ATT&CKReferencesFireEye HAWKBALL Jun 2019

FireEye HAWKBALL Jun 2019

Patil, S. and Williams, M.. (2019, June 5). Government Sector in Central Asia Targeted With New HAWKBALL Backdoor Delivered via Microsoft Office Vulnerabilities. Retrieved June 20, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareHAWKBALL

HAWKBALL has encrypted the payload with an XOR-based algorithm.

T1033
System Owner/User Discovery
MalwareHAWKBALL

HAWKBALL can collect the user name of the system.

T1041
Exfiltration Over C2 Channel
MalwareHAWKBALL

HAWKBALL has sent system information and files over the C2 channel.

T1059.003
Windows Command Shell
MalwareHAWKBALL

HAWKBALL has created a cmd.exe reverse shell, executed commands, and uploaded output via the command line.

T1070.004
File Deletion
MalwareHAWKBALL

HAWKBALL has the ability to delete files.

T1071.001
Web Protocols
MalwareHAWKBALL

HAWKBALL has used HTTP to communicate with a single hard-coded C2 server.

T1082
System Information Discovery
MalwareHAWKBALL

HAWKBALL can collect the OS version, architecture information, and computer name.

T1106
Native API
MalwareHAWKBALL

HAWKBALL has leveraged several Windows API calls to create processes, gather disk information, and detect debugger activity.

T1203
Exploitation for Client Execution
MalwareHAWKBALL

HAWKBALL has exploited Microsoft Office vulnerabilities CVE-2017-11882 and CVE-2018-0802 to deliver the payload.

T1559.002
Dynamic Data Exchange
MalwareHAWKBALL

HAWKBALL has used an OLE object that uses Equation Editor to drop the embedded shellcode.

T1560.003
Archive via Custom Method
MalwareHAWKBALL

HAWKBALL has encrypted data with XOR before sending it over the C2 channel.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.