Raggi, M. Schwarz, D.. (2019, August 1). LookBack Malware Targets the United States Utilities Sector with Phishing Attacks Impersonating Engineering Licensing Boards. Retrieved February 25, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareLookBack | LookBack can enumerate services on the victim machine. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareLookBack | LookBack has a C2 proxy tool that masquerades as |
| T1057 Process Discovery |
MalwareLookBack | LookBack can list running processes. |
| T1059.003 Windows Command Shell |
MalwareLookBack | LookBack executes the |
| T1059.005 Visual Basic |
MalwareLookBack | LookBack has used VBA macros in Microsoft Word attachments to drop additional files to the host. |
| T1070.004 File Deletion |
MalwareLookBack | LookBack removes itself after execution and can delete files on the system. |
| T1071.001 Web Protocols |
MalwareLookBack | LookBack’s C2 proxy tool sends data to a C2 server over HTTP. |
| T1083 File and Directory Discovery |
MalwareLookBack | LookBack can retrieve file listings from the victim machine. |
| T1095 Non-Application Layer Protocol |
MalwareLookBack | LookBack uses a custom binary protocol over sockets for C2 communications. |
| T1113 Screen Capture |
MalwareLookBack | LookBack can take desktop screenshots. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLookBack | LookBack has a function that decrypts malicious data. |
| T1489 Service Stop |
MalwareLookBack | LookBack can kill processes and delete services. |
| T1529 System Shutdown/Reboot |
MalwareLookBack | LookBack can shutdown and reboot the victim machine. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLookBack | LookBack sets up a Registry Run key to establish a persistence mechanism. |
| T1573.001 Symmetric Cryptography |
MalwareLookBack | LookBack uses a modified version of RC4 for data transfer. |
| T1574.001 DLL |
MalwareLookBack | LookBack side loads its communications module as a DLL into the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.