F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareBlackEnergy | BlackEnergy has gathered information about network IP configurations using ipconfig.exe and about routing tables using route.exe. |
| T1049 System Network Connections Discovery |
MalwareBlackEnergy | BlackEnergy has gathered information about local network connections using netstat. |
| T1055.001 Dynamic-link Library Injection |
MalwareBlackEnergy | BlackEnergy injects its DLL component into svchost.exe. |
| T1057 Process Discovery |
MalwareBlackEnergy | BlackEnergy has gathered a process list by using Tasklist.exe. |
| T1070 Indicator Removal |
MalwareBlackEnergy | BlackEnergy has removed the watermark associated with enabling the |
| T1071.001 Web Protocols |
MalwareBlackEnergy | BlackEnergy communicates with its C2 server over HTTP. |
| T1082 System Information Discovery |
MalwareBlackEnergy | BlackEnergy has used Systeminfo to gather the OS version, as well as information on the system configuration, BIOS, the motherboard, and the processor. |
| T1083 File and Directory Discovery |
MalwareBlackEnergy | BlackEnergy gathers a list of installed apps from the uninstall program Registry. It also gathers registered mail, browser, and instant messaging clients from the Registry. BlackEnergy has searched for given file types. |
| T1543.003 Windows Service |
MalwareBlackEnergy | One variant of BlackEnergy creates a new service using either a hard-coded or randomly generated name. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBlackEnergy | The BlackEnergy 3 variant drops its main DLL component and then creates a .lnk shortcut to that file in the startup folder. |
| T1547.009 Shortcut Modification |
MalwareBlackEnergy | The BlackEnergy 3 variant drops its main DLL component and then creates a .lnk shortcut to that file in the startup folder. |
| T1548.002 Bypass User Account Control |
MalwareBlackEnergy | BlackEnergy attempts to bypass default User Access Control (UAC) settings by exploiting a backward-compatibility setting found in Windows 7 and later. |
| T1552.001 Credentials In Files |
MalwareBlackEnergy | BlackEnergy has used a plug-in to gather credentials stored in files on the host by various software programs, including The Bat! email client, Outlook, and Windows Credential Store. |
| T1553.006 Code Signing Policy Modification |
MalwareBlackEnergy | BlackEnergy has enabled the |
| T1555.003 Credentials from Web Browsers |
MalwareBlackEnergy | BlackEnergy has used a plug-in to gather credentials from web browsers including FireFox, Google Chrome, and Internet Explorer. |
| T1574.010 Services File Permissions Weakness |
MalwareBlackEnergy | One variant of BlackEnergy locates existing driver services that have been disabled and drops its driver component into one of those service's paths, replacing the legitimate executable. The malware then sets the hijacked service to start automatically to establish persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.