ATT&CKReferencesCheckPoint Bandook Nov 2020

CheckPoint Bandook Nov 2020

Check Point. (2020, November 26). Bandook: Signed & Delivered. Retrieved May 31, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples22

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareBandook

Bandook can collect local files from the system .

T1016
System Network Configuration Discovery
MalwareBandook

Bandook has a command to get the public IP address from a system.

T1027.003
Steganography
MalwareBandook

Bandook has used .PNG images within a zip file to build the executable.

T1041
Exfiltration Over C2 Channel
MalwareBandook

Bandook can upload files from a victim's machine over the C2 channel.

T1055.012
Process Hollowing
MalwareBandook

Bandook has been launched by starting iexplore.exe and replacing it with Bandook's payload.

T1059
Command and Scripting Interpreter
MalwareBandook

Bandook can support commands to execute Java-based payloads.

T1059.001
PowerShell
MalwareBandook

Bandook has used PowerShell loaders as part of execution.

T1059.003
Windows Command Shell
MalwareBandook

Bandook is capable of spawning a Windows command shell.

T1059.005
Visual Basic
MalwareBandook

Bandook has used malicious VBA code against the target system.

T1059.006
Python
MalwareBandook

Bandook can support commands to execute Python-based payloads.

T1070.004
File Deletion
MalwareBandook

Bandook has a command to delete a file.

T1083
File and Directory Discovery
MalwareBandook

Bandook has a command to list files on a system.

T1095
Non-Application Layer Protocol
MalwareBandook

Bandook has a command built in to use a raw TCP socket.

T1105
Ingress Tool Transfer
MalwareBandook

Bandook can download files to the system.

T1106
Native API
MalwareBandook

Bandook has used the ShellExecuteW() function call.

T1113
Screen Capture
MalwareBandook

Bandook is capable of taking an image of and uploading the current desktop.

T1140
Deobfuscate/Decode Files or Information
MalwareBandook

Bandook has decoded its PowerShell script.

T1204.002
Malicious File
MalwareBandook

Bandook has used lure documents to convince the user to enable macros.

T1553.002
Code Signing
MalwareBandook

Bandook was signed with valid Certum certificates.

T1566.001
Spearphishing Attachment
MalwareBandook

Bandook is delivered via a malicious Word document inside a zip file.

T1573.001
Symmetric Cryptography
MalwareBandook

Bandook has used AES encryption for C2 communication.

T1680
Local Storage Discovery
MalwareBandook

Bandook can collect information about the drives available on the system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.