Sadique, M. and Singh, A. (2020, September 29). Spear Phishing Campaign Delivers Buer and Bazar Malware. Retrieved November 19, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareBazar | Bazar has a variant with a packed payload. |
| T1059.003 Windows Command Shell |
MalwareBazar | Bazar can launch cmd.exe to perform reconnaissance commands. |
| T1102 Web Service |
MalwareBazar | Bazar downloads have been hosted on Google Docs. |
| T1104 Multi-Stage Channels |
MalwareBazar | The Bazar loader is used to download and execute the Bazar backdoor. |
| T1105 Ingress Tool Transfer |
MalwareBazar | Bazar can download and deploy additional payloads, including ransomware and post-exploitation frameworks such as Cobalt Strike. |
| T1204.001 Malicious Link |
MalwareBazar | Bazar can gain execution after a user clicks on a malicious link to decoy landing pages hosted on Google Docs. |
| T1547.004 Winlogon Helper DLL |
MalwareBazar | Bazar can use Winlogon Helper DLL to establish persistence. |
| T1566.002 Spearphishing Link |
MalwareBazar | Bazar has been spread via emails with embedded malicious links. |
| T1573.002 Asymmetric Cryptography |
MalwareBazar | Bazar can use TLS in C2 communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.