ATT&CKReferencesS2 Grupo TrickBot June 2017

S2 Grupo TrickBot June 2017

Salinas, M., Holguin, J. (2017, June). Evolution of Trickbot. Retrieved July 31, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareTrickBot

TrickBot collects local files and information from the victim’s local machine.

T1007
System Service Discovery
MalwareTrickBot

TrickBot collects a list of install programs and services on the system’s machine.

T1016
System Network Configuration Discovery
MalwareTrickBot

TrickBot obtains the IP address, location, and other relevant network information from the victim’s machine.

T1027
Obfuscated Files or Information
MalwareTrickBot

TrickBot uses non-descriptive names to hide functionality.

T1027.002
Software Packing
MalwareTrickBot

TrickBot leverages a custom packer to obfuscate its functionality.

T1027.013
Encrypted/Encoded File
MalwareTrickBot

TrickBot uses an AES CBC (256 bits) encryption algorithm for its loader and configuration files.

T1053.005
Scheduled Task
MalwareTrickBot

TrickBot creates a scheduled task on the system that provides persistence.

T1055.012
Process Hollowing
MalwareTrickBot

TrickBot injects into the svchost.exe process.

T1071.001
Web Protocols
MalwareTrickBot

TrickBot uses HTTPS to communicate with its C2 servers, to get malware updates, modules that perform most of the malware logic and various configuration files.

T1082
System Information Discovery
MalwareTrickBot

TrickBot gathers the OS version, machine name, CPU type, amount of RAM available, and UEFI/BIOS firmware information from the victim’s machine.

T1083
File and Directory Discovery
MalwareTrickBot

TrickBot searches the system for all of the following file extensions: .avi, .mov, .mkv, .mpeg, .mpeg4, .mp4, .mp3, .wav, .ogg, .jpeg, .jpg, .png, .bmp, .gif, .tiff, .ico, .xlsx, and .zip. It can also obtain browsing history, cookies, and plug-in information.

T1087.001
Local Account
MalwareTrickBot

TrickBot collects the users of the system.

T1106
Native API
MalwareTrickBot

TrickBot uses the Windows API call, CreateProcessW(), to manage execution flow. TrickBot has also used Nt* API functions to perform Process Injection.

T1571
Non-Standard Port
MalwareTrickBot

Some TrickBot samples have used HTTP over ports 447 and 8082 for C2. Newer versions of TrickBot have been known to use a custom communication protocol which sends the data unencrypted over port 443.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.