ATT&CKReferencesCrowdstrike Qakbot October 2020

Crowdstrike Qakbot October 2020

CS. (2020, October 7). Duck Hunting with Falcon Complete: A Fowl Banking Trojan Evolves, Part 2. Retrieved September 27, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareQakBot

QakBot can use net config workstation, arp -a, `nslookup`, and ipconfig /all to gather network configuration information.

T1018
Remote System Discovery
MalwareQakBot

QakBot can identify remote systems through the net view command.

T1027.005
Indicator Removal from Tools
MalwareQakBot

QakBot can make small changes to itself in order to change its checksum and hash value.

T1053.005
Scheduled Task
MalwareQakBot

QakBot has the ability to create scheduled tasks for persistence.

T1059.003
Windows Command Shell
MalwareQakBot

QakBot can use cmd.exe to launch itself and to execute multiple C2 commands.

T1059.005
Visual Basic
MalwareQakBot

QakBot can use VBS to download and execute malicious files.

T1070.004
File Deletion
MalwareQakBot

QakBot can delete folders and files including overwriting its executable with legitimate programs.

T1071.001
Web Protocols
MalwareQakBot

QakBot has the ability to use HTTP and HTTPS in communication with C2 servers.

T1082
System Information Discovery
MalwareQakBot

QakBot can collect system information including the OS version and domain on a compromised host.

T1105
Ingress Tool Transfer
MalwareQakBot

QakBot has the ability to download additional components and malware.

T1110
Brute Force
MalwareQakBot

QakBot can conduct brute force attacks to capture credentials.

T1132.001
Standard Encoding
MalwareQakBot

QakBot can Base64 encode system information sent to C2.

T1204.002
Malicious File
MalwareQakBot

QakBot has gained execution through users opening malicious attachments.

T1210
Exploitation of Remote Services
MalwareQakBot

QakBot can move laterally using worm-like functionality through exploitation of SMB.

T1218.007
Msiexec
MalwareQakBot

QakBot can use MSIExec to spawn multiple cmd.exe processes.

T1218.011
Rundll32
MalwareQakBot

QakBot has used Rundll32.exe to drop malicious DLLs including Brute Ratel C4 and to enable C2 communication.

T1518.001
Security Software Discovery
MalwareQakBot

QakBot can identify the installed antivirus product on a targeted system.

T1547.001
Registry Run Keys / Startup Folder
MalwareQakBot

QakBot can maintain persistence by creating an auto-run Registry key.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.