ATT&CKReferencesUS-CERT BADCALL

US-CERT BADCALL

US-CERT. (2018, February 06). Malware Analysis Report (MAR) - 10135536-G. Retrieved June 7, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareBADCALL

BADCALL collects the network adapter information.

T1082
System Information Discovery
MalwareBADCALL

BADCALL collects the computer name and host name on the compromised system.

T1090
Proxy
MalwareBADCALL

BADCALL functions as a proxy server between the victim and C2 server.

T1112
Modify Registry
MalwareBADCALL

BADCALL modifies the firewall Registry key SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfileGloballyOpenPorts\\List.

T1571
Non-Standard Port
MalwareBADCALL

BADCALL communicates on ports 443 and 8000 with a FakeTLS method.

T1573.001
Symmetric Cryptography
MalwareBADCALL

BADCALL encrypts C2 traffic using an XOR/ADD cipher.

T1686.003
Windows Host Firewall
MalwareBADCALL

BADCALL disables the Windows firewall before binding to a port.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.