ATT&CKReferencesCyberBit Dtrack

CyberBit Dtrack

Hod Gavriel. (2019, November 21). Dtrack: In-depth analysis of APT on a nuclear power plant. Retrieved January 20, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareDtrack

Dtrack can collect a variety of information from victim machines.

T1012
Query Registry
MalwareDtrack

Dtrack can collect the RegisteredOwner, RegisteredOrganization, and InstallDate registry values.

T1016
System Network Configuration Discovery
MalwareDtrack

Dtrack can collect the host's IP addresses using the ipconfig command.

T1036.005
Match Legitimate Resource Name or Location
MalwareDtrack

One of Dtrack can hide in replicas of legitimate programs like OllyDbg, 7-Zip, and FileZilla.

T1057
Process Discovery
MalwareDtrack

Dtrack’s dropper can list all running processes.

T1059.003
Windows Command Shell
MalwareDtrack

Dtrack has used cmd.exe to add a persistent service.

T1074.001
Local Data Staging
MalwareDtrack

Dtrack can save collected data to disk, different file formats, and network shares.

T1078
Valid Accounts
MalwareDtrack

Dtrack used hard-coded credentials to gain access to a network share.

T1082
System Information Discovery
MalwareDtrack

Dtrack can collect the victim's computer name, hostname and adapter information to create a unique identifier.

T1083
File and Directory Discovery
MalwareDtrack

Dtrack can list files on available disk volumes.

T1105
Ingress Tool Transfer
MalwareDtrack

Dtrack’s can download and upload a file to the victim’s computer.

T1129
Shared Modules
MalwareDtrack

Dtrack contains a function that calls LoadLibrary and GetProcAddress.

T1217
Browser Information Discovery
MalwareDtrack

Dtrack can retrieve browser history.

T1543.003
Windows Service
MalwareDtrack

Dtrack can add a service called WBService to establish persistence.

T1574
Hijack Execution Flow
MalwareDtrack

One of Dtrack can replace the normal flow of a program execution with malicious code.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.