mirror of
https://github.com/MBCProject/mbc-markdown
synced 2026-06-08 11:36:36 +00:00
c3033e4061
* update staging (#158) * update format/wording * Capa 7.1 rule updates (#156) * Update self-deletion.md Added CAPA rule "self delete using alternate data streams" (https://github.com/mandiant/capa-rules/blob/v7.1.0/anti-analysis/anti-forensic/self-deletion/self-delete-using-alternate-data-streams.yml) * Update obfuscated-files-or-information.md added new CAPA rule "encrypt data using RC4 via SystemFunction033" https://github.com/mandiant/capa-rules/blob/v7.1.0/data-manipulation/encryption/rc4/encrypt-data-using-rc4-via-systemfunction033.yml * Update disk-wipe.md Added capa rule "https://github.com/mandiant/capa-rules/blob/v7.1.0/impact/wipe-disk/delete-drive-layout-via-ioctl.yml" https://github.com/mandiant/capa-rules/blob/v7.1.0/impact/wipe-disk/delete-drive-layout-via-ioctl.yml * Update system-information-discovery.md Added new CAPA rule "get disk information via IOCTL" https://github.com/mandiant/capa-rules/blob/v7.1.0/nursery/get-disk-information-via-ioctl.yml * Update system-information-discovery.md Added new CAPA rule "get volume information via IOCTL" https://github.com/mandiant/capa-rules/blob/v7.1.0/nursery/get-volume-information-via-ioctl.yml * Update dns-communication.md Removed duplication in APIs in "Resolve DNS" CAPA rule * Update socket-communication.md Updated APIs for "create raw socket" CAPA rule * Update socket-communication.md Updated APIs on CAPA rule "get socket status" * Update socket-communication.md Updated CAPA rule "initialize Winsock library" * Update socket-communication.md Updated API listing on CAPA rule "receive data on socket" * Update socket-communication.md Updated API listing for "send data on socket" CAPA rule * Update socket-communication.md Update APIs for CAPA rule "set socket configuration" * Update socket-communication.md Updated CAPA rule "connect tcp socket" to add APIs * Update socket-communication.md Added APIs to CAPA rule "create tcp socket" * Update socket-communication.md Added APIs to "create UDP socket" CAPA rule * Update encrypt-data.md Added new APIs to "encrypt data using DPAPI" CAPA rule * Update install-driver.md Added APIs to CAPA rule "install driver" * Update set-file-attributes.md Added APIs to CAPA rule "change file permissions on Linux" * Update writes-file.md Updated APIs for CAPA rule "write file on linux" * Update system-information-discovery.md Removed API from CAPA rule "get disk size" to align with published CAPA rule in v. 7.1 * Update create-process.md Added API to "create process on linux" CAPA rule * Update hijack-execution-flow.md Added API calls to CAPA rule "execute shellcode via Windows callback function" * Update self-deletion.md Changed link to master * Update obfuscated-files-or-information.md Changed rule link to release to point to master * Update system-information-discovery.md Removed nursery rules * Update disk-wipe.md Updated link to master branch * Update socket-communication.md Checked for correct socket listings under the APIs --------- Co-authored-by: brightmt <50853930+brightmt@users.noreply.github.com> * New method (#159) * update format/wording * Update disassembler-evasion.md * Update disassembler-evasion.md * Corpus fix (#160) * update format/wording * fix tables * Edits --------- Co-authored-by: ryan <ryanxu@wustl.edu> * New method (#161) * update format/wording * Update disassembler-evasion.md * Update disassembler-evasion.md --------- Co-authored-by: brightmt <50853930+brightmt@users.noreply.github.com> Co-authored-by: ryan <ryanxu@wustl.edu>
6.2 KiB
6.2 KiB
| ID | X0006 |
| Type | Bot/Botnet (spambot) |
| Aliases | Bobax |
| Platforms | Windows |
| Year | 2014 |
| Associated ATT&CK Software | None |
Gamut
Gamut is a spamming botnet.
ATT&CK Techniques
| Name | Use |
|---|---|
| Command and Control::Application Layer Protocol::Web Protocols (T1071.001) | The malware uses HTTP for command and control. [1] |
| Defense Evasion::File and Directory Permissions Modification (T1222) | Gamut sets file attributes. [3] |
| Execution::Shared Modules (T1129) | Gamut links functions at runtime on Windows. [3] |
Enhanced ATT&CK Techniques
| Name | Use |
|---|---|
| Defense Evasion::Modify Registry (E1112) | The malware adds a registry key. [1] |
| Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02) | Gamut encodes data using XOR. [3] |
| Discovery::Application Window Discovery::Window Text (E1010.m01) | Gamut gets a graphical window text. [3] |
| Command and Control::Ingress Tool Transfer (E1105) | The malware receives files from C2. [1] |
| Discovery::File and Directory Discovery (E1083) | Gamut gets common file paths. [3] |
| Discovery::System Information Discovery (E1082) | Gamut queries environment variables. [3] |
| Execution::Command and Scripting Interpreter (E1059) | Gamut accepts command line arguments. [3] |
MBC Behaviors
Indicators of Compromise
SHA256 Hashes
- a56162bc623841102301df8e5c918f27fe8c2a58ae049d81c838fcf256654932
- 1a9c4807500d25e83c456185a6b4571108e0f00c45667b520725ca8ae6f34fa4
References
[1] https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/gamut-spambot-analysis/
[2] https://any.run/report/a56162bc623841102301df8e5c918f27fe8c2a58ae049d81c838fcf256654932/1a6f6db3-83d5-442e-8f0d-42cfab2e0d34
[3] capa v4.0, analyzed at MITRE on 10/12/2022