Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1001.001 Junk Data |
BendyBear has used byte randomization to obscure its behavior. |
| T1012 Query Registry |
BendyBear can query the host's Registry key at |
| T1027.013 Encrypted/Encoded File |
BendyBear has encrypted payloads using RC4 and XOR. |
| T1027.014 Polymorphic Code |
BendyBear changes its runtime footprint during code execution to evade signature-based defenses. |
| T1105 Ingress Tool Transfer |
BendyBear is designed to download an implant from a C2 server. |
| T1106 Native API |
BendyBear can load and execute modules and Windows Application Programming (API) calls using standard shellcode API hashing. |
| T1124 System Time Discovery |
BendyBear has the ability to determine local time on a compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
BendyBear has decrypted function blocks using a XOR key during runtime to evade detection. |
| T1497.003 Time Based Checks |
BendyBear can check for analysis environments and signs of debugging using the Windows API |
| T1571 Non-Standard Port |
BendyBear has used a custom RC4 and XOR encrypted protocol over port 443 for C2. |
| T1573.001 Symmetric Cryptography |
BendyBear communicates to a C2 server over port 443 using modified RC4 and XOR-encrypted chunks. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.