ATT&CKReferencesTrend Micro DRBControl February 2020

Trend Micro DRBControl February 2020

Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples61

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareClambling

Clambling can collect information from a compromised host.

T1005
Data from Local System
MalwareRCSession

RCSession can collect data from a compromised host.

T1012
Query Registry
MalwareClambling

Clambling has the ability to enumerate Registry keys, including KEY_CURRENT_USER\Software\Bitcoin\Bitcoin-Qt\strDataDir to search for a bitcoin wallet.

T1016
System Network Configuration Discovery
MalwareClambling

Clambling can enumerate the IP address of a compromised machine.

T1027
Obfuscated Files or Information
MalwarePlugX

PlugX can use API hashing and modify the names of strings to evade detection.

T1027
Obfuscated Files or Information
MalwareClambling

The Clambling executable has been obfuscated when dropped on a compromised host.

T1027.002
Software Packing
GroupThreat Group-3390

Threat Group-3390 has packed malware and tools, including using VMProtect.

T1027.011
Fileless Storage
MalwareRCSession

RCSession can store its obfuscated configuration file in the Registry under `HKLM\SOFTWARE\Plus` or `HKCU\SOFTWARE\Plus`.

T1027.013
Encrypted/Encoded File
MalwareHyperBro

HyperBro can be delivered encrypted to a compromised host.

T1027.015
Compression
MalwareRCSession

RCSession can compress and obfuscate its strings to evade detection on a compromised host.

T1033
System Owner/User Discovery
GroupThreat Group-3390

Threat Group-3390 has used `whoami` to collect system user information.

T1033
System Owner/User Discovery
MalwareClambling

Clambling can identify the username on a compromised host.

T1036
Masquerading
MalwareRCSession

RCSession has used a file named English.rtf to appear benign on victim hosts.

T1055
Process Injection
MalwareClambling

Clambling can inject into the `svchost.exe` process for execution.

T1055.012
Process Hollowing
MalwareRCSession

RCSession can launch itself from a hollowed svchost.exe process.

T1055.012
Process Hollowing
MalwareClambling

Clambling can execute binaries through process hollowing.

T1056.001
Keylogging
MalwareRCSession

RCSession has the ability to capture keystrokes on a compromised host.

T1056.001
Keylogging
MalwareClambling

Clambling can capture keystrokes on a compromised host.

T1057
Process Discovery
MalwareClambling

Clambling can enumerate processes on a targeted system.

T1059.001
PowerShell
MalwareClambling

The Clambling dropper can use PowerShell to download the malware.

T1059.001
PowerShell
GroupThreat Group-3390

Threat Group-3390 has used PowerShell for execution.

T1059.003
Windows Command Shell
MalwareRCSession

RCSession can use `cmd.exe` for execution on compromised hosts.

T1059.003
Windows Command Shell
MalwareClambling

Clambling can use cmd.exe for command execution.

T1070.004
File Deletion
GroupThreat Group-3390

Threat Group-3390 has deleted existing logs and exfiltrated file archives from a victim.

T1071
Application Layer Protocol
MalwareClambling

Clambling has the ability to use Telnet for communication.

T1071.001
Web Protocols
MalwareClambling

Clambling has the ability to communicate over HTTP.

T1071.001
Web Protocols
MalwareRCSession

RCSession can use HTTP in C2 communications.

T1082
System Information Discovery
MalwareClambling

Clambling can discover the hostname, computer name, and Windows version of a targeted machine.

T1083
File and Directory Discovery
MalwareClambling

Clambling can browse directories on a compromised host.

T1095
Non-Application Layer Protocol
MalwareRCSession

RCSession has the ability to use TCP and UDP in C2 communications.

T1095
Non-Application Layer Protocol
MalwareClambling

Clambling has the ability to use TCP and UDP for communication.

T1102.002
Bidirectional Communication
MalwareClambling

Clambling can use Dropbox to download malicious payloads, send commands, and receive information.

T1105
Ingress Tool Transfer
GroupThreat Group-3390

Threat Group-3390 has downloaded additional malware and tools, including through the use of `certutil`, onto a compromised host .

T1112
Modify Registry
MalwareClambling

Clambling can set and delete Registry keys.

T1112
Modify Registry
MalwareRCSession

RCSession can write its configuration file to the Registry.

T1113
Screen Capture
MalwareClambling

Clambling has the ability to capture screenshots.

T1115
Clipboard Data
MalwareClambling

Clambling has the ability to capture and store clipboard data.

T1124
System Time Discovery
MalwareClambling

Clambling can determine the current time.

T1125
Video Capture
MalwareClambling

Clambling can record screen content in AVI format.

T1135
Network Share Discovery
MalwareClambling

Clambling has the ability to enumerate network shares.

T1140
Deobfuscate/Decode Files or Information
MalwareClambling

Clambling can deobfuscate its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwarePlugX

PlugX decompresses and decrypts itself using the Microsoft API call RtlDecompressBuffer. PlugX has also decrypted its payloads in memory.

T1140
Deobfuscate/Decode Files or Information
MalwareHyperBro

HyperBro can unpack and decrypt its payload prior to execution.

T1204.002
Malicious File
GroupThreat Group-3390

Threat Group-3390 has lured victims into opening malicious files containing malware.

T1204.002
Malicious File
MalwareClambling

Clambling has gained execution through luring victims into opening malicious files.

T1497.003
Time Based Checks
MalwareClambling

Clambling can wait 30 minutes before initiating contact with C2.

T1547.001
Registry Run Keys / Startup Folder
MalwareClambling

Clambling can establish persistence by adding a Registry run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareRCSession

RCSession has the ability to modify a Registry Run key to establish persistence.

T1548.002
Bypass User Account Control
MalwareClambling

Clambling has the ability to bypass UAC using a `passuac.dll` file.

T1548.002
Bypass User Account Control
MalwareRCSession

RCSession can bypass UAC to escalate privileges.

Showing the first 50.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.