ATT&CKReferencesThreatExpert Agent.btz

ThreatExpert Agent.btz

Shevchenko, S.. (2008, November 30). Agent.btz - A Threat That Hit Pentagon. Retrieved April 8, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareAgent.btz

Agent.btz collects the network adapter’s IP and MAC address as well as IP addresses of the network adapter’s default gateway, primary/secondary WINS, DHCP, and DNS servers, and saves them into a log file.

T1033
System Owner/User Discovery
MalwareAgent.btz

Agent.btz obtains the victim username and saves it to a file.

T1091
Replication Through Removable Media
MalwareAgent.btz

Agent.btz drops itself onto removable media devices and creates an autorun.inf file with an instruction to run that file. When the device is inserted into another system, it opens autorun.inf and loads the malware.

T1105
Ingress Tool Transfer
MalwareAgent.btz

Agent.btz attempts to download an encrypted binary from a specified domain.

T1560.003
Archive via Custom Method
MalwareAgent.btz

Agent.btz saves system information into an XML file that is then XOR-encoded.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.