US-CERT. (2018, February 06). Malware Analysis Report (MAR) - 10135536-G. Retrieved June 7, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareBADCALL | BADCALL collects the network adapter information. |
| T1082 System Information Discovery |
MalwareBADCALL | BADCALL collects the computer name and host name on the compromised system. |
| T1090 Proxy |
MalwareBADCALL | BADCALL functions as a proxy server between the victim and C2 server. |
| T1112 Modify Registry |
MalwareBADCALL | BADCALL modifies the firewall Registry key |
| T1571 Non-Standard Port |
MalwareBADCALL | BADCALL communicates on ports 443 and 8000 with a FakeTLS method. |
| T1573.001 Symmetric Cryptography |
MalwareBADCALL | BADCALL encrypts C2 traffic using an XOR/ADD cipher. |
| T1686.003 Windows Host Firewall |
MalwareBADCALL | BADCALL disables the Windows firewall before binding to a port. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.