mirror of
https://github.com/MBCProject/mbc-markdown
synced 2026-06-08 11:36:36 +00:00
bd31003a22
* Fixing links * Code samples (#149) * Update obfuscated-files-or-information.md Added code sample with some proposed formatting incl. annotations explaining broad behavior patterns * Update obfuscated-files-or-information.md Added brief clarification to note * Update obfuscated-files-or-information.md Made requested changes to format * Update system-information-discovery.md Added code snippet from PoisonIvy RAT * Update debugger-detection.md Added code with example of PEB access * Update system-information-discovery.md Added new method based on code snippet * Update registry.md Added snippet for registry key query * Update generate-pseudorandom-sequence.md Added example of Mersenne Twister algorithm * Update keylogging.md Add Dark Comet keylogging code sample * Update dns-communication.md Added code sample from darkcomet * Update socket-communication.md Added DarkComet code snippet * Update delete-file.md Provided DarkComet sample * Update file-and-directory-discovery.md Added DarkComet snippet * Update allocate-memory.md Added DarkComet sample * Update modulo.md Added Hupigon snippet * Update get-file-attributes.md Added Hupigon sample * Update application-window-discovery.md Added Hupigon snippet * Update create-process.md Added Hupigon snippet. * Update conditional-execution.md Added Hupigon snippet * Update create-thread.md Added Hupigon snippet * Update resume-thread.md Added Hupigon snippet * Update command-and-scripting-interpreter.md Added SmokeLoader sample * Update change-memory-protection.md Added SmokeLoader snippet * Update console.md Added snippet from SmokeLoader * Update dynamic-analysis-evasion.md Added Industroyer sample * Update interprocess-communication.md Added CobaltStrike sample * Update read-file.md Added Cobalt Strike snippet * Update writes-file.md Added cobalt strike snippet * Update noncryptographic-hash.md Added emotet snippet * Update clipboard-modification.md Added emotet snippet * Update check-mutex.md Added emotet sampler * Update check-mutex.md Fixed typo * Update create-mutex.md Added Emotet snippet * Update allocate-thread-local-storage.md Added emotet snippet * Update registry-run-keys-startup-folder.md Added emotet snippet * Update wininet.md Added EnvyScout snippet * Update http-communication.md Added EnvyScout snippet * Update enumerate-threads.md Added Envyscout snippet * Update set-thread-local-storage-value.md Added Envyscout sample * Update create-directory.md Added explosive snippet * Update delete-directory.md Added explosive code snippet (note: the malware is called "explosive") * Update set-file-attributes.md Added explosive sample * Update terminate-process.md Added explosive snippet * Update terminate-thread.md Added explosive sample * Update move-file.md Added Finfisher snippet * Update screen-capture.md Added ECCENTRICBANDWAGON snippet * Fix links (#150) * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * fix link * update mod date * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * fix links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * update links * Update code-discovery.md * Update taskbar-discovery.md * Update conditional-execution.md * Update memory-dump-evasion.md * Update execution-dependency.md * Update compromise-data-integrity.md * Update dns-communication.md * Update http-communication.md * Update interprocess-communication.md * Update socket-communication.md * Update wininet.md * Update generate-pseudorandom-sequence.md * Update modulo.md * Update noncryptographic-hash.md * Update create-directory.md * Update delete-directory.md * Update delete-file.md * Update get-file-attributes.md * Update move-file.md * Update read-file.md * Update terminate-thread.md * Update set-file-attributes.md * Update writes-file.md * Update allocate-memory.md * Update change-memory-protection.md * Update console.md * Update registry.md * Update allocate-thread-local-storage.md * Update check-mutex.md * Update terminate-process.md * Update create-mutex.md * Update create-process.md * Update set-thread-local-storage-value.md * Update resume-thread.md * Update enumerate-threads.md * Update create-thread.md * update for 3.1 release * update for 3.1 release * update for 3.1 release --------- Co-authored-by: ryan <ryanxu@wustl.edu> Co-authored-by: brightmt <50853930+brightmt@users.noreply.github.com>
6.9 KiB
6.9 KiB
| ID | E1203 |
| Objective(s) | Execution, Impact |
| Related ATT&CK Techniques | Exploitation for Client Execution (T1203) |
| Impact Type | Breach |
| Version | 3.2 |
| Created | 1 August 2019 |
| Last Modified | 30 April 2024 |
Exploitation for Client Execution
Software is exploited - either because of a vulnerability or through its designed features - to gain access for malware. In general, exploitation may be done by a human attacker, but MBC focuses on software exploits implemented in code. Malware-specific details are below.
