ATT&CKReferencesMalwarebytes Saint Bot April 2021

Malwarebytes Saint Bot April 2021

Hasherezade. (2021, April 6). A deep dive into Saint Bot, a new downloader. Retrieved June 9, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples22

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareSaint Bot

Saint Bot can collect files and information from a compromised host.

T1012
Query Registry
MalwareSaint Bot

Saint Bot has used `check_registry_keys` as part of its environmental checks.

T1016
System Network Configuration Discovery
MalwareSaint Bot

Saint Bot can collect the IP address of a victim machine.

T1027.002
Software Packing
MalwareSaint Bot

Saint Bot has been packed using a dark market crypter.

T1033
System Owner/User Discovery
MalwareSaint Bot

Saint Bot can collect the username from a compromised host.

T1036
Masquerading
MalwareSaint Bot

Saint Bot has renamed malicious binaries as `wallpaper.mp4` and `slideshow.mp4` to avoid detection.

T1036.005
Match Legitimate Resource Name or Location
MalwareSaint Bot

Saint Bot has been disguised as a legitimate executable, including as Windows SDK.

T1053.005
Scheduled Task
MalwareSaint Bot

Saint Bot has created a scheduled task named "Maintenance" to establish persistence.

T1055.001
Dynamic-link Library Injection
MalwareSaint Bot

Saint Bot has injected its DLL component into `EhStorAurhn.exe`.

T1055.004
Asynchronous Procedure Call
MalwareSaint Bot

Saint Bot has written its payload into a newly-created `EhStorAuthn.exe` process using `ZwWriteVirtualMemory` and executed it using `NtQueueApcThread` and `ZwAlertResumeThread`.

T1071.001
Web Protocols
MalwareSaint Bot

Saint Bot has used HTTP for C2 communications.

T1082
System Information Discovery
MalwareSaint Bot

Saint Bot can identify the OS version, CPU, and other details from a victim's machine.

T1106
Native API
MalwareSaint Bot

Saint Bot has used different API calls, including `GetProcAddress`, `VirtualAllocEx`, `WriteProcessMemory`, `CreateProcessA`, and `SetThreadContext`.

T1132.001
Standard Encoding
MalwareSaint Bot

Saint Bot has used Base64 to encode its C2 communications.

T1140
Deobfuscate/Decode Files or Information
MalwareSaint Bot

Saint Bot can deobfuscate strings and files for execution.

T1204.002
Malicious File
MalwareSaint Bot

Saint Bot has relied on users to execute a malicious attachment delivered via spearphishing.

T1218.004
InstallUtil
MalwareSaint Bot

Saint Bot had used `InstallUtil.exe` to download and deploy executables.

T1218.010
Regsvr32
MalwareSaint Bot

Saint Bot has used `regsvr32` to execute scripts.

T1547.001
Registry Run Keys / Startup Folder
MalwareSaint Bot

Saint Bot has established persistence by being copied to the Startup directory or through the `\Software\Microsoft\Windows\CurrentVersion\Run` registry key.

T1566.001
Spearphishing Attachment
MalwareSaint Bot

Saint Bot has been distributed as malicious attachments within spearphishing emails.

T1614
System Location Discovery
MalwareSaint Bot

Saint Bot has conducted system locale checks to see if the compromised host is in Russia, Ukraine, Belarus, Armenia, Kazakhstan, or Moldova.

T1622
Debugger Evasion
MalwareSaint Bot

Saint Bot has used `is_debugger_present` as part of its environmental checks.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.