[3]](#3)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.trustwave.com/Resources/SpiderLabs-Blog/Gamut-Spambot-Analysis/
|
||||
|
||||
<a name="2">[2]</a> https://en.wikipedia.org/wiki/Bagle_(computer_worm)
|
||||
|
||||
<a name="3">[3]</a> https://securelist.com/the-banking-trojan-emotet-detailed-analysis/69560/
|
||||
|
||||
@@ -1,8 +1,18 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0021**|
|
||||
|**Objective(s)**|[Execution](../execution), [Lateral Movement](../lateral-movement)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0021</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../execution">Execution</a>, <a href="../lateral-movement">Lateral Movement</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Send Poisoned Text Message
|
||||
@@ -1,15 +1,25 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1569**|
|
||||
|**Objective(s)**|[Execution](../execution)|
|
||||
|**Related ATT&CK Technique**|[System Services](https://attack.mitre.org/techniques/T1569/)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1569</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../execution">Execution</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>System Services (<a href="https://attack.mitre.org/techniques/T1569/">T1569</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
System Services
|
||||
===============
|
||||
Malware may abuse system services or daemons to execute.
|
||||
|
||||
**See ATT&CK:** [**System Services**](https://attack.mitre.org/techniques/T1569/).
|
||||
See ATT&CK: **System Services ([T1569](https://attack.mitre.org/techniques/T1569/))**.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|
||||
@@ -0,0 +1,39 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1204</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../execution">Execution</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>User Execution (<a href="https://attack.mitre.org/techniques/T1204">T1204</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
User Execution
|
||||
==============
|
||||
Malware may include code that relies on specific actions by a user to execute. Note that this MBC behavior differs from [User Execution](https://attack.mitre.org/techniques/T1204) in that it does do not include direct code execution (user action for *initial* execution) - MBC does not encompass ATT&CK's Initial Access Tactic.
|
||||
|
||||
See ATT&CK Technique: **User Execution ([T1204](https://attack.mitre.org/techniques/T1204/))**.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
|[**GotBotKR**](../xample-malware/gotbotkr.md)|2019| GoBotKR makes their malware look like the torrent content that the user intended to download, in order to entice a user to click on it. [[1]](#1)|
|
||||
|[**Rombertik**](../xample-malware/rombertik.md)|2015|The malware relies on a victim to execute itself [[2]](#2)|
|
||||
|[**Terminator**](../xample-malware/terminator.md)|2013|The malware relies on user interaction to execute [[3]](#3)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/
|
||||
|
||||
<a name="2">[2]</a> https://blogs.cisco.com/security/talos/rombertik
|
||||
|
||||
<a name="3">[3]</a> https://www.mandiant.com/resources/hot-knives-through-butter-evading-file-based-sandboxes
|
||||
@@ -1,18 +0,0 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1204**|
|
||||
|**Objective(s)**|[Execution](../execution)|
|
||||
|**Related ATT&CK Technique**|[User Execution](https://attack.mitre.org/techniques/T1204)|
|
||||
|
||||
|
||||
User Interaction
|
||||
================
|
||||
Malware may include code that relies on specific actions by a user to execute. Note that this MBC behavior differs from [User Execution](https://attack.mitre.org/techniques/T1204) in that it does do not include direct code execution (user action for *initial* execution) - MBE does not encompass ATT&CK's Initial Access Tactic.
|
||||
|
||||
**See ATT&CK Technique:** [**User Execution**](https://attack.mitre.org/techniques/T1204).
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|
||||
@@ -1,10 +1,13 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**OB0010**|
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>OB0010</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
# Exfiltration #
|
||||
Behaviors that steal data from the system on which it executes. This includes stored data (e.g., files) as well as data input into applications (e.g., web browser).
|
||||
Behaviors that enable malware to steal data from a system. This includes stored data, such as files, as well as data input into applications, such as web browsers.
|
||||
|
||||
* **Automated Exfiltration** [E1020](../exfiltration/auto-exfiltrate.md)
|
||||
* **Archive Collected Data** [E1560](../exfiltration/data-encrypted.md)
|
||||
* **Automated Exfiltration** [E1020](../exfiltration/automated-exfiltration.md)
|
||||
* **Archive Collected Data** [E1560](../exfiltration/archive-collected-data.md)
|
||||
|
||||
@@ -0,0 +1,48 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1560</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../exfiltration">Exfiltration</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Archive Collected Data (<a href="https://attack.mitre.org/techniques/T1560/">T1560</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Archive Collected Data
|
||||
======================
|
||||
Malware may obfuscate data via encryption or encoding before exfiltration.
