ATT&CKReferencesESET Casbaneiro Oct 2019

ESET Casbaneiro Oct 2019

ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples22

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareMetamorfo

Metamorfo has encrypted payloads and strings.

T1033
System Owner/User Discovery
MalwareMetamorfo

Metamorfo has collected the username from the victim's machine.

T1036.005
Match Legitimate Resource Name or Location
MalwareMetamorfo

Metamorfo has disguised an MSI file as the Adobe Acrobat Reader Installer and has masqueraded payloads as OneDrive, WhatsApp, or Spotify, for example.

T1041
Exfiltration Over C2 Channel
MalwareMetamorfo

Metamorfo can send the data it collects to the C2 server.

T1056.001
Keylogging
MalwareMetamorfo

Metamorfo has a command to launch a keylogger and capture keystrokes on the victim’s machine.

T1071.001
Web Protocols
MalwareMetamorfo

Metamorfo has used HTTP for C2.

T1082
System Information Discovery
MalwareMetamorfo

Metamorfo has collected the hostname and operating system version from the compromised host.

T1102.001
Dead Drop Resolver
MalwareMetamorfo

Metamorfo has used YouTube to store and hide C&C server domains.

T1105
Ingress Tool Transfer
MalwareMetamorfo

Metamorfo has used MSI files to download additional files to execute.

T1112
Modify Registry
MalwareMetamorfo

Metamorfo has written process names to the Registry, disabled IE browser features, deleted Registry keys, and changed the ExtendedUIHoverTime key.

T1113
Screen Capture
MalwareMetamorfo

Metamorfo can collect screenshots of the victim’s machine.

T1115
Clipboard Data
MalwareMetamorfo

Metamorfo has a function to hijack data from the clipboard by monitoring the contents of the clipboard and replacing the cryptocurrency wallet with the attacker's.

T1140
Deobfuscate/Decode Files or Information
MalwareMetamorfo

Upon execution, Metamorfo has unzipped itself after being downloaded to the system and has performed string decryption.

T1204.002
Malicious File
MalwareMetamorfo

Metamorfo requires the user to double-click the executable to run the malicious HTA file or to download a malicious installer.

T1218.007
Msiexec
MalwareMetamorfo

Metamorfo has used MsiExec.exe to automatically execute files.

T1518
Software Discovery
MalwareMetamorfo

Metamorfo has searched the compromised system for banking applications.

T1518.001
Security Software Discovery
MalwareMetamorfo

Metamorfo collects a list of installed antivirus software from the victim’s system.

T1547.001
Registry Run Keys / Startup Folder
MalwareMetamorfo

Metamorfo has configured persistence to the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run, Spotify =% APPDATA%\Spotify\Spotify.exe and used .LNK files in the startup folder to achieve persistence.

T1565.002
Transmitted Data Manipulation
MalwareMetamorfo

Metamorfo has a function that can watch the contents of the system clipboard for valid bitcoin addresses, which it then overwrites with the attacker's address.

T1566.001
Spearphishing Attachment
MalwareMetamorfo

Metamorfo has been delivered to victims via emails with malicious HTML attachments.

T1573.001
Symmetric Cryptography
MalwareMetamorfo

Metamorfo has encrypted C2 commands with AES-256.

T1574.001
DLL
MalwareMetamorfo

Metamorfo has side-loaded its malicious DLL file.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.