Bar, T., Conant, S. (2017, October 20). BadPatch. Retrieved November 13, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareBadPatch | BadPatch collects files from the local system that have the following extensions, then prepares them for exfiltration: .xls, .xlsx, .pdf, .mdb, .rar, .zip, .doc, .docx. |
| T1056.001 Keylogging |
MalwareBadPatch | BadPatch has a keylogging capability. |
| T1071.001 Web Protocols |
MalwareBadPatch | BadPatch uses HTTP for C2. |
| T1071.003 Mail Protocols |
MalwareBadPatch | BadPatch uses SMTP for C2. |
| T1074.001 Local Data Staging |
MalwareBadPatch | BadPatch stores collected data in log files before exfiltration. |
| T1082 System Information Discovery |
MalwareBadPatch | BadPatch collects the OS system, OS version, MAC address, and the computer name from the victim’s machine. |
| T1083 File and Directory Discovery |
MalwareBadPatch | BadPatch searches for files with specific file extensions. |
| T1105 Ingress Tool Transfer |
MalwareBadPatch | BadPatch can download and execute or update malware. |
| T1113 Screen Capture |
MalwareBadPatch | BadPatch captures screenshots in .jpg format and then exfiltrates them. |
| T1497.001 System Checks |
MalwareBadPatch | BadPatch attempts to detect if it is being run in a Virtual Machine (VM) using a WMI query for disk drive name, BIOS, and motherboard information. |
| T1518.001 Security Software Discovery |
MalwareBadPatch | BadPatch uses WMI to enumerate installed security products in the victim’s environment. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBadPatch | BadPatch establishes a foothold by adding a link to the malware executable in the startup folder. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.