|
||||
|
||||
See ATT&CK Technique: **Archive Collected Data ([T1560](https://attack.mitre.org/techniques/T1560/))**.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Encoding**|E1560.m01|Data is encoded.|
|
||||
|**Encoding - Custom Encoding**|E1560.m04|Data is encoded. A custom algorithm is used to encode the exfiltrated data.|
|
||||
|**Encoding - Standard Encoding**|E1560.m03|Data is encoded. A standard algorithm, such as base64 encoding, is used to encode the exfiltrated data.|
|
||||
|**Encryption**|E1560.m02|Data is encrypted.|
|
||||
|**Encryption - Custom Encryption**|E1560.m06|Data is encrypted. A custom algorithm is used to encrypt the exfiltrated data.|
|
||||
|**Encryption - Standard Encryption**|E1560.m05|Data is encrypted. A standard algorithm, such as Rijndael/AES, DES, RC4, is used to encrypt the exfiltrated data.|
|
||||
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**TrickBot**](../xample-malware/trickbot.md)|2016|Uses a custom crypter leveraging Microsoft's CryptoAPI to encrypt C2 traffic. C2 update responses seem to have been digitally signed using bcrypt [[1]](#1)|
|
||||
|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|Exfiltrated payloads are XORed with a static 31-byte long byte string found inside Stuxnet and hexified in order to be passed on as an ASCII data parameter in an HTTP request to the C2 servers [[2]](#2)|
|
||||
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.bitdefender.com/blog/labs/trickbot-is-dead-long-live-trickbot/
|
||||
|
||||
<a name="2">[2]</a> https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en
|
||||
@@ -1,18 +0,0 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1020**|
|
||||
|**Objective(s)**|[Exfiltration](../exfiltration)|
|
||||
|**Related ATT&CK Technique**|[Automated Exfiltration](https://attack.mitre.org/techniques/T1020/)|
|
||||
|
||||
|
||||
Automated Exfiltration
|
||||
======================
|
||||
Malware may exfiltrate data via automated processing or scripting.
|
||||
|
||||
**See ATT&CK Technique:** [**Automated Exfiltration**](https://attack.mitre.org/techniques/T1020/).
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Exfiltrate via File Hosting Service**|E1020.m01|Malware may exfiltrate files to a file hosting location.|
|
||||
@@ -0,0 +1,28 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1020</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../exfiltration">Exfiltration</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Automated Exfiltration (<a href="https://attack.mitre.org/techniques/T1020/">T1020</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Automated Exfiltration
|
||||
======================
|
||||
Malware may exfiltrate data via automated processing or scripting.
|
||||
|
||||
See ATT&CK Technique: **Automated Exfiltration ([T1020](https://attack.mitre.org/techniques/T1020/))**.
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Exfiltrate via File Hosting Service**|E1020.m01|Malware may exfiltrate files to a file hosting location.|
|
||||
@@ -1,23 +0,0 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1560**|
|
||||
|**Objective(s)**|[Exfiltration](../exfiltration)|
|
||||
|**Related ATT&CK Technique**|[Archive Collected Data](https://attack.mitre.org/techniques/T1560/)|
|
||||
|
||||
|
||||
Archive Collected Data
|
||||
======================
|
||||
Malware may obfuscate data via encryption or encoding before exfiltration.
|
||||
|
||||
**See ATT&CK Technique:** [**Archive Collected Data**](https://attack.mitre.org/techniques/T1560/).
|
||||
|
||||
Methods
|
||||
-------
|
||||
|Name|ID|Description|
|
||||
|---|---|---|
|
||||
|**Encoding**|E1560.m01|Data is encoded.|
|
||||
|**Encoding - Custom Encoding**|E1560.m04|Data is encoded. A custom algorithm is used to encode the exfiltrated data.|
|
||||
|**Encoding - Standard Encoding**|E1560.m03|Data is encoded. A standard algorithm, such as base64 encoding, is used to encode the exfiltrated data.|
|
||||
|**Encryption**|E1560.m02|Data is encrypted.|
|
||||
|**Encryption - Custom Encryption**|E1560.m06|Data is encrypted. A custom algorithm is used to encrypt the exfiltrated data.|
|
||||
|**Encryption - Standard Encryption**|E1560.m05|Data is encrypted. A standard algorithm, such as Rijndael/AES, DES, RC4, is used to encrypt the exfiltrated data.|
|
||||
+14
-11
@@ -1,24 +1,27 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**OB0008**|
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>OB0008</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
# Impact #
|
||||
Behaviors that enable malware to achieve its mission of manipulating, interrupting, or destroying systems and/or data.
