Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
MalwareBlackEnergy | BlackEnergy has the capability to communicate over a backup channel via plus.google.com. |
| T1016 System Network Configuration Discovery |
MalwareBlackEnergy | BlackEnergy has gathered information about network IP configurations using ipconfig.exe and about routing tables using route.exe. |
| T1021.002 SMB/Windows Admin Shares |
MalwareBlackEnergy | BlackEnergy has run a plug-in on a victim to spread through the local network by using PsExec and accessing admin shares. |
| T1046 Network Service Discovery |
MalwareBlackEnergy | BlackEnergy has conducted port scans on a host. |
| T1049 System Network Connections Discovery |
MalwareBlackEnergy | BlackEnergy has gathered information about local network connections using netstat. |
| T1056.001 Keylogging |
MalwareBlackEnergy | BlackEnergy has run a keylogger plug-in on a victim. |
| T1057 Process Discovery |
MalwareBlackEnergy | BlackEnergy has gathered a process list by using Tasklist.exe. |
| T1082 System Information Discovery |
MalwareBlackEnergy | BlackEnergy has used Systeminfo to gather the OS version, as well as information on the system configuration, BIOS, the motherboard, and the processor. |
| T1083 File and Directory Discovery |
MalwareBlackEnergy | BlackEnergy gathers a list of installed apps from the uninstall program Registry. It also gathers registered mail, browser, and instant messaging clients from the Registry. BlackEnergy has searched for given file types. |
| T1113 Screen Capture |
MalwareBlackEnergy | BlackEnergy is capable of taking screenshots. |
| T1120 Peripheral Device Discovery |
MalwareBlackEnergy | BlackEnergy can gather very specific information about attached USB devices, to include device instance ID and drive geometry. |
| T1552.001 Credentials In Files |
MalwareBlackEnergy | BlackEnergy has used a plug-in to gather credentials stored in files on the host by various software programs, including The Bat! email client, Outlook, and Windows Credential Store. |
| T1555.003 Credentials from Web Browsers |
MalwareBlackEnergy | BlackEnergy has used a plug-in to gather credentials from web browsers including FireFox, Google Chrome, and Internet Explorer. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.