Savelesky, K., et al. (2019, July 23). ABADBABE 8BADFOOD: Discovering BADHATCH and a Detailed Look at FIN8's Tooling. Retrieved September 8, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.009 Embedded Payloads |
MalwareBADHATCH | BADHATCH has an embedded second stage DLL payload within the first stage of the malware. |
| T1041 Exfiltration Over C2 Channel |
MalwareBADHATCH | BADHATCH can exfiltrate data over the C2 channel. |
| T1047 Windows Management Instrumentation |
MalwareBADHATCH | BADHATCH can utilize WMI to collect system information, create new processes, and run malicious PowerShell scripts on a compromised machine. |
| T1055 Process Injection |
MalwareBADHATCH | BADHATCH can inject itself into an existing explorer.exe process by using `RtlCreateUserThread`. |
| T1055.001 Dynamic-link Library Injection |
MalwareBADHATCH | BADHATCH has the ability to execute a malicious DLL by injecting into `explorer.exe` on a compromised machine. |
| T1055.004 Asynchronous Procedure Call |
MalwareBADHATCH | BADHATCH can inject itself into a new `svchost.exe -k netsvcs` process using the asynchronous procedure call (APC) queue. |
| T1059.001 PowerShell |
MalwareBADHATCH | BADHATCH can utilize `powershell.exe` to execute commands on a compromised host. |
| T1059.003 Windows Command Shell |
MalwareBADHATCH | BADHATCH can use `cmd.exe` to execute commands on a compromised host. |
| T1070.004 File Deletion |
MalwareBADHATCH | BADHATCH has the ability to delete PowerShell scripts from a compromised machine. |
| T1071.001 Web Protocols |
MalwareBADHATCH | BADHATCH can use HTTP and HTTPS over port 443 to communicate with actor-controlled C2 servers. |
| T1082 System Information Discovery |
MalwareBADHATCH | BADHATCH can obtain current system information from a compromised machine such as the `SHELL PID`, `PSVERSION`, `HOSTNAME`, `LOGONSERVER`, `LASTBOOTUP`, OS type/version, bitness, and hostname. |
| T1105 Ingress Tool Transfer |
MalwareBADHATCH | BADHATCH has the ability to load a second stage malicious DLL file onto a compromised machine. |
| T1106 Native API |
MalwareBADHATCH | BADHATCH can utilize Native API functions such as, `ToolHelp32` and `Rt1AdjustPrivilege` to enable `SeDebugPrivilege` on a compromised machine. |
| T1573.002 Asymmetric Cryptography |
MalwareBADHATCH | BADHATCH can beacon to a hardcoded C2 IP address using TLS encryption every 5 minutes. |
| T1620 Reflective Code Loading |
MalwareBADHATCH | BADHATCH can copy a large byte array of 64-bit shellcode into process memory and execute it with a call to `CreateThread`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.