Xiao, C. (2018, September 17). Xbash Combines Botnet, Ransomware, Coinmining in Worm that Targets Linux and Windows. Retrieved November 14, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareXbash | Xbash can collect IP addresses and local intranet information from a victim’s machine. |
| T1046 Network Service Discovery |
MalwareXbash | Xbash can perform port scanning of TCP and UDP ports. |
| T1053.003 Cron |
MalwareXbash | Xbash can create a cronjob for persistence if it determines it is on a Linux system. |
| T1059.001 PowerShell |
MalwareXbash | Xbash can use scripts to invoke PowerShell to download a malicious PE executable or PE DLL for execution. |
| T1059.005 Visual Basic |
MalwareXbash | Xbash can execute malicious VBScript payloads on the victim’s machine. |
| T1059.007 JavaScript |
MalwareXbash | Xbash can execute malicious JavaScript payloads on the victim’s machine. |
| T1071.001 Web Protocols |
MalwareXbash | Xbash uses HTTP for C2 communications. |
| T1102.001 Dead Drop Resolver |
MalwareXbash | Xbash can obtain a webpage hosted on Pastebin to update its C2 domain list. |
| T1105 Ingress Tool Transfer |
MalwareXbash | Xbash can download additional malicious files from its C2 server. |
| T1110.001 Password Guessing |
MalwareXbash | Xbash can obtain a list of weak passwords from the C2 server to use for brute forcing as well as attempt to brute force services with open ports. |
| T1203 Exploitation for Client Execution |
MalwareXbash | Xbash can attempt to exploit known vulnerabilities in Hadoop, Redis, or ActiveMQ when it finds those services running in order to conduct further execution. |
| T1218.005 Mshta |
MalwareXbash | Xbash can use mshta for executing scripts. |
| T1218.010 Regsvr32 |
MalwareXbash | Xbash can use regsvr32 for executing scripts. |
| T1485 Data Destruction |
MalwareXbash | Xbash has destroyed Linux-based databases as part of its ransomware capabilities. |
| T1486 Data Encrypted for Impact |
MalwareXbash | Xbash has maliciously encrypted victim's database systems and demanded a cryptocurrency ransom be paid. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareXbash | Xbash can create a Startup item for persistence if it determines it is on a Windows system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.