ATT&CKReferencesCyberreason Anchor December 2019

Cyberreason Anchor December 2019

Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples37

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareTrickBot

TrickBot can use secondary C2 servers for communication after establishing connectivity and relaying victim information to primary C2 servers.

T1008
Fallback Channels
MalwareAnchor

Anchor can use secondary C2 servers for communication after establishing connectivity and relaying victim information to primary C2 servers.

T1016
System Network Configuration Discovery
MalwareCobalt Strike

Cobalt Strike can determine the NetBios name and the IP addresses of targets machines including domain controllers.

T1016
System Network Configuration Discovery
MalwareTrickBot

TrickBot obtains the IP address, location, and other relevant network information from the victim’s machine.

T1018
Remote System Discovery
MalwareTrickBot

TrickBot can enumerate computers and network devices.

T1027
Obfuscated Files or Information
MalwareAnchor

Anchor has obfuscated code with stack strings and string encryption.

T1027.002
Software Packing
MalwareAnchor

Anchor has come with a packed payload.

T1033
System Owner/User Discovery
MalwareTrickBot

TrickBot can identify the user and groups the user belongs to on a compromised host.

T1036
Masquerading
MalwareTrickBot

The TrickBot downloader has used an icon to appear as a Microsoft Word document.

T1041
Exfiltration Over C2 Channel
MalwareTrickBot

TrickBot can send information about the compromised host and upload data to a hardcoded C2 server.

T1053.005
Scheduled Task
MalwareAnchor

Anchor can create a scheduled task for persistence.

T1055.012
Process Hollowing
MalwareTrickBot

TrickBot injects into the svchost.exe process.

T1059.001
PowerShell
MalwareCobalt Strike

Cobalt Strike can execute a payload on a remote host with PowerShell. This technique does not write any data to disk. Cobalt Strike can also use PowerSploit and other scripting frameworks to perform execution.

T1059.003
Windows Command Shell
MalwareAnchor

Anchor has used cmd.exe to run its self deletion routine.

T1069
Permission Groups Discovery
MalwareTrickBot

TrickBot can identify the groups the user on a compromised host belongs to.

T1070.004
File Deletion
MalwareAnchor

Anchor can self delete its dropper after the malware is successfully deployed.

T1071.001
Web Protocols
MalwareAnchor

Anchor has used HTTP and HTTPS in C2 communications.

T1071.001
Web Protocols
MalwareTrickBot

TrickBot uses HTTPS to communicate with its C2 servers, to get malware updates, modules that perform most of the malware logic and various configuration files.

T1071.004
DNS
MalwareAnchor

Variants of Anchor can use DNS tunneling to communicate with C2.

T1082
System Information Discovery
MalwareTrickBot

TrickBot gathers the OS version, machine name, CPU type, amount of RAM available, and UEFI/BIOS firmware information from the victim’s machine.

T1087.002
Domain Account
MalwareCobalt Strike

Cobalt Strike can determine if the user on an infected machine is in the admin or domain admin group.

T1095
Non-Application Layer Protocol
MalwareAnchor

Anchor has used ICMP in C2 communications.

T1105
Ingress Tool Transfer
MalwareAnchor

Anchor can download additional payloads.

T1132.001
Standard Encoding
MalwareTrickBot

TrickBot can Base64-encode C2 commands.

T1140
Deobfuscate/Decode Files or Information
MalwareTrickBot

TrickBot decodes the configuration data and modules.

T1204.002
Malicious File
MalwareTrickBot

TrickBot has attempted to get users to launch malicious documents to deliver its payload.

T1480
Execution Guardrails
MalwareAnchor

Anchor can terminate itself if specific execution flags are not present.

T1482
Domain Trust Discovery
MalwareTrickBot

TrickBot can gather information about domain trusts by utilizing Nltest.

T1543.003
Windows Service
MalwareAnchor

Anchor can establish persistence by creating a service.

T1552.001
Credentials In Files
MalwareTrickBot

TrickBot can obtain passwords stored in files from several applications such as Outlook, Filezilla, OpenSSH, OpenVPN and WinSCP. Additionally, it searches for the ".vnc.lnk" affix to steal VNC credentials.

T1553.002
Code Signing
MalwareAnchor

Anchor has been signed with valid certificates to evade detection by security tools.

T1553.002
Code Signing
MalwareTrickBot

TrickBot has come with a signed downloader component.

T1555.003
Credentials from Web Browsers
MalwareTrickBot

TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge, sometimes using esentutl.

T1555.005
Password Managers
MalwareTrickBot

TrickBot can steal passwords from the KeePass open source password manager.

T1564.004
NTFS File Attributes
MalwareAnchor

Anchor has used NTFS to hide files.

T1566.002
Spearphishing Link
MalwareTrickBot

TrickBot has been delivered via malicious links in phishing e-mails.

T1569.002
Service Execution
MalwareAnchor

Anchor can create and execute services to load its payload.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.