Schwarz, D. et al. (2019, October 16). TA505 Distributes New SDBbot Remote Access Trojan with Get2 Downloader. Retrieved May 29, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareSDBbot | SDBbot has the ability to access the file system on a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareSDBbot | SDBbot has the ability to determine the domain name and whether a proxy is configured on a compromised host. |
| T1021.001 Remote Desktop Protocol |
MalwareSDBbot | SDBbot has the ability to use RDP to connect to victim's machines. |
| T1027 Obfuscated Files or Information |
MalwareSDBbot | SDBbot has the ability to XOR the strings for its installer component with a hardcoded 128 byte key. |
| T1033 System Owner/User Discovery |
MalwareSDBbot | SDBbot has the ability to identify the user on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareGet2 | Get2 has the ability to identify the current username of an infected host. |
| T1055.001 Dynamic-link Library Injection |
MalwareGet2 | Get2 has the ability to inject DLLs into processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareSDBbot | SDBbot has the ability to inject a downloaded DLL into a newly created rundll32.exe process. |
| T1057 Process Discovery |
MalwareGet2 | Get2 has the ability to identify running processes on an infected host. |
| T1059 Command and Scripting Interpreter |
MalwareGet2 | Get2 has the ability to run executables with command-line arguments. |
| T1059.003 Windows Command Shell |
MalwareSDBbot | SDBbot has the ability to use the command shell to execute commands on a compromised host. |
| T1070 Indicator Removal |
MalwareSDBbot | SDBbot has the ability to clean up and remove data structures from a compromised host. |
| T1070.004 File Deletion |
MalwareSDBbot | SDBbot has the ability to delete files from a compromised host. |
| T1071.001 Web Protocols |
MalwareGet2 | Get2 has the ability to use HTTP to send information collected from an infected host to C2. |
| T1082 System Information Discovery |
MalwareSDBbot | SDBbot has the ability to identify the OS version, OS bit information and computer name. |
| T1082 System Information Discovery |
MalwareGet2 | Get2 has the ability to identify the computer name and Windows version of an infected host. |
| T1083 File and Directory Discovery |
MalwareSDBbot | SDBbot has the ability to get directory listings or drive information on a compromised host. |
| T1090 Proxy |
MalwareSDBbot | SDBbot has the ability to use port forwarding to establish a proxy between a target host and C2. |
| T1095 Non-Application Layer Protocol |
MalwareSDBbot | SDBbot has the ability to communicate with C2 with TCP over port 443. |
| T1105 Ingress Tool Transfer |
MalwareSDBbot | SDBbot has the ability to download a DLL from C2 to a compromised host. |
| T1125 Video Capture |
MalwareSDBbot | SDBbot has the ability to record video on a compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSDBbot | SDBbot has the ability to decrypt and decompress its payload to enable code execution. |
| T1204.001 Malicious Link |
GroupTA505 | TA505 has used lures to get users to click links in emails and attachments. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files. |
| T1204.002 Malicious File |
GroupTA505 | TA505 has used lures to get users to enable content in malicious attachments and execute malicious files contained in archives. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files. |
| T1546.011 Application Shimming |
MalwareSDBbot | SDBbot has the ability to use application shimming for persistence if it detects it is running as admin on Windows XP or 7, by creating a shim database to patch services.exe. |
| T1546.012 Image File Execution Options Injection |
MalwareSDBbot | SDBbot has the ability to use image file execution options for persistence if it detects it is running with admin privileges on a Windows version newer than Windows 7. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSDBbot | SDBbot has the ability to add a value to the Registry Run key to establish persistence if it detects it is running with regular user privilege. |
| T1566.001 Spearphishing Attachment |
GroupTA505 | TA505 has used spearphishing emails with malicious attachments to initially compromise victims. |
| T1566.002 Spearphishing Link |
GroupTA505 | TA505 has sent spearphishing emails containing malicious links. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.