Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupBRONZE BUTLER | BRONZE BUTLER has used various tools (such as Mimikatz and WCE) to perform credential dumping. |
| T1005 Data from Local System |
GroupBRONZE BUTLER | BRONZE BUTLER has exfiltrated files stolen from local systems. |
| T1018 Remote System Discovery |
GroupBRONZE BUTLER | BRONZE BUTLER typically use |
| T1027.001 Binary Padding |
GroupBRONZE BUTLER | BRONZE BUTLER downloader code has included "0" characters at the end of the file to inflate the file size in a likely attempt to evade anti-virus detection. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupBRONZE BUTLER | BRONZE BUTLER has given malware the same name as an existing file on the file share server to cause users to unwittingly launch and install the malware on additional systems. |
| T1039 Data from Network Shared Drive |
GroupBRONZE BUTLER | BRONZE BUTLER has exfiltrated files stolen from file shares. |
| T1053.002 At |
GroupBRONZE BUTLER | BRONZE BUTLER has used at to register a scheduled task to execute malware during lateral movement. |
| T1053.005 Scheduled Task |
GroupBRONZE BUTLER | BRONZE BUTLER has used schtasks to register a scheduled task to execute malware during lateral movement. |
| T1056.001 Keylogging |
MalwareDaserf | Daserf can log keystrokes. |
| T1059.001 PowerShell |
GroupBRONZE BUTLER | BRONZE BUTLER has used PowerShell for execution. |
| T1059.003 Windows Command Shell |
GroupBRONZE BUTLER | BRONZE BUTLER has used batch scripts and the command-line interface for execution. |
| T1059.003 Windows Command Shell |
MalwareDaserf | Daserf can execute shell commands. |
| T1059.005 Visual Basic |
GroupBRONZE BUTLER | BRONZE BUTLER has used VBS and VBE scripts for execution. |
| T1070.004 File Deletion |
GroupBRONZE BUTLER | The BRONZE BUTLER uploader or malware the uploader uses |
| T1071.001 Web Protocols |
MalwareDaserf | Daserf uses HTTP for C2. |
| T1071.001 Web Protocols |
GroupBRONZE BUTLER | BRONZE BUTLER malware has used HTTP for C2. |
| T1080 Taint Shared Content |
GroupBRONZE BUTLER | BRONZE BUTLER has placed malware on file shares and given it the same name as legitimate documents on the share. |
| T1083 File and Directory Discovery |
GroupBRONZE BUTLER | BRONZE BUTLER has collected a list of files from the victim and uploaded it to its C2 server, and then created a new list of specific files to steal. |
| T1087.002 Domain Account |
GroupBRONZE BUTLER | BRONZE BUTLER has used |
| T1102.001 Dead Drop Resolver |
GroupBRONZE BUTLER | BRONZE BUTLER's MSGET downloader uses a dead drop resolver to access malicious payloads. |
| T1105 Ingress Tool Transfer |
MalwareDaserf | Daserf can download remote files. |
| T1105 Ingress Tool Transfer |
GroupBRONZE BUTLER | BRONZE BUTLER has used various tools to download files, including DGet (a similar tool to wget). |
| T1113 Screen Capture |
GroupBRONZE BUTLER | BRONZE BUTLER has used a tool to capture screenshots. |
| T1113 Screen Capture |
MalwareDaserf | Daserf can take screenshots. |
| T1124 System Time Discovery |
GroupBRONZE BUTLER | BRONZE BUTLER has used |
| T1132.001 Standard Encoding |
MalwareDaserf | Daserf uses custom base64 encoding to obfuscate HTTP traffic. |
| T1132.001 Standard Encoding |
GroupBRONZE BUTLER | Several BRONZE BUTLER tools encode data with base64 when posting it to a C2 server. |
| T1140 Deobfuscate/Decode Files or Information |
GroupBRONZE BUTLER | BRONZE BUTLER downloads encoded payloads and decodes them on the victim. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupBRONZE BUTLER | BRONZE BUTLER has used a batch script that adds a Registry Run key to establish malware persistence. |
| T1548.002 Bypass User Account Control |
GroupBRONZE BUTLER | BRONZE BUTLER has used a Windows 10 specific tool and xxmm to bypass UAC for privilege escalation. |
| T1550.003 Pass the Ticket |
GroupBRONZE BUTLER | BRONZE BUTLER has created forged Kerberos Ticket Granting Ticket (TGT) and Ticket Granting Service (TGS) tickets to maintain administrative access. |
| T1560.001 Archive via Utility |
GroupBRONZE BUTLER | BRONZE BUTLER has compressed data into password-protected RAR archives prior to exfiltration. |
| T1573.001 Symmetric Cryptography |
GroupBRONZE BUTLER | BRONZE BUTLER has used RC4 encryption (for Datper malware) and AES (for xxmm malware) to obfuscate HTTP traffic. BRONZE BUTLER has also used a tool called RarStar that encodes data with a custom XOR algorithm when posting it to a C2 server. |
| T1573.001 Symmetric Cryptography |
MalwareDaserf | Daserf uses RC4 encryption to obfuscate HTTP traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.