mirror of
https://github.com/MBCProject/mbc-markdown
synced 2026-06-08 11:36:36 +00:00
f7d92d59fa
- Updating capa detection in behaviors - Newsletter - Conti malware - pafish faq
1.8 KiB
1.8 KiB
| ID | B0020 |
| Objective(s) | Execution, Lateral Movement |
| Related ATT&CK Techniques | Phishing (T1566) |
| Version | 2.0 |
| Created | 1 August 2019 |
| Last Modified | 12 June 2023 |
Send Email
Sends an email message from the system on which the malware is executing to one or more recipients, mostly commonly for the purpose of spamming or for distributing a malicious attachment or URL (malspamming).
This behavior is related to the Phishing (T1566) ATT&CK technique defined under ATT&CK's Initial Access tactic.
Use in Malware
| Name | Date | Method | Description |
|---|---|---|---|
| Gamut | 2014 | -- | Gamut probes the infected system's SMTP port 25 by sending a test SMTP transaction to mail.ru and hotmail.com. If port 25 is open, the bot requests the spam template and email list, which it uses to send spam. [1] |
| Bagle | 2004 | -- | Bagle uses its own SMTP engine to mass-mail itself as an attachment from an infected computer. [2] |
| Emotet | 2018 | -- | Spam email with the Emotet loader is sent automatically. [3] |
References
[1] https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/gamut-spambot-analysis/
[2] https://en.wikipedia.org/wiki/Bagle_(computer_worm)
[3] https://securelist.com/the-banking-trojan-emotet-detailed-analysis/69560/