mirror of
https://github.com/MBCProject/mbc-markdown
synced 2026-06-08 11:36:36 +00:00
1.8 KiB
1.8 KiB
| ID | E1204 |
| Objective(s) | Execution |
| Related ATT&CK Techniques | User Execution (T1204) |
| Version | 2.0 |
| Created | 28 August 2019 |
| Last Modified | 31 October 2022 |
User Execution
Malware may include code that relies on specific actions by a user to execute. Note that this MBC behavior differs from User Execution in that it does do not include direct code execution (user action for initial execution) - MBC does not encompass ATT&CK's Initial Access Tactic.
See ATT&CK Technique: User Execution (T1204).
Use in Malware
| Name | Date | Description |
|---|---|---|
| TrickBot | 2016 | Trojan spyware program that has mainly been used for targeting banking sites. |
| GotBotKR | 2019 | GoBotKR makes their malware look like the torrent content that the user intended to download, in order to entice a user to click on it. [1] |
| Rombertik | 2015 | The malware relies on a victim to execute itself [2] |
| Terminator | 2013 | The malware relies on user interaction to execute [3] |
References
[1] https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/
[2] https://blogs.cisco.com/security/talos/rombertik
[3] https://www.mandiant.com/resources/hot-knives-through-butter-evading-file-based-sandboxes