Malware.View on attack.mitre.org
Saint Bot is a .NET downloader that has been used by Saint Bear since at least March 2021.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Saint Bot can collect files and information from a compromised host. |
| T1012 Query Registry |
Saint Bot has used `check_registry_keys` as part of its environmental checks. |
| T1016 System Network Configuration Discovery |
Saint Bot can collect the IP address of a victim machine. |
| T1027 Obfuscated Files or Information |
Saint Bot has been obfuscated to help avoid detection. |
| T1027.002 Software Packing |
Saint Bot has been packed using a dark market crypter. |
| T1033 System Owner/User Discovery |
Saint Bot can collect the username from a compromised host. |
| T1036 Masquerading |
Saint Bot has renamed malicious binaries as `wallpaper.mp4` and `slideshow.mp4` to avoid detection. |
| T1036.005 Match Legitimate Resource Name or Location |
Saint Bot has been disguised as a legitimate executable, including as Windows SDK. |
| T1053.005 Scheduled Task |
Saint Bot has created a scheduled task named "Maintenance" to establish persistence. |
| T1055.001 Dynamic-link Library Injection |
Saint Bot has injected its DLL component into `EhStorAurhn.exe`. |
| T1055.004 Asynchronous Procedure Call |
Saint Bot has written its payload into a newly-created `EhStorAuthn.exe` process using `ZwWriteVirtualMemory` and executed it using `NtQueueApcThread` and `ZwAlertResumeThread`. |
| T1055.012 Process Hollowing |
The Saint Bot loader has used API calls to spawn `MSBuild.exe` in a suspended state before injecting the decrypted Saint Bot binary into it. |
| T1057 Process Discovery |
Saint Bot has enumerated running processes on a compromised host to determine if it is running under the process name `dfrgui.exe`. |
| T1059.001 PowerShell |
Saint Bot has used PowerShell for execution. |
| T1059.003 Windows Command Shell |
Saint Bot has used `cmd.exe` and `.bat` scripts for execution. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.