|
||||
Behaviors that enable malware to manipulate, interrupt, or destroy systems and data.
|
||||
|
||||
* **Clipboard Modification** [E1510](../impact/clipboard-mod.md)
|
||||
* **Clipboard Modification** [E1510](../impact/clipboard-modification.md)
|
||||
* **Component Firmware** [F0009](../persistence/component-firmware.md)
|
||||
* **Compromise Data Integrity** [B0016](../impact/compromise-data.md)
|
||||
* **Compromise Data Integrity** [B0016](../impact/compromise-data-integrity.md)
|
||||
* **Data Destruction** [E1485](../impact/data-destruction.md)
|
||||
* **Data Encrypted for Impact** [E1486](../impact/encrypt-impact.md)
|
||||
* **Data Encrypted for Impact** [E1486](../impact/data-encrypted-for-impact.md)
|
||||
* **Denial of Service** [B0033](../impact/denial-of-service.md)
|
||||
* **Destroy Hardware** [B0017](../impact/destroy-hardware.md)
|
||||
* **Disk Wipe** [F0014](../impact/disk-wipe.md)
|
||||
* **Exploit Kit Behavior** [E1190](../impact/exploit-kit-behavior.md)
|
||||
* **Exploitation for Client Execution** [E1203](../execution/exploit-software.md)
|
||||
* **Generate Fraudulent Advertising Revenue** [E1472](../impact/generate-fraud-rev.md)
|
||||
* **Exploit Kit Behavior** [E1190](../impact/exploit-kit.md)
|
||||
* **Exploitation for Client Execution** [E1203](../execution/exploitation-for-client-execution.md)
|
||||
* **Generate Network Traffic from Victim** [E1643](../impact/generate-traffic-from-victim.md)
|
||||
* **Manipulate Network Traffic** [B0019](../impact/manipulate-network-traffic.md)
|
||||
* **Modify Hardware** [B0042](../impact/modify-hardware.md)
|
||||
* **Remote Access** [B0022](../impact/remote-access.md)
|
||||
* **Resource Hijacking** [B0018](../impact/hijack-sys-resources.md)
|
||||
* **Resource Hijacking** [B0018](../impact/resource-hijacking.md)
|
||||
* **Spamming** [B0039](../impact/spamming.md)
|
||||
|
||||
@@ -1,10 +0,0 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1510**|
|
||||
|**Objective(s)**|[Impact](../impact)|
|
||||
|**Related ATT&CK Technique**|[Clipboard Modification](https://attack.mitre.org/techniques/T1510/)|
|
||||
|
||||
|
||||
Clipboard Modification
|
||||
======================
|
||||
ATT&CK defines Clipboard Modification as a Mobile technique (Android platform). MBC extends it to the Windows platform.
|
||||
@@ -0,0 +1,20 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1510</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../impact">Impact</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Clipboard Modification (<a href="https://attack.mitre.org/techniques/T1510/">T1510</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Clipboard Modification
|
||||
======================
|
||||
ATT&CK defines Clipboard Modification as a Mobile technique (Android platform). MBC extends it to the Windows platform.
|
||||
@@ -0,0 +1,22 @@
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0016</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../impact">Impact</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Data Manipulation: Stored Data Manipulation (<a href="https://attack.mitre.org/techniques/T1565/001/">T1565.001</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Compromise Data Integrity
|
||||
=========================
|
||||
Data stored on the file system of a compromised system is manipulated to compromise its integrity.
|
||||
|
||||
The related **Data Manipulation: Stored Data Manipulation ([T1565.001](https://attack.mitre.org/techniques/T1565/001/))** ATT&CK sub-technique was defined subsequent to this MBC behavior.
|
||||
@@ -1,12 +0,0 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0016**|
|
||||
|**Objective(s)**|[Impact](../impact)|
|
||||
|**Related ATT&CK Sub-Technique**|[Data Manipulation: Stored Data Manipulation](https://attack.mitre.org/techniques/T1565/001/)|
|
||||
|
||||
|
||||
Compromise Data Integrity
|
||||
=========================
|
||||
Data stored on the file system of a compromised system is manipulated to compromise its integrity.
|
||||
|
||||
The subsequently defined ATT&CK sub-technique [Data Manipulation: Stored Data Manipulation](https://attack.mitre.org/techniques/T1565/001/) is related to this MBC behavior.
