Joe Security. (2020, July 13). TrickBot's new API-Hammering explained. Retrieved September 30, 2021.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1055 Process Injection |
MalwareTrickBot | TrickBot has used |
| T1106 Native API |
MalwareTrickBot | TrickBot uses the Windows API call, CreateProcessW(), to manage execution flow. TrickBot has also used |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTrickBot | TrickBot decodes the configuration data and modules. |
| T1497.003 Time Based Checks |
MalwareTrickBot | TrickBot has used |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.