Frydrych, M. (2020, April 14). TA505 Continues to Infect Networks With SDBbot RAT. Retrieved May 29, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
GroupTA505 | TA505 has used UPX to obscure malicious code. |
| T1027.002 Software Packing |
MalwareSDBbot | SDBbot has used a packed installer file. |
| T1055.001 Dynamic-link Library Injection |
GroupTA505 | TA505 has been seen injecting a DLL into winword.exe. |
| T1059.005 Visual Basic |
GroupTA505 | TA505 has used VBS for code execution. |
| T1069 Permission Groups Discovery |
GroupTA505 | TA505 has used TinyMet to enumerate members of privileged groups. TA505 has also run |
| T1071.001 Web Protocols |
GroupTA505 | TA505 has used HTTP to communicate with C2 nodes. |
| T1078.002 Domain Accounts |
GroupTA505 | TA505 has used stolen domain admin accounts to compromise additional hosts. |
| T1125 Video Capture |
MalwareSDBbot | SDBbot has the ability to record video on a compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSDBbot | SDBbot has the ability to decrypt and decompress its payload to enable code execution. |
| T1204.002 Malicious File |
GroupTA505 | TA505 has used lures to get users to enable content in malicious attachments and execute malicious files contained in archives. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSDBbot | SDBbot has the ability to add a value to the Registry Run key to establish persistence if it detects it is running with regular user privilege. |
| T1566.001 Spearphishing Attachment |
GroupTA505 | TA505 has used spearphishing emails with malicious attachments to initially compromise victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.