ATT&CKReferencesTalos Bisonal Mar 2020

Talos Bisonal Mar 2020

Mercer, W., et al. (2020, March 5). Bisonal: 10 years of play. Retrieved January 26, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples33

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareBisonal

Bisonal has collected information from a compromised host.

T1012
Query Registry
MalwareBisonal

Bisonal has used the RegQueryValueExA function to retrieve proxy information in the Registry.

T1016
System Network Configuration Discovery
MalwareBisonal

Bisonal can execute ipconfig on the victim’s machine.

T1027.001
Binary Padding
MalwareBisonal

Bisonal has appended random binary data to the end of itself to generate a large binary.

T1027.002
Software Packing
MalwareBisonal

Bisonal has used the MPRESS packer and similar tools for obfuscation.

T1027.013
Encrypted/Encoded File
MalwareBisonal

Bisonal's DLL file and non-malicious decoy file are encrypted with RC4 and some function name strings are obfuscated.

T1036
Masquerading
MalwareBisonal

Bisonal dropped a decoy payload with a .jpg extension that contained a malicious Visual Basic script.

T1036.005
Match Legitimate Resource Name or Location
MalwareBisonal

Bisonal has renamed malicious code to `msacm32.dll` to hide within a legitimate library; earlier versions were disguised as `winhelp`.

T1041
Exfiltration Over C2 Channel
MalwareBisonal

Bisonal has added the exfiltrated data to the URL over the C2 channel.

T1057
Process Discovery
MalwareBisonal

Bisonal can obtain a list of running processes on the victim’s machine.

T1059.003
Windows Command Shell
MalwareBisonal

Bisonal has launched cmd.exe and used the ShellExecuteW() API function to execute commands on the system.

T1059.005
Visual Basic
MalwareBisonal

Bisonal's dropper creates VBS scripts on the victim’s machine.

T1070.004
File Deletion
MalwareBisonal

Bisonal will delete its dropper and VBS scripts from the victim’s machine.

T1082
System Information Discovery
MalwareBisonal

Bisonal has used commands and API calls to gather system information.

T1083
File and Directory Discovery
MalwareBisonal

Bisonal can retrieve a file listing from the system.

T1090
Proxy
MalwareBisonal

Bisonal has supported use of a proxy server.

T1095
Non-Application Layer Protocol
MalwareBisonal

Bisonal has used raw sockets for network communication.

T1105
Ingress Tool Transfer
MalwareBisonal

Bisonal has the capability to download files to execute on the victim’s machine.

T1106
Native API
MalwareBisonal

Bisonal has used the Windows API to communicate with the Service Control Manager to execute a thread.

T1112
Modify Registry
MalwareBisonal

Bisonal has deleted Registry keys to clean up its prior activity.

T1132.001
Standard Encoding
MalwareBisonal

Bisonal has encoded binary data with Base64 and ASCII.

T1137.006
Add-ins
MalwareBisonal

Bisonal has been loaded through a `.wll` extension added to the ` %APPDATA%\microsoft\word\startup\` repository.

T1140
Deobfuscate/Decode Files or Information
MalwareBisonal

Bisonal has decoded strings in the malware using XOR and RC4.

T1203
Exploitation for Client Execution
GroupTonto Team

Tonto Team has exploited Microsoft vulnerabilities, including CVE-2018-0798, CVE-2018-8174, CVE-2018-0802, CVE-2017-11882, CVE-2019-9489 CVE-2020-8468, and CVE-2018-0798 to enable execution of their delivered malicious payloads.

T1204.002
Malicious File
MalwareBisonal

Bisonal has relied on users to execute malicious file attachments delivered via spearphishing emails.

T1204.002
Malicious File
GroupTonto Team

Tonto Team has relied on user interaction to open their malicious RTF documents.

T1497
Virtualization/Sandbox Evasion
MalwareBisonal

Bisonal can check to determine if the compromised system is running on VMware.

T1497.003
Time Based Checks
MalwareBisonal

Bisonal has checked if the malware is running in a virtual environment with the anti-debug function GetTickCount() to compare the timing.

T1543.003
Windows Service
MalwareBisonal

Bisonal has been modified to be used as a Windows service.

T1547.001
Registry Run Keys / Startup Folder
MalwareBisonal

Bisonal has added itself to the Registry key HKEY_CURRENT_USER\Software\Microsoft\CurrentVersion\Run\ for persistence.

T1566.001
Spearphishing Attachment
MalwareBisonal

Bisonal has been delivered as malicious email attachments.

T1568
Dynamic Resolution
MalwareBisonal

Bisonal has used a dynamic DNS service for C2.

T1573.001
Symmetric Cryptography
MalwareBisonal

Bisonal variants reported on in 2014 and 2015 used a simple XOR cipher for C2. Some Bisonal samples encrypt C2 communications with RC4.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.