ATT&CKReferencesBitdefender Trickbot VNC module Whitepaper 2021

Bitdefender Trickbot VNC module Whitepaper 2021

Radu Tudorica. (2021, July 12). A Fresh Look at Trickbot’s Ever-Improving VNC Module. Retrieved September 28, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1021.005
VNC
MalwareTrickBot

TrickBot has used a VNC module to monitor the victim and collect information to pivot to valuable systems on the network

T1041
Exfiltration Over C2 Channel
MalwareTrickBot

TrickBot can send information about the compromised host and upload data to a hardcoded C2 server.

T1059.001
PowerShell
MalwareTrickBot

TrickBot has been known to use PowerShell to download new payloads, open documents, and upload data to command and control servers.

T1090.002
External Proxy
MalwareTrickBot

TrickBot has been known to reach a command and control server via one of nine proxy IP addresses.

T1105
Ingress Tool Transfer
MalwareTrickBot

TrickBot downloads several additional files and saves them to the victim's machine.

T1555.003
Credentials from Web Browsers
MalwareTrickBot

TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge, sometimes using esentutl.

T1564.003
Hidden Window
MalwareWarzoneRAT

WarzoneRAT has the ability of performing remote desktop access via a hVNC window for decreased visibility.

T1571
Non-Standard Port
MalwareTrickBot

Some TrickBot samples have used HTTP over ports 447 and 8082 for C2. Newer versions of TrickBot have been known to use a custom communication protocol which sends the data unencrypted over port 443.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.