US-CERT. (2017, December 13). Malware Analysis Report (MAR) - 10135536-B. Retrieved July 17, 2018.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareBankshot | Bankshot searches for certain Registry keys to be configured before executing the payload. |
| T1059.003 Windows Command Shell |
MalwareBankshot | Bankshot uses the command-line interface to execute arbitrary commands. |
| T1070 Indicator Removal |
MalwareBankshot | Bankshot deletes all artifacts associated with the malware from the infected machine. |
| T1082 System Information Discovery |
MalwareBankshot | Bankshot gathers system information, network addresses, and the operation system version. |
| T1083 File and Directory Discovery |
MalwareBankshot | Bankshot searches for files on the victim's machine. |
| T1105 Ingress Tool Transfer |
MalwareBankshot | Bankshot uploads files and secondary payloads to the victim's machine. |
| T1112 Modify Registry |
MalwareBankshot | Bankshot writes data into the Registry key |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBankshot | Bankshot decodes embedded XOR strings. |
| T1543.003 Windows Service |
MalwareBankshot | Bankshot can terminate a specific process by its process id. |
| T1571 Non-Standard Port |
MalwareBankshot | Bankshot binds and listens on port 1058 for HTTP traffic while also utilizing a FakeTLS method. |
| T1680 Local Storage Discovery |
MalwareBankshot | Bankshot gathers disk type and disk free space. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.