ATT&CKReferencesJoe Sec Trickbot

Joe Sec Trickbot

Joe Security. (2020, July 13). TrickBot's new API-Hammering explained. Retrieved September 30, 2021.

Open the source

Techniques1

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1055
Process Injection
MalwareTrickBot

TrickBot has used Nt* Native API functions to inject code into legitimate processes such as wermgr.exe.

T1106
Native API
MalwareTrickBot

TrickBot uses the Windows API call, CreateProcessW(), to manage execution flow. TrickBot has also used Nt* API functions to perform Process Injection.

T1140
Deobfuscate/Decode Files or Information
MalwareTrickBot

TrickBot decodes the configuration data and modules.

T1497.003
Time Based Checks
MalwareTrickBot

TrickBot has used printf and file I/O loops to delay process execution as part of API hammering.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.