Truman, D. (2024, January 19). Inside the SYSTEMBC Command-and-Control Server. Retrieved June 18, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1053.005 Scheduled Task |
MalwareSystemBC | SystemBC has executed a copy of itself as a scheduled task with the `start` command. The copy of SystemBC has random file and directory names within the ProgramData directory. |
| T1090.003 Multi-hop Proxy |
MalwareSystemBC | SystemBC has used multiple proxy layers, such as SOCKS5 and Tor, for C2 communication. SystemBC has also leveraged Tor for encrypting and concealing C2 traffic. The server component of SystemBC has used SOCKS5 for C2 communication. |
| T1105 Ingress Tool Transfer |
MalwareSystemBC | SystemBC has downloaded additional files for execution on the victim’s machine. The server component of SystemBC has the ability to send additional files to victim machines. |
| T1124 System Time Discovery |
MalwareSystemBC | SystemBC has leveraged the time of the device to create a text file with a filename that uses the function of `uniqid(time()).‘.txt`, consisting of the 10 character UNIX timestamp and 13 hexadecimal characters. |
| T1571 Non-Standard Port |
MalwareSystemBC | The server component of SystemBC has used various TCP ports for C2 communication. |
| T1620 Reflective Code Loading |
MalwareSystemBC | SystemBC has downloaded a text file into memory and set the area of memory via the VirtualProtect call. Then, SystemBC has executed the file via the CreateThread call. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.