ATT&CKReferencesUnit42 Xbash Sept 2018

Unit42 Xbash Sept 2018

Xiao, C. (2018, September 17). Xbash Combines Botnet, Ransomware, Coinmining in Worm that Targets Linux and Windows. Retrieved November 14, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareXbash

Xbash can collect IP addresses and local intranet information from a victim’s machine.

T1046
Network Service Discovery
MalwareXbash

Xbash can perform port scanning of TCP and UDP ports.

T1053.003
Cron
MalwareXbash

Xbash can create a cronjob for persistence if it determines it is on a Linux system.

T1059.001
PowerShell
MalwareXbash

Xbash can use scripts to invoke PowerShell to download a malicious PE executable or PE DLL for execution.

T1059.005
Visual Basic
MalwareXbash

Xbash can execute malicious VBScript payloads on the victim’s machine.

T1059.007
JavaScript
MalwareXbash

Xbash can execute malicious JavaScript payloads on the victim’s machine.

T1071.001
Web Protocols
MalwareXbash

Xbash uses HTTP for C2 communications.

T1102.001
Dead Drop Resolver
MalwareXbash

Xbash can obtain a webpage hosted on Pastebin to update its C2 domain list.

T1105
Ingress Tool Transfer
MalwareXbash

Xbash can download additional malicious files from its C2 server.

T1110.001
Password Guessing
MalwareXbash

Xbash can obtain a list of weak passwords from the C2 server to use for brute forcing as well as attempt to brute force services with open ports.

T1203
Exploitation for Client Execution
MalwareXbash

Xbash can attempt to exploit known vulnerabilities in Hadoop, Redis, or ActiveMQ when it finds those services running in order to conduct further execution.

T1218.005
Mshta
MalwareXbash

Xbash can use mshta for executing scripts.

T1218.010
Regsvr32
MalwareXbash

Xbash can use regsvr32 for executing scripts.

T1485
Data Destruction
MalwareXbash

Xbash has destroyed Linux-based databases as part of its ransomware capabilities.

T1486
Data Encrypted for Impact
MalwareXbash

Xbash has maliciously encrypted victim's database systems and demanded a cryptocurrency ransom be paid.

T1547.001
Registry Run Keys / Startup Folder
MalwareXbash

Xbash can create a Startup item for persistence if it determines it is on a Windows system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.