ATT&CKReferencesTrend Micro Qakbot May 2020

Trend Micro Qakbot May 2020

Mendoza, E. et al. (2020, May 25). Qakbot Resurges, Spreads through VBS Files. Retrieved September 27, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1027.001
Binary Padding
MalwareQakBot

QakBot can use large file sizes to evade detection.

T1053.005
Scheduled Task
MalwareQakBot

QakBot has the ability to create scheduled tasks for persistence.

T1055
Process Injection
MalwareQakBot

QakBot can inject itself into processes including explore.exe, Iexplore.exe, Mobsync.exe., and wermgr.exe.

T1059.005
Visual Basic
MalwareQakBot

QakBot can use VBS to download and execute malicious files.

T1071.001
Web Protocols
MalwareQakBot

QakBot has the ability to use HTTP and HTTPS in communication with C2 servers.

T1091
Replication Through Removable Media
MalwareQakBot

QakBot has the ability to use removable drives to spread through compromised networks.

T1105
Ingress Tool Transfer
MalwareQakBot

QakBot has the ability to download additional components and malware.

T1120
Peripheral Device Discovery
MalwareQakBot

QakBot can identify peripheral devices on targeted systems.

T1135
Network Share Discovery
MalwareQakBot

QakBot can use net share to identify network shares for use in lateral movement.

T1204.001
Malicious Link
MalwareQakBot

QakBot has gained execution through users opening malicious links.

T1204.002
Malicious File
MalwareQakBot

QakBot has gained execution through users opening malicious attachments.

T1497.001
System Checks
MalwareQakBot

QakBot can check the compromised host for the presence of multiple executables associated with analysis tools and halt execution if any are found.

T1547.001
Registry Run Keys / Startup Folder
MalwareQakBot

QakBot can maintain persistence by creating an auto-run Registry key.

T1566.001
Spearphishing Attachment
MalwareQakBot

QakBot has spread through emails with malicious attachments.

T1566.002
Spearphishing Link
MalwareQakBot

QakBot has spread through emails with malicious links.

T1568.002
Domain Generation Algorithms
MalwareQakBot

QakBot can use domain generation algorithms in C2 communication.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.