Vrabie, V., et al. (2021, March 10). FIN8 Returns with Improved BADHATCH Toolkit. Retrieved September 8, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1018 Remote System Discovery |
MalwareBADHATCH | BADHATCH can use a PowerShell object such as, `System.Net.NetworkInformation.Ping` to ping a computer. |
| T1027.010 Command Obfuscation |
MalwareBADHATCH | BADHATCH malicious PowerShell commands can be encoded with base64. |
| T1027.015 Compression |
MalwareBADHATCH | BADHATCH can be compressed with the ApLib algorithm. |
| T1033 System Owner/User Discovery |
MalwareBADHATCH | BADHATCH can obtain logged user information from a compromised machine and can execute the command `whoami.exe`. |
| T1041 Exfiltration Over C2 Channel |
MalwareBADHATCH | BADHATCH can exfiltrate data over the C2 channel. |
| T1046 Network Service Discovery |
MalwareBADHATCH | BADHATCH can check for open ports on a computer by establishing a TCP connection. |
| T1047 Windows Management Instrumentation |
MalwareBADHATCH | BADHATCH can utilize WMI to collect system information, create new processes, and run malicious PowerShell scripts on a compromised machine. |
| T1049 System Network Connections Discovery |
MalwareBADHATCH | BADHATCH can execute `netstat.exe -f` on a compromised machine. |
| T1053.005 Scheduled Task |
MalwareBADHATCH | BADHATCH can use `schtasks.exe` to gain persistence. |
| T1055 Process Injection |
MalwareBADHATCH | BADHATCH can inject itself into an existing explorer.exe process by using `RtlCreateUserThread`. |
| T1055.004 Asynchronous Procedure Call |
MalwareBADHATCH | BADHATCH can inject itself into a new `svchost.exe -k netsvcs` process using the asynchronous procedure call (APC) queue. |
| T1057 Process Discovery |
MalwareBADHATCH | BADHATCH can retrieve a list of running processes from a compromised machine. |
| T1059.001 PowerShell |
MalwareBADHATCH | BADHATCH can utilize `powershell.exe` to execute commands on a compromised host. |
| T1059.003 Windows Command Shell |
MalwareBADHATCH | BADHATCH can use `cmd.exe` to execute commands on a compromised host. |
| T1069.002 Domain Groups |
MalwareBADHATCH | BADHATCH can use `net.exe group "domain admins" /domain` to identify Domain Administrators. |
| T1071.001 Web Protocols |
MalwareBADHATCH | BADHATCH can use HTTP and HTTPS over port 443 to communicate with actor-controlled C2 servers. |
| T1071.002 File Transfer Protocols |
MalwareBADHATCH | BADHATCH can emulate an FTP server to connect to actor-controlled C2 servers. |
| T1082 System Information Discovery |
MalwareBADHATCH | BADHATCH can obtain current system information from a compromised machine such as the `SHELL PID`, `PSVERSION`, `HOSTNAME`, `LOGONSERVER`, `LASTBOOTUP`, OS type/version, bitness, and hostname. |
| T1090 Proxy |
MalwareBADHATCH | BADHATCH can use SOCKS4 and SOCKS5 proxies to connect to actor-controlled C2 servers. BADHATCH can also emulate a reverse proxy on a compromised machine to connect with actor-controlled C2 servers. |
| T1102 Web Service |
MalwareBADHATCH | BADHATCH can be utilized to abuse `sslip.io`, a free IP to domain mapping service, as part of actor-controlled C2 channels. |
| T1113 Screen Capture |
MalwareBADHATCH | BADHATCH can take screenshots and send them to an actor-controlled C2 server. |
| T1124 System Time Discovery |
MalwareBADHATCH | BADHATCH can obtain the `DATETIME` and `UPTIME` from a compromised machine. |
| T1134.001 Token Impersonation/Theft |
MalwareBADHATCH | BADHATCH can impersonate a `lsass.exe` or `vmtoolsd.exe` token. |
| T1135 Network Share Discovery |
MalwareBADHATCH | BADHATCH can check a user's access to the C$ share on a compromised machine. |
| T1482 Domain Trust Discovery |
MalwareBADHATCH | BADHATCH can use `nltest.exe /domain_trusts` to discover domain trust relationships on a compromised machine. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwareBADHATCH | BADHATCH can use WMI event subscriptions for persistence. |
| T1548.002 Bypass User Account Control |
MalwareBADHATCH | BADHATCH can utilize the CMSTPLUA COM interface and the SilentCleanup task to bypass UAC. |
| T1550.002 Pass the Hash |
MalwareBADHATCH | BADHATCH can perform pass the hash on compromised machines with x64 versions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.