SDBbot

S0461

Malware.View on attack.mitre.org

About this malware

SDBbot is a backdoor with installer and loader components that has been used by TA505 since at least 2019.

Techniques used24

Procedure examples24

TechniqueProcedure example
T1005
Data from Local System

SDBbot has the ability to access the file system on a compromised host.

T1016
System Network Configuration Discovery

SDBbot has the ability to determine the domain name and whether a proxy is configured on a compromised host.

T1021.001
Remote Desktop Protocol

SDBbot has the ability to use RDP to connect to victim's machines.

T1027
Obfuscated Files or Information

SDBbot has the ability to XOR the strings for its installer component with a hardcoded 128 byte key.

T1027.002
Software Packing

SDBbot has used a packed installer file.

T1033
System Owner/User Discovery

SDBbot has the ability to identify the user on a compromised host.

T1041
Exfiltration Over C2 Channel

SDBbot has sent collected data from a compromised host to its C2 servers.

T1055.001
Dynamic-link Library Injection

SDBbot has the ability to inject a downloaded DLL into a newly created rundll32.exe process.

T1057
Process Discovery

SDBbot can enumerate a list of running processes on a compromised machine.

T1059.003
Windows Command Shell

SDBbot has the ability to use the command shell to execute commands on a compromised host.

T1070
Indicator Removal

SDBbot has the ability to clean up and remove data structures from a compromised host.

T1070.004
File Deletion

SDBbot has the ability to delete files from a compromised host.

T1082
System Information Discovery

SDBbot has the ability to identify the OS version, OS bit information and computer name.

T1083
File and Directory Discovery

SDBbot has the ability to get directory listings or drive information on a compromised host.

T1090
Proxy

SDBbot has the ability to use port forwarding to establish a proxy between a target host and C2.

View all 24 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. IBM TA505 April 2020 Open source
    Frydrych, M. (2020, April 14). TA505 Continues to Infect Networks With SDBbot RAT. Retrieved May 29, 2020.
  2. Proofpoint TA505 October 2019 Open source
    Schwarz, D. et al. (2019, October 16). TA505 Distributes New SDBbot Remote Access Trojan with Get2 Downloader. Retrieved May 29, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.