ATT&CKReferencesUnit 42 BadPatch Oct 2017

Unit 42 BadPatch Oct 2017

Bar, T., Conant, S. (2017, October 20). BadPatch. Retrieved November 13, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareBadPatch

BadPatch collects files from the local system that have the following extensions, then prepares them for exfiltration: .xls, .xlsx, .pdf, .mdb, .rar, .zip, .doc, .docx.

T1056.001
Keylogging
MalwareBadPatch

BadPatch has a keylogging capability.

T1071.001
Web Protocols
MalwareBadPatch

BadPatch uses HTTP for C2.

T1071.003
Mail Protocols
MalwareBadPatch

BadPatch uses SMTP for C2.

T1074.001
Local Data Staging
MalwareBadPatch

BadPatch stores collected data in log files before exfiltration.

T1082
System Information Discovery
MalwareBadPatch

BadPatch collects the OS system, OS version, MAC address, and the computer name from the victim’s machine.

T1083
File and Directory Discovery
MalwareBadPatch

BadPatch searches for files with specific file extensions.

T1105
Ingress Tool Transfer
MalwareBadPatch

BadPatch can download and execute or update malware.

T1113
Screen Capture
MalwareBadPatch

BadPatch captures screenshots in .jpg format and then exfiltrates them.

T1497.001
System Checks
MalwareBadPatch

BadPatch attempts to detect if it is being run in a Virtual Machine (VM) using a WMI query for disk drive name, BIOS, and motherboard information.

T1518.001
Security Software Discovery
MalwareBadPatch

BadPatch uses WMI to enumerate installed security products in the victim’s environment.

T1547.001
Registry Run Keys / Startup Folder
MalwareBadPatch

BadPatch establishes a foothold by adding a link to the malware executable in the startup folder.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.