Files
MBCProject-mbc-markdown/execution/user-execution.md
T
2022-11-10 12:02:12 -05:00

1.8 KiB

ID E1204
Objective(s) Execution
Related ATT&CK Techniques User Execution (T1204)
Version 2.0
Created 28 August 2019
Last Modified 31 October 2022

User Execution

Malware may include code that relies on specific actions by a user to execute. Note that this MBC behavior differs from User Execution in that it does do not include direct code execution (user action for initial execution) - MBC does not encompass ATT&CK's Initial Access Tactic.

See ATT&CK Technique: User Execution (T1204).

Use in Malware

Name Date Description
TrickBot 2016 Trojan spyware program that has mainly been used for targeting banking sites.
GotBotKR 2019 GoBotKR makes their malware look like the torrent content that the user intended to download, in order to entice a user to click on it. [1]
Rombertik 2015 The malware relies on a victim to execute itself [2]
Terminator 2013 The malware relies on user interaction to execute [3]

References

[1] https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/

[2] https://blogs.cisco.com/security/talos/rombertik

[3] https://www.mandiant.com/resources/hot-knives-through-butter-evading-file-based-sandboxes