ATT&CKReferencesHarmonProofpoint_SystemBC_Aug2019

HarmonProofpoint_SystemBC_Aug2019

Harmon, K., et al. (2019, August 1). SystemBC is like Christmas in July for SOCKS5 Malware and Exploit Kits . Retrieved June 13, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1071.004
DNS
MalwareSystemBC

SystemBC has used DNS servers to resolve .bit domains to C2 infrastructure.

T1082
System Information Discovery
MalwareSystemBC

SystemBC has collected username , build number and serial number, then sent the information to the C2 server. SystemBC has also gathered device name, operating system, and processor type.

T1090.003
Multi-hop Proxy
MalwareSystemBC

SystemBC has used multiple proxy layers, such as SOCKS5 and Tor, for C2 communication. SystemBC has also leveraged Tor for encrypting and concealing C2 traffic. The server component of SystemBC has used SOCKS5 for C2 communication.

T1480
Execution Guardrails
MalwareSystemBC

SystemBC has checked if the last characters of DNS server names end in .bit before initializing C2 communication. SystemBC has identified running processes associated with anti-virus solutions to include `a2guard.exe` to determine whether it executes or not.

T1573.001
Symmetric Cryptography
MalwareSystemBC

SystemBC has encrypted its C2 traffic with RC4.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.