See ATT&CK: Exploitation for Client Execution (T1203).
Methods
| Name | ID | Description |
|---|---|---|
| File Transfer Protocol (FTP) Servers | E1203.m03 | Malware leverages an FTP server. |
| Java-based Web Servers | E1203.m02 | Malware leverages a Java-based web server. |
| Red Hat JBoss Enterprise Products | E1203.m04 | Malware leverages JBoss Enterprise products. |
| Remote Desktop Protocols | E1203.m01 | RDP is used by malware. |
| Sysinternals | E1203.m05 | Sysinternals tools are used for additional command line functionality. |
| Windows Utilities | E1203.m06 | One or more Windows utilities are used. |
Use in Malware
| Name | Date | Method | Description |
|---|---|---|---|
| SamSam | 2015 | E1203.m01 | Attackers associated with SamSam exploit vulnerabilities in remote desktop protocols (RDP), Java-based web servers, or file transfer protocol (FTP) servers. [1] |
Detection
| Tool: CAPE | Mapping | APIs |
|---|---|---|
| office_cve2017_11882 | Exploitation for Client Execution (E1203) | CreateProcessInternalW |
| office_cve2017_11882_network | Exploitation for Client Execution (E1203) | ConnectEx, URLDownloadToFileW |
| office_flash_load | Exploitation for Client Execution (E1203) | CoGetClassObject, CoCreateInstance |
| office_postscript | Exploitation for Client Execution (E1203) | NtWriteFile |
| persistence_rdp_registry | Exploitation for Client Execution::Remote Desktop Protocols (E1203.m01) | -- |
| exploit_getbasekerneladdress | Exploitation for Client Execution (E1203) | EnumDeviceDrivers, LdrGetProcedureAddress, LdrLoadDll, K32EnumDeviceDrivers |
| cve_2016_7200 | Exploitation for Client Execution (E1203) | JsEval, COleScript_ParseScriptText, COleScript_Compile |
| stack_pivot | Exploitation for Client Execution (E1203) | VirtualProtectEx, NtAllocateVirtualMemory, NtMapViewOfSection, NtWriteVirtualMemory, NtWow64WriteVirtualMemory64, URLDownloadToFileW, WriteProcessMemory, NtProtectVirtualMemory |
| stack_pivot_file_created | Exploitation for Client Execution (E1203) | NtCreateFile |
| stack_pivot_process_create | Exploitation for Client Execution (E1203) | NtCreateUserProcess, CreateProcessInternalW |
| uses_windows_utilities | Exploitation for Client Execution::Windows Utilities (E1203.m06) | -- |
| uses_windows_utilities_curl | Exploitation for Client Execution::Windows Utilities (E1203.m06) | -- |
| cve_2014_6332 | Exploitation for Client Execution (E1203) | JsEval, COleScript_ParseScriptText, COleScript_Compile |
| exploit_gethaldispatchtable | Exploitation for Client Execution (E1203) | LdrGetProcedureAddress, LdrLoadDll |
| cve_2015_2419_js | Exploitation for Client Execution (E1203) | JsEval, COleScript_ParseScriptText, COleScript_Compile |
| sysinternals_psexec | Exploitation for Client Execution (E1203) | -- |
| sysinternals_psexec | Exploitation for Client Execution::Sysinternals (E1203.m05) | -- |
| sysinternals_tools | Exploitation for Client Execution (E1203) | -- |
| sysinternals_tools | Exploitation for Client Execution::Sysinternals (E1203.m05) | -- |
| uses_rdp_clip | Exploitation for Client Execution::Remote Desktop Protocols (E1203.m01) | -- |
| uses_remote_desktop_session | Exploitation for Client Execution::Remote Desktop Protocols (E1203.m01) | -- |
| cve_2016-0189 | Exploitation for Client Execution (E1203) | JsEval, COleScript_ParseScriptText, COleScript_Compile |
| exploit_heapspray | Exploitation for Client Execution (E1203) | NtAllocateVirtualMemory |
| rtf_aslr_bypass | Exploitation for Client Execution (E1203) | -- |
| rtf_exploit_static | Exploitation for Client Execution (E1203) | -- |
References
[1] https://blog.malwarebytes.com/cybercrime/2018/05/samsam-ransomware-need-know/