Mercer, W., et al. (2020, March 5). Bisonal: 10 years of play. Retrieved January 26, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareBisonal | Bisonal has collected information from a compromised host. |
| T1012 Query Registry |
MalwareBisonal | Bisonal has used the RegQueryValueExA function to retrieve proxy information in the Registry. |
| T1016 System Network Configuration Discovery |
MalwareBisonal | Bisonal can execute |
| T1027.001 Binary Padding |
MalwareBisonal | Bisonal has appended random binary data to the end of itself to generate a large binary. |
| T1027.002 Software Packing |
MalwareBisonal | Bisonal has used the MPRESS packer and similar tools for obfuscation. |
| T1027.013 Encrypted/Encoded File |
MalwareBisonal | Bisonal's DLL file and non-malicious decoy file are encrypted with RC4 and some function name strings are obfuscated. |
| T1036 Masquerading |
MalwareBisonal | Bisonal dropped a decoy payload with a .jpg extension that contained a malicious Visual Basic script. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBisonal | Bisonal has renamed malicious code to `msacm32.dll` to hide within a legitimate library; earlier versions were disguised as `winhelp`. |
| T1041 Exfiltration Over C2 Channel |
MalwareBisonal | Bisonal has added the exfiltrated data to the URL over the C2 channel. |
| T1057 Process Discovery |
MalwareBisonal | Bisonal can obtain a list of running processes on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareBisonal | Bisonal has launched cmd.exe and used the ShellExecuteW() API function to execute commands on the system. |
| T1059.005 Visual Basic |
MalwareBisonal | Bisonal's dropper creates VBS scripts on the victim’s machine. |
| T1070.004 File Deletion |
MalwareBisonal | Bisonal will delete its dropper and VBS scripts from the victim’s machine. |
| T1082 System Information Discovery |
MalwareBisonal | Bisonal has used commands and API calls to gather system information. |
| T1083 File and Directory Discovery |
MalwareBisonal | Bisonal can retrieve a file listing from the system. |
| T1090 Proxy |
MalwareBisonal | Bisonal has supported use of a proxy server. |
| T1095 Non-Application Layer Protocol |
MalwareBisonal | Bisonal has used raw sockets for network communication. |
| T1105 Ingress Tool Transfer |
MalwareBisonal | Bisonal has the capability to download files to execute on the victim’s machine. |
| T1106 Native API |
MalwareBisonal | Bisonal has used the Windows API to communicate with the Service Control Manager to execute a thread. |
| T1112 Modify Registry |
MalwareBisonal | Bisonal has deleted Registry keys to clean up its prior activity. |
| T1132.001 Standard Encoding |
MalwareBisonal | Bisonal has encoded binary data with Base64 and ASCII. |
| T1137.006 Add-ins |
MalwareBisonal | Bisonal has been loaded through a `.wll` extension added to the ` %APPDATA%\microsoft\word\startup\` repository. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBisonal | Bisonal has decoded strings in the malware using XOR and RC4. |
| T1203 Exploitation for Client Execution |
GroupTonto Team | Tonto Team has exploited Microsoft vulnerabilities, including CVE-2018-0798, CVE-2018-8174, CVE-2018-0802, CVE-2017-11882, CVE-2019-9489 CVE-2020-8468, and CVE-2018-0798 to enable execution of their delivered malicious payloads. |
| T1204.002 Malicious File |
MalwareBisonal | Bisonal has relied on users to execute malicious file attachments delivered via spearphishing emails. |
| T1204.002 Malicious File |
GroupTonto Team | Tonto Team has relied on user interaction to open their malicious RTF documents. |
| T1497 Virtualization/Sandbox Evasion |
MalwareBisonal | Bisonal can check to determine if the compromised system is running on VMware. |
| T1497.003 Time Based Checks |
MalwareBisonal | Bisonal has checked if the malware is running in a virtual environment with the anti-debug function GetTickCount() to compare the timing. |
| T1543.003 Windows Service |
MalwareBisonal | Bisonal has been modified to be used as a Windows service. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBisonal | Bisonal has added itself to the Registry key |
| T1566.001 Spearphishing Attachment |
MalwareBisonal | Bisonal has been delivered as malicious email attachments. |
| T1568 Dynamic Resolution |
MalwareBisonal | Bisonal has used a dynamic DNS service for C2. |
| T1573.001 Symmetric Cryptography |
MalwareBisonal | Bisonal variants reported on in 2014 and 2015 used a simple XOR cipher for C2. Some Bisonal samples encrypt C2 communications with RC4. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.