|
||||
@@ -1,15 +1,25 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1485**|
|
||||
|**Objective(s)**|[Impact](../impact)|
|
||||
|**Related ATT&CK Technique**|[Data Destruction](https://attack.mitre.org/techniques/T1485/), [Delete Device Data](https://attack.mitre.org/techniques/T1447/)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1485</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../impact">Impact</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Data Destruction (<a href="https://attack.mitre.org/techniques/T1485/">T1485</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Data Destruction
|
||||
================
|
||||
Data, system files, or other files are destroyed. Individual files are selected, as opposed to wiping an entire sector.
|
||||
|
||||
see ATT&CK: [**Data Destruction**](https://attack.mitre.org/techniques/T1485/).
|
||||
See ATT&CK: **Data Destruction ([T1485](https://attack.mitre.org/techniques/T1485/))**.
|
||||
|
||||
Methods
|
||||
-------
|
||||
@@ -24,7 +34,19 @@ Malware Examples
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Shamoon**](../xample-malware/shamoon.md)|2012|A 2018 variant includes a component that erases files and then wipes the master boot record, preventing file recovery.[[1]](#1)|
|
||||
|[**Rombertik**](../xample-malware/rombertik.md)|2015|If a specific anti-analysis check fails, the malware will overwrite the Master Boot Record or the User's home folder [[2]](#2)|
|
||||
|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|BlackEnergy 2 variant contains a Destroy plugin that destroys data stored on victim hard drives by overwriting file contents [[3]](#3)|
|
||||
|[**Conficker**](../xample-malware/conficker.md)|2008|resets system restore points and deletes backup files [[4]](#4)|
|
||||
|[**MazarBot**](../xample-malware/mazarbot.md)|2016|Can erase phone data [[5]](#5)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> http://www.darkreading.com/attacks-breaches/disk-wiping-shamoon-malware-resurfaces-with-file-erasing-malware-in-tow/d/d-id/1333509
|
||||
|
||||
<a name="2">[2]</a> https://blogs.cisco.com/security/talos/rombertik
|
||||
|
||||
<a name="3">[3]</a> https://securelist.com/be2-extraordinary-plugins-siemens-targeting-dev-fails/68838/
|
||||
|
||||
<a name="4">[4]</a> https://en.wikipedia.org/wiki/Conficker
|
||||
|
||||
<a name="5">[5]</a> https://heimdalsecurity.com/blog/security-alert-mazar-bot-active-attacks-android-malware/
|
||||
|
||||
@@ -1,15 +1,24 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1486**|
|
||||
|**Objective(s)**|[Impact](../impact)|
|
||||
|**Related ATT&CK Techniques**|[Data Encrypted for Impact](https://attack.mitre.org/techniques/T1486/), [Data Encrypted for Impact (Mobile)](https://attack.mitre.org/techniques/T1471/)|
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>E1486</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../impact">Impact</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Data Encrypted for Impact (<a href="https://attack.mitre.org/techniques/T1486/">T1486</a>), Data Encrypted for Impact (Mobile) (<a href="https://attack.mitre.org/techniques/T1471/">T1471</a>) </b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Data Encrypted for Impact
|
||||
=========================
|
||||
Malware may encrypt files stored on the system to prevent user access until a ransom is paid and/or to interrupt system availability. The encryption process usually iterates over all letter drives in the system (except for CD drives) and then recursively encrypts all files with specific suffixes.
|
||||
|
||||
See ATT&CK: [**Data Encrypted for Impact**](https://attack.mitre.org/techniques/T1486/) and [**Data Encrypted for Impact (Mobile)**](https://attack.mitre.org/techniques/T1471/).
|
||||
See ATT&CK: **Data Encrypted for Impact ([T1486](https://attack.mitre.org/techniques/T1486/))** and **Data Encrypted for Impact (Mobile) ([T1471](https://attack.mitre.org/techniques/T1471/))**
|
||||
|
||||
Methods
|
||||
-------
|
||||
@@ -1,25 +1,37 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0033**|
|
||||
|**Objective(s)**|[Impact](../impact)|
|
||||
|**Related ATT&CK Technique**|[Network Denial of Device](https://attack.mitre.org/techniques/T1498/)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0033</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../impact">Impact</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Network Denial of Service (<a href="https://attack.mitre.org/techniques/T1498/">T1498</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Denial of Service
|
||||
=================
|
||||
Malware may make a network unavailable, for example, by launching a network-based denial of service (DoS) attack.
