Hayashi, K., Ray, V. (2018, July 31). Bisonal Malware Used in Attacks Against Russia and South Korea. Retrieved August 7, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareBisonal | Bisonal can execute |
| T1027.013 Encrypted/Encoded File |
MalwareBisonal | Bisonal's DLL file and non-malicious decoy file are encrypted with RC4 and some function name strings are obfuscated. |
| T1057 Process Discovery |
MalwareBisonal | Bisonal can obtain a list of running processes on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareBisonal | Bisonal has launched cmd.exe and used the ShellExecuteW() API function to execute commands on the system. |
| T1059.005 Visual Basic |
MalwareBisonal | Bisonal's dropper creates VBS scripts on the victim’s machine. |
| T1070.004 File Deletion |
MalwareBisonal | Bisonal will delete its dropper and VBS scripts from the victim’s machine. |
| T1071.001 Web Protocols |
MalwareBisonal | Bisonal has used HTTP for C2 communications. |
| T1082 System Information Discovery |
MalwareBisonal | Bisonal has used commands and API calls to gather system information. |
| T1105 Ingress Tool Transfer |
MalwareBisonal | Bisonal has the capability to download files to execute on the victim’s machine. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBisonal | Bisonal has decoded strings in the malware using XOR and RC4. |
| T1218.011 Rundll32 |
MalwareBisonal | Bisonal has used rundll32.exe to execute as part of the Registry Run key it adds: |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBisonal | Bisonal has added itself to the Registry key |
| T1573.001 Symmetric Cryptography |
MalwareBisonal | Bisonal variants reported on in 2014 and 2015 used a simple XOR cipher for C2. Some Bisonal samples encrypt C2 communications with RC4. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.