Mendoza, E. et al. (2020, May 25). Qakbot Resurges, Spreads through VBS Files. Retrieved September 27, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.001 Binary Padding |
MalwareQakBot | QakBot can use large file sizes to evade detection. |
| T1053.005 Scheduled Task |
MalwareQakBot | QakBot has the ability to create scheduled tasks for persistence. |
| T1055 Process Injection |
MalwareQakBot | QakBot can inject itself into processes including explore.exe, Iexplore.exe, Mobsync.exe., and wermgr.exe. |
| T1059.005 Visual Basic |
MalwareQakBot | QakBot can use VBS to download and execute malicious files. |
| T1071.001 Web Protocols |
MalwareQakBot | QakBot has the ability to use HTTP and HTTPS in communication with C2 servers. |
| T1091 Replication Through Removable Media |
MalwareQakBot | QakBot has the ability to use removable drives to spread through compromised networks. |
| T1105 Ingress Tool Transfer |
MalwareQakBot | QakBot has the ability to download additional components and malware. |
| T1120 Peripheral Device Discovery |
MalwareQakBot | QakBot can identify peripheral devices on targeted systems. |
| T1135 Network Share Discovery |
MalwareQakBot | QakBot can use |
| T1204.001 Malicious Link |
MalwareQakBot | QakBot has gained execution through users opening malicious links. |
| T1204.002 Malicious File |
MalwareQakBot | QakBot has gained execution through users opening malicious attachments. |
| T1497.001 System Checks |
MalwareQakBot | QakBot can check the compromised host for the presence of multiple executables associated with analysis tools and halt execution if any are found. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareQakBot | QakBot can maintain persistence by creating an auto-run Registry key. |
| T1566.001 Spearphishing Attachment |
MalwareQakBot | QakBot has spread through emails with malicious attachments. |
| T1566.002 Spearphishing Link |
MalwareQakBot | QakBot has spread through emails with malicious links. |
| T1568.002 Domain Generation Algorithms |
MalwareQakBot | QakBot can use domain generation algorithms in C2 communication. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.