ATT&CKReferencesSecurelist BlackEnergy Nov 2014

Securelist BlackEnergy Nov 2014

Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareBlackEnergy

BlackEnergy has the capability to communicate over a backup channel via plus.google.com.

T1016
System Network Configuration Discovery
MalwareBlackEnergy

BlackEnergy has gathered information about network IP configurations using ipconfig.exe and about routing tables using route.exe.

T1021.002
SMB/Windows Admin Shares
MalwareBlackEnergy

BlackEnergy has run a plug-in on a victim to spread through the local network by using PsExec and accessing admin shares.

T1046
Network Service Discovery
MalwareBlackEnergy

BlackEnergy has conducted port scans on a host.

T1049
System Network Connections Discovery
MalwareBlackEnergy

BlackEnergy has gathered information about local network connections using netstat.

T1056.001
Keylogging
MalwareBlackEnergy

BlackEnergy has run a keylogger plug-in on a victim.

T1057
Process Discovery
MalwareBlackEnergy

BlackEnergy has gathered a process list by using Tasklist.exe.

T1082
System Information Discovery
MalwareBlackEnergy

BlackEnergy has used Systeminfo to gather the OS version, as well as information on the system configuration, BIOS, the motherboard, and the processor.

T1083
File and Directory Discovery
MalwareBlackEnergy

BlackEnergy gathers a list of installed apps from the uninstall program Registry. It also gathers registered mail, browser, and instant messaging clients from the Registry. BlackEnergy has searched for given file types.

T1113
Screen Capture
MalwareBlackEnergy

BlackEnergy is capable of taking screenshots.

T1120
Peripheral Device Discovery
MalwareBlackEnergy

BlackEnergy can gather very specific information about attached USB devices, to include device instance ID and drive geometry.

T1552.001
Credentials In Files
MalwareBlackEnergy

BlackEnergy has used a plug-in to gather credentials stored in files on the host by various software programs, including The Bat! email client, Outlook, and Windows Credential Store.

T1555.003
Credentials from Web Browsers
MalwareBlackEnergy

BlackEnergy has used a plug-in to gather credentials from web browsers including FireFox, Google Chrome, and Internet Explorer.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.