Patil, S. and Williams, M.. (2019, June 5). Government Sector in Central Asia Targeted With New HAWKBALL Backdoor Delivered via Microsoft Office Vulnerabilities. Retrieved June 20, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareHAWKBALL | HAWKBALL has encrypted the payload with an XOR-based algorithm. |
| T1033 System Owner/User Discovery |
MalwareHAWKBALL | HAWKBALL can collect the user name of the system. |
| T1041 Exfiltration Over C2 Channel |
MalwareHAWKBALL | HAWKBALL has sent system information and files over the C2 channel. |
| T1059.003 Windows Command Shell |
MalwareHAWKBALL | HAWKBALL has created a cmd.exe reverse shell, executed commands, and uploaded output via the command line. |
| T1070.004 File Deletion |
MalwareHAWKBALL | HAWKBALL has the ability to delete files. |
| T1071.001 Web Protocols |
MalwareHAWKBALL | HAWKBALL has used HTTP to communicate with a single hard-coded C2 server. |
| T1082 System Information Discovery |
MalwareHAWKBALL | HAWKBALL can collect the OS version, architecture information, and computer name. |
| T1106 Native API |
MalwareHAWKBALL | HAWKBALL has leveraged several Windows API calls to create processes, gather disk information, and detect debugger activity. |
| T1203 Exploitation for Client Execution |
MalwareHAWKBALL | HAWKBALL has exploited Microsoft Office vulnerabilities CVE-2017-11882 and CVE-2018-0802 to deliver the payload. |
| T1559.002 Dynamic Data Exchange |
MalwareHAWKBALL | HAWKBALL has used an OLE object that uses Equation Editor to drop the embedded shellcode. |
| T1560.003 Archive via Custom Method |
MalwareHAWKBALL | HAWKBALL has encrypted data with XOR before sending it over the C2 channel. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.