ATT&CKReferencesGigamon BADHATCH Jul 2019

Gigamon BADHATCH Jul 2019

Savelesky, K., et al. (2019, July 23). ABADBABE 8BADFOOD: Discovering BADHATCH and a Detailed Look at FIN8's Tooling. Retrieved September 8, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1027.009
Embedded Payloads
MalwareBADHATCH

BADHATCH has an embedded second stage DLL payload within the first stage of the malware.

T1041
Exfiltration Over C2 Channel
MalwareBADHATCH

BADHATCH can exfiltrate data over the C2 channel.

T1047
Windows Management Instrumentation
MalwareBADHATCH

BADHATCH can utilize WMI to collect system information, create new processes, and run malicious PowerShell scripts on a compromised machine.

T1055
Process Injection
MalwareBADHATCH

BADHATCH can inject itself into an existing explorer.exe process by using `RtlCreateUserThread`.

T1055.001
Dynamic-link Library Injection
MalwareBADHATCH

BADHATCH has the ability to execute a malicious DLL by injecting into `explorer.exe` on a compromised machine.

T1055.004
Asynchronous Procedure Call
MalwareBADHATCH

BADHATCH can inject itself into a new `svchost.exe -k netsvcs` process using the asynchronous procedure call (APC) queue.

T1059.001
PowerShell
MalwareBADHATCH

BADHATCH can utilize `powershell.exe` to execute commands on a compromised host.

T1059.003
Windows Command Shell
MalwareBADHATCH

BADHATCH can use `cmd.exe` to execute commands on a compromised host.

T1070.004
File Deletion
MalwareBADHATCH

BADHATCH has the ability to delete PowerShell scripts from a compromised machine.

T1071.001
Web Protocols
MalwareBADHATCH

BADHATCH can use HTTP and HTTPS over port 443 to communicate with actor-controlled C2 servers.

T1082
System Information Discovery
MalwareBADHATCH

BADHATCH can obtain current system information from a compromised machine such as the `SHELL PID`, `PSVERSION`, `HOSTNAME`, `LOGONSERVER`, `LASTBOOTUP`, OS type/version, bitness, and hostname.

T1105
Ingress Tool Transfer
MalwareBADHATCH

BADHATCH has the ability to load a second stage malicious DLL file onto a compromised machine.

T1106
Native API
MalwareBADHATCH

BADHATCH can utilize Native API functions such as, `ToolHelp32` and `Rt1AdjustPrivilege` to enable `SeDebugPrivilege` on a compromised machine.

T1573.002
Asymmetric Cryptography
MalwareBADHATCH

BADHATCH can beacon to a hardcoded C2 IP address using TLS encryption every 5 minutes.

T1620
Reflective Code Loading
MalwareBADHATCH

BADHATCH can copy a large byte array of 64-bit shellcode into process memory and execute it with a call to `CreateThread`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.