ATT&CKReferencesBitDefender BADHATCH Mar 2021

BitDefender BADHATCH Mar 2021

Vrabie, V., et al. (2021, March 10). FIN8 Returns with Improved BADHATCH Toolkit. Retrieved September 8, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples28

TechniqueUsed byProcedure example
T1018
Remote System Discovery
MalwareBADHATCH

BADHATCH can use a PowerShell object such as, `System.Net.NetworkInformation.Ping` to ping a computer.

T1027.010
Command Obfuscation
MalwareBADHATCH

BADHATCH malicious PowerShell commands can be encoded with base64.

T1027.015
Compression
MalwareBADHATCH

BADHATCH can be compressed with the ApLib algorithm.

T1033
System Owner/User Discovery
MalwareBADHATCH

BADHATCH can obtain logged user information from a compromised machine and can execute the command `whoami.exe`.

T1041
Exfiltration Over C2 Channel
MalwareBADHATCH

BADHATCH can exfiltrate data over the C2 channel.

T1046
Network Service Discovery
MalwareBADHATCH

BADHATCH can check for open ports on a computer by establishing a TCP connection.

T1047
Windows Management Instrumentation
MalwareBADHATCH

BADHATCH can utilize WMI to collect system information, create new processes, and run malicious PowerShell scripts on a compromised machine.

T1049
System Network Connections Discovery
MalwareBADHATCH

BADHATCH can execute `netstat.exe -f` on a compromised machine.

T1053.005
Scheduled Task
MalwareBADHATCH

BADHATCH can use `schtasks.exe` to gain persistence.

T1055
Process Injection
MalwareBADHATCH

BADHATCH can inject itself into an existing explorer.exe process by using `RtlCreateUserThread`.

T1055.004
Asynchronous Procedure Call
MalwareBADHATCH

BADHATCH can inject itself into a new `svchost.exe -k netsvcs` process using the asynchronous procedure call (APC) queue.

T1057
Process Discovery
MalwareBADHATCH

BADHATCH can retrieve a list of running processes from a compromised machine.

T1059.001
PowerShell
MalwareBADHATCH

BADHATCH can utilize `powershell.exe` to execute commands on a compromised host.

T1059.003
Windows Command Shell
MalwareBADHATCH

BADHATCH can use `cmd.exe` to execute commands on a compromised host.

T1069.002
Domain Groups
MalwareBADHATCH

BADHATCH can use `net.exe group "domain admins" /domain` to identify Domain Administrators.

T1071.001
Web Protocols
MalwareBADHATCH

BADHATCH can use HTTP and HTTPS over port 443 to communicate with actor-controlled C2 servers.

T1071.002
File Transfer Protocols
MalwareBADHATCH

BADHATCH can emulate an FTP server to connect to actor-controlled C2 servers.

T1082
System Information Discovery
MalwareBADHATCH

BADHATCH can obtain current system information from a compromised machine such as the `SHELL PID`, `PSVERSION`, `HOSTNAME`, `LOGONSERVER`, `LASTBOOTUP`, OS type/version, bitness, and hostname.

T1090
Proxy
MalwareBADHATCH

BADHATCH can use SOCKS4 and SOCKS5 proxies to connect to actor-controlled C2 servers. BADHATCH can also emulate a reverse proxy on a compromised machine to connect with actor-controlled C2 servers.

T1102
Web Service
MalwareBADHATCH

BADHATCH can be utilized to abuse `sslip.io`, a free IP to domain mapping service, as part of actor-controlled C2 channels.

T1113
Screen Capture
MalwareBADHATCH

BADHATCH can take screenshots and send them to an actor-controlled C2 server.

T1124
System Time Discovery
MalwareBADHATCH

BADHATCH can obtain the `DATETIME` and `UPTIME` from a compromised machine.

T1134.001
Token Impersonation/Theft
MalwareBADHATCH

BADHATCH can impersonate a `lsass.exe` or `vmtoolsd.exe` token.

T1135
Network Share Discovery
MalwareBADHATCH

BADHATCH can check a user's access to the C$ share on a compromised machine.

T1482
Domain Trust Discovery
MalwareBADHATCH

BADHATCH can use `nltest.exe /domain_trusts` to discover domain trust relationships on a compromised machine.

T1546.003
Windows Management Instrumentation Event Subscription
MalwareBADHATCH

BADHATCH can use WMI event subscriptions for persistence.

T1548.002
Bypass User Account Control
MalwareBADHATCH

BADHATCH can utilize the CMSTPLUA COM interface and the SilentCleanup task to bypass UAC.

T1550.002
Pass the Hash
MalwareBADHATCH

BADHATCH can perform pass the hash on compromised machines with x64 versions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.