Grunzweig, J. and Miller-Osborn, J.. (2016, February 4). T9000: Advanced Modular Backdoor Uses Complex Anti-Analysis Techniques. Retrieved April 15, 2016.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareT9000 | T9000 gathers and beacons the MAC and IP addresses during installation. |
| T1033 System Owner/User Discovery |
MalwareT9000 | T9000 gathers and beacons the username of the logged in account during installation. It will also gather the username of running processes to determine if it is running as SYSTEM. |
| T1082 System Information Discovery |
MalwareT9000 | T9000 gathers and beacons the operating system build number and CPU Architecture (32-bit/64-bit) during installation. |
| T1113 Screen Capture |
MalwareT9000 | T9000 can take screenshots of the desktop and target application windows, saving them to user directories as one byte XOR encrypted .dat files. |
| T1119 Automated Collection |
MalwareT9000 | T9000 searches removable storage devices for files with a pre-defined list of file extensions (e.g. * .doc, *.ppt, *.xls, *.docx, *.pptx, *.xlsx). Any matching files are encrypted and written to a local user directory. |
| T1120 Peripheral Device Discovery |
MalwareT9000 | T9000 searches through connected drives for removable storage devices. |
| T1123 Audio Capture |
MalwareT9000 | T9000 uses the Skype API to record audio and video calls. It writes encrypted data to |
| T1124 System Time Discovery |
MalwareT9000 | T9000 gathers and beacons the system time during installation. |
| T1125 Video Capture |
MalwareT9000 | T9000 uses the Skype API to record audio and video calls. It writes encrypted data to |
| T1518.001 Security Software Discovery |
MalwareT9000 | T9000 performs checks for various antivirus and security products during installation. |
| T1546.010 AppInit DLLs |
MalwareT9000 | If a victim meets certain criteria, T9000 uses the AppInit_DLL functionality to achieve persistence by ensuring that every user mode process that is spawned will load its malicious DLL, ResN32.dll. It does this by creating the following Registry keys: |
| T1560.003 Archive via Custom Method |
MalwareT9000 | T9000 encrypts collected data using a single byte XOR key. |
| T1574.001 DLL |
MalwareT9000 | During the T9000 installation process, it drops a copy of the legitimate Microsoft binary igfxtray.exe. The executable contains a side-loading weakness which is used to load a portion of the malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.