Hada, H. (2021, December 28). Flagpro The new malware used by BlackTech. Retrieved March 25, 2022.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareFlagpro | Flagpro can collect data from a compromised host, including Windows authentication information. |
| T1010 Application Window Discovery |
MalwareFlagpro | Flagpro can check the name of the window displayed on the system. |
| T1016 System Network Configuration Discovery |
MalwareFlagpro | Flagpro has been used to execute the |
| T1018 Remote System Discovery |
MalwareFlagpro | Flagpro has been used to execute |
| T1027 Obfuscated Files or Information |
MalwareFlagpro | Flagpro has been delivered within ZIP or RAR password-protected archived files. |
| T1029 Scheduled Transfer |
MalwareFlagpro | Flagpro has the ability to wait for a specified time interval between communicating with and executing commands from C2. |
| T1033 System Owner/User Discovery |
MalwareFlagpro | Flagpro has been used to run the |
| T1036 Masquerading |
MalwareFlagpro | Flagpro can download malicious files with a .tmp extension and append them with .exe prior to execution. |
| T1041 Exfiltration Over C2 Channel |
MalwareFlagpro | Flagpro has exfiltrated data to the C2 server. |
| T1049 System Network Connections Discovery |
MalwareFlagpro | Flagpro has been used to execute |
| T1057 Process Discovery |
MalwareFlagpro | Flagpro has been used to run the |
| T1059.003 Windows Command Shell |
MalwareFlagpro | Flagpro can use `cmd.exe` to execute commands received from C2. |
| T1059.005 Visual Basic |
MalwareFlagpro | Flagpro can execute malicious VBA macros embedded in .xlsm files. |
| T1069.001 Local Groups |
MalwareFlagpro | Flagpro has been used to execute the |
| T1070 Indicator Removal |
MalwareFlagpro | Flagpro can close specific Windows Security and Internet Explorer dialog boxes to mask external connections. |
| T1071.001 Web Protocols |
MalwareFlagpro | Flagpro can communicate with its C2 using HTTP. |
| T1105 Ingress Tool Transfer |
MalwareFlagpro | Flagpro can download additional malware from the C2 server. |
| T1106 Native API |
MalwareFlagpro | Flagpro can use Native API to enable obfuscation including `GetLastError` and `GetTickCount`. |
| T1132.001 Standard Encoding |
MalwareFlagpro | Flagpro has encoded bidirectional data communications between a target system and C2 server using Base64. |
| T1135 Network Share Discovery |
MalwareFlagpro | Flagpro has been used to execute `net view` to discover mapped network shares. |
| T1204.002 Malicious File |
MalwareFlagpro | Flagpro has relied on users clicking a malicious attachment delivered through spearphishing. |
| T1204.002 Malicious File |
GroupBlackTech | BlackTech has used e-mails with malicious documents to lure victims into installing malware. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFlagpro | Flagpro has dropped an executable file to the startup directory. |
| T1566.001 Spearphishing Attachment |
GroupBlackTech | BlackTech has used spearphishing e-mails with malicious password-protected archived files (ZIP or RAR) to deliver malware. |
| T1566.001 Spearphishing Attachment |
MalwareFlagpro | Flagpro has been distributed via spearphishing as an email attachment. |
| T1614.001 System Language Discovery |
MalwareFlagpro | Flagpro can check whether the target system is using Japanese, Taiwanese, or English through detection of specific Windows Security and Internet Explorer dialog. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.