Salinas, M., Holguin, J. (2017, June). Evolution of Trickbot. Retrieved July 31, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareTrickBot | TrickBot collects local files and information from the victim’s local machine. |
| T1007 System Service Discovery |
MalwareTrickBot | TrickBot collects a list of install programs and services on the system’s machine. |
| T1016 System Network Configuration Discovery |
MalwareTrickBot | TrickBot obtains the IP address, location, and other relevant network information from the victim’s machine. |
| T1027 Obfuscated Files or Information |
MalwareTrickBot | TrickBot uses non-descriptive names to hide functionality. |
| T1027.002 Software Packing |
MalwareTrickBot | TrickBot leverages a custom packer to obfuscate its functionality. |
| T1027.013 Encrypted/Encoded File |
MalwareTrickBot | TrickBot uses an AES CBC (256 bits) encryption algorithm for its loader and configuration files. |
| T1053.005 Scheduled Task |
MalwareTrickBot | TrickBot creates a scheduled task on the system that provides persistence. |
| T1055.012 Process Hollowing |
MalwareTrickBot | TrickBot injects into the svchost.exe process. |
| T1071.001 Web Protocols |
MalwareTrickBot | TrickBot uses HTTPS to communicate with its C2 servers, to get malware updates, modules that perform most of the malware logic and various configuration files. |
| T1082 System Information Discovery |
MalwareTrickBot | TrickBot gathers the OS version, machine name, CPU type, amount of RAM available, and UEFI/BIOS firmware information from the victim’s machine. |
| T1083 File and Directory Discovery |
MalwareTrickBot | TrickBot searches the system for all of the following file extensions: .avi, .mov, .mkv, .mpeg, .mpeg4, .mp4, .mp3, .wav, .ogg, .jpeg, .jpg, .png, .bmp, .gif, .tiff, .ico, .xlsx, and .zip. It can also obtain browsing history, cookies, and plug-in information. |
| T1087.001 Local Account |
MalwareTrickBot | TrickBot collects the users of the system. |
| T1106 Native API |
MalwareTrickBot | TrickBot uses the Windows API call, CreateProcessW(), to manage execution flow. TrickBot has also used |
| T1571 Non-Standard Port |
MalwareTrickBot | Some TrickBot samples have used HTTP over ports 447 and 8082 for C2. Newer versions of TrickBot have been known to use a custom communication protocol which sends the data unencrypted over port 443. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.