Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
MalwareTrickBot | TrickBot can use secondary C2 servers for communication after establishing connectivity and relaying victim information to primary C2 servers. |
| T1008 Fallback Channels |
MalwareAnchor | Anchor can use secondary C2 servers for communication after establishing connectivity and relaying victim information to primary C2 servers. |
| T1016 System Network Configuration Discovery |
MalwareCobalt Strike | Cobalt Strike can determine the NetBios name and the IP addresses of targets machines including domain controllers. |
| T1016 System Network Configuration Discovery |
MalwareTrickBot | TrickBot obtains the IP address, location, and other relevant network information from the victim’s machine. |
| T1018 Remote System Discovery |
MalwareTrickBot | TrickBot can enumerate computers and network devices. |
| T1027 Obfuscated Files or Information |
MalwareAnchor | Anchor has obfuscated code with stack strings and string encryption. |
| T1027.002 Software Packing |
MalwareAnchor | Anchor has come with a packed payload. |
| T1033 System Owner/User Discovery |
MalwareTrickBot | TrickBot can identify the user and groups the user belongs to on a compromised host. |
| T1036 Masquerading |
MalwareTrickBot | The TrickBot downloader has used an icon to appear as a Microsoft Word document. |
| T1041 Exfiltration Over C2 Channel |
MalwareTrickBot | TrickBot can send information about the compromised host and upload data to a hardcoded C2 server. |
| T1053.005 Scheduled Task |
MalwareAnchor | Anchor can create a scheduled task for persistence. |
| T1055.012 Process Hollowing |
MalwareTrickBot | TrickBot injects into the svchost.exe process. |
| T1059.001 PowerShell |
MalwareCobalt Strike | Cobalt Strike can execute a payload on a remote host with PowerShell. This technique does not write any data to disk. Cobalt Strike can also use PowerSploit and other scripting frameworks to perform execution. |
| T1059.003 Windows Command Shell |
MalwareAnchor | Anchor has used cmd.exe to run its self deletion routine. |
| T1069 Permission Groups Discovery |
MalwareTrickBot | TrickBot can identify the groups the user on a compromised host belongs to. |
| T1070.004 File Deletion |
MalwareAnchor | Anchor can self delete its dropper after the malware is successfully deployed. |
| T1071.001 Web Protocols |
MalwareAnchor | Anchor has used HTTP and HTTPS in C2 communications. |
| T1071.001 Web Protocols |
MalwareTrickBot | TrickBot uses HTTPS to communicate with its C2 servers, to get malware updates, modules that perform most of the malware logic and various configuration files. |
| T1071.004 DNS |
MalwareAnchor | Variants of Anchor can use DNS tunneling to communicate with C2. |
| T1082 System Information Discovery |
MalwareTrickBot | TrickBot gathers the OS version, machine name, CPU type, amount of RAM available, and UEFI/BIOS firmware information from the victim’s machine. |
| T1087.002 Domain Account |
MalwareCobalt Strike | Cobalt Strike can determine if the user on an infected machine is in the admin or domain admin group. |
| T1095 Non-Application Layer Protocol |
MalwareAnchor | Anchor has used ICMP in C2 communications. |
| T1105 Ingress Tool Transfer |
MalwareAnchor | Anchor can download additional payloads. |
| T1132.001 Standard Encoding |
MalwareTrickBot | TrickBot can Base64-encode C2 commands. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTrickBot | TrickBot decodes the configuration data and modules. |
| T1204.002 Malicious File |
MalwareTrickBot | TrickBot has attempted to get users to launch malicious documents to deliver its payload. |
| T1480 Execution Guardrails |
MalwareAnchor | Anchor can terminate itself if specific execution flags are not present. |
| T1482 Domain Trust Discovery |
MalwareTrickBot | TrickBot can gather information about domain trusts by utilizing Nltest. |
| T1543.003 Windows Service |
MalwareAnchor | Anchor can establish persistence by creating a service. |
| T1552.001 Credentials In Files |
MalwareTrickBot | TrickBot can obtain passwords stored in files from several applications such as Outlook, Filezilla, OpenSSH, OpenVPN and WinSCP. Additionally, it searches for the ".vnc.lnk" affix to steal VNC credentials. |
| T1553.002 Code Signing |
MalwareAnchor | Anchor has been signed with valid certificates to evade detection by security tools. |
| T1553.002 Code Signing |
MalwareTrickBot | TrickBot has come with a signed downloader component. |
| T1555.003 Credentials from Web Browsers |
MalwareTrickBot | TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge, sometimes using esentutl. |
| T1555.005 Password Managers |
MalwareTrickBot | TrickBot can steal passwords from the KeePass open source password manager. |
| T1564.004 NTFS File Attributes |
MalwareAnchor | Anchor has used NTFS to hide files. |
| T1566.002 Spearphishing Link |
MalwareTrickBot | TrickBot has been delivered via malicious links in phishing e-mails. |
| T1569.002 Service Execution |
MalwareAnchor