ATT&CKReferencesProofpoint TA505 October 2019

Proofpoint TA505 October 2019

Schwarz, D. et al. (2019, October 16). TA505 Distributes New SDBbot Remote Access Trojan with Get2 Downloader. Retrieved May 29, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples29

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareSDBbot

SDBbot has the ability to access the file system on a compromised host.

T1016
System Network Configuration Discovery
MalwareSDBbot

SDBbot has the ability to determine the domain name and whether a proxy is configured on a compromised host.

T1021.001
Remote Desktop Protocol
MalwareSDBbot

SDBbot has the ability to use RDP to connect to victim's machines.

T1027
Obfuscated Files or Information
MalwareSDBbot

SDBbot has the ability to XOR the strings for its installer component with a hardcoded 128 byte key.

T1033
System Owner/User Discovery
MalwareSDBbot

SDBbot has the ability to identify the user on a compromised host.

T1033
System Owner/User Discovery
MalwareGet2

Get2 has the ability to identify the current username of an infected host.

T1055.001
Dynamic-link Library Injection
MalwareGet2

Get2 has the ability to inject DLLs into processes.

T1055.001
Dynamic-link Library Injection
MalwareSDBbot

SDBbot has the ability to inject a downloaded DLL into a newly created rundll32.exe process.

T1057
Process Discovery
MalwareGet2

Get2 has the ability to identify running processes on an infected host.

T1059
Command and Scripting Interpreter
MalwareGet2

Get2 has the ability to run executables with command-line arguments.

T1059.003
Windows Command Shell
MalwareSDBbot

SDBbot has the ability to use the command shell to execute commands on a compromised host.

T1070
Indicator Removal
MalwareSDBbot

SDBbot has the ability to clean up and remove data structures from a compromised host.

T1070.004
File Deletion
MalwareSDBbot

SDBbot has the ability to delete files from a compromised host.

T1071.001
Web Protocols
MalwareGet2

Get2 has the ability to use HTTP to send information collected from an infected host to C2.

T1082
System Information Discovery
MalwareSDBbot

SDBbot has the ability to identify the OS version, OS bit information and computer name.

T1082
System Information Discovery
MalwareGet2

Get2 has the ability to identify the computer name and Windows version of an infected host.

T1083
File and Directory Discovery
MalwareSDBbot

SDBbot has the ability to get directory listings or drive information on a compromised host.

T1090
Proxy
MalwareSDBbot

SDBbot has the ability to use port forwarding to establish a proxy between a target host and C2.

T1095
Non-Application Layer Protocol
MalwareSDBbot

SDBbot has the ability to communicate with C2 with TCP over port 443.

T1105
Ingress Tool Transfer
MalwareSDBbot

SDBbot has the ability to download a DLL from C2 to a compromised host.

T1125
Video Capture
MalwareSDBbot

SDBbot has the ability to record video on a compromised host.

T1140
Deobfuscate/Decode Files or Information
MalwareSDBbot

SDBbot has the ability to decrypt and decompress its payload to enable code execution.

T1204.001
Malicious Link
GroupTA505

TA505 has used lures to get users to click links in emails and attachments. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files.

T1204.002
Malicious File
GroupTA505

TA505 has used lures to get users to enable content in malicious attachments and execute malicious files contained in archives. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files.

T1546.011
Application Shimming
MalwareSDBbot

SDBbot has the ability to use application shimming for persistence if it detects it is running as admin on Windows XP or 7, by creating a shim database to patch services.exe.

T1546.012
Image File Execution Options Injection
MalwareSDBbot

SDBbot has the ability to use image file execution options for persistence if it detects it is running with admin privileges on a Windows version newer than Windows 7.

T1547.001
Registry Run Keys / Startup Folder
MalwareSDBbot

SDBbot has the ability to add a value to the Registry Run key to establish persistence if it detects it is running with regular user privilege.

T1566.001
Spearphishing Attachment
GroupTA505

TA505 has used spearphishing emails with malicious attachments to initially compromise victims.

T1566.002
Spearphishing Link
GroupTA505

TA505 has sent spearphishing emails containing malicious links.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.