|
||||
|
||||
Endpoint denial of service behaviors are captured by the [Endpoint Denial of Service](https://attack.mitre.org/techniques/T1499/) technique.
|
||||
Endpoint denial of service behaviors are captured by the **Endpoint Denial of Service ([T1499](https://attack.mitre.org/techniques/T1499/))** technique.
|
||||
|
||||
The subsequently defined ATT&CK technique [Network Denial of Device](https://attack.mitre.org/techniques/T1498/) is related to this MBC behavior.
|
||||
The related **Network Denial of Service ([T1498](https://attack.mitre.org/techniques/T1498/))** ATT&CK technique was defined subsequent to this MBC behavior.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**BlackEnergy**](../xample-malware/blackenergy.md)|October 2007|Launches distributed denial of service attacks that can target more than one IP address per hostname. [[1]](#1)|
|
||||
|[**GotBotKR**](../xample-malware/gotbotkr.md)|2019|GoBotKR has been used to execute endpoint DDoS attacks – for example, TCP Flood or SYN Flood. [[2]](#2)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> http://atlas-public.ec2.arbor.net/docs/BlackEnergy+DDoS+Bot+Analysis.pdf
|
||||
|
||||
|
||||
<a name="2">[2]</a> https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/
|
||||
|
||||
@@ -1,8 +1,18 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**B0017**|
|
||||
|**Objective(s)**|[Impact](../impact)|
|
||||
|**Related ATT&CK Technique**|None|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>B0017</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../impact">Impact</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>None</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
Destroy Hardware
|
||||
|
||||
+28
-7
@@ -1,11 +1,32 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**F0014**|
|
||||
|**Objective(s)**|[Impact](../impact)|
|
||||
|**Related ATT&CK Sub-Technique**|[Disk Wipe](https://attack.mitre.org/techniques/T1561/)|
|
||||
|
||||
<table>
|
||||
<tr>
|
||||
<td><b>ID</b></td>
|
||||
<td><b>F0014</b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Objective(s)</b></td>
|
||||
<td><b><a href="../impact">Impact</a></b></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>Related ATT&CK Techniques</b></td>
|
||||
<td><b>Disk Wipe (<a href="https://attack.mitre.org/techniques/T1561/">T1561</a>)</b></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
Disk Wipe
|
||||
=========
|
||||
Malware may erase the content of storage devices. This behavior is different than [Data Destruction](../impact/data-destruction.md) because sections of the disk are erased rather than individual files.
|
||||
Malware may erase the content of storage devices. This behavior is different than **Data Destruction ([E1485](../impact/data-destruction.md))** because sections of the disk are erased rather than individual files.
|
||||
|
||||
This description refines the ATT&CK [**Disk Wipe**](https://attack.mitre.org/techniques/T1561/) sub-technique.
|
||||
This description refines the ATT&CK **Disk Wipe ([T1203](https://attack.mitre.org/techniques/T1561/)**] sub-technique.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Shamoon**](../xample-malware/shamoon.md)|2012|An overwrite component will overwrite the MBR so that the compromised computer can no longer start [[1]](#1)|
|
||||
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://community.broadcom.com/symantecenterprise/communities/community-home/librarydocuments/viewdocument?DocumentKey=281521ea-2d18-4bf9-9e88-8b1dc41cfdb6&CommunityKey=1ecf5f55-9545-44d6-b0f4-4e4a7f5f5e68&tab=librarydocuments
|
||||
|
||||
@@ -1,22 +0,0 @@
|
||||
|||
|
||||
|---|---|
|
||||
|**ID**|**E1190**|
|
||||
|**Objective(s)**|[Impact](../impact)|
|
||||
|**Related ATT&CK Technique**|[Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190)|
|
||||
|
||||
|
||||
Exploit Kit Behavior
|
||||
====================
|
||||
An Exploit Kit is a toolkit that exploits vulnerabilities in software to deliver malicious payloads (malware).
|
||||
|
||||
**See related ATT&CK Technique:** [**Exploit Public-Facing Application**](https://attack.mitre.org/techniques/T1190), which relates to Initial Access. Under the Impact objective, exploit behaviors are considered more broadly in MBC.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|---|---|---|
|
||||
|[**Ursnif**](../xample-malware/ursnif.md)||Ursnif is sometimes delivered via exploit kit. [[1]](#1)|
|
||||
|
||||
References
|
||||
----------
|
||||
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/ursnif
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user