ATT&CKReferencesUS-CERT Bankshot Dec 2017

US-CERT Bankshot Dec 2017

US-CERT. (2017, December 13). Malware Analysis Report (MAR) - 10135536-B. Retrieved July 17, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareBankshot

Bankshot searches for certain Registry keys to be configured before executing the payload.

T1059.003
Windows Command Shell
MalwareBankshot

Bankshot uses the command-line interface to execute arbitrary commands.

T1070
Indicator Removal
MalwareBankshot

Bankshot deletes all artifacts associated with the malware from the infected machine.

T1082
System Information Discovery
MalwareBankshot

Bankshot gathers system information, network addresses, and the operation system version.

T1083
File and Directory Discovery
MalwareBankshot

Bankshot searches for files on the victim's machine.

T1105
Ingress Tool Transfer
MalwareBankshot

Bankshot uploads files and secondary payloads to the victim's machine.

T1112
Modify Registry
MalwareBankshot

Bankshot writes data into the Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Pniumj.

T1140
Deobfuscate/Decode Files or Information
MalwareBankshot

Bankshot decodes embedded XOR strings.

T1543.003
Windows Service
MalwareBankshot

Bankshot can terminate a specific process by its process id.

T1571
Non-Standard Port
MalwareBankshot

Bankshot binds and listens on port 1058 for HTTP traffic while also utilizing a FakeTLS method.

T1680
Local Storage Discovery
MalwareBankshot

Bankshot gathers disk type and disk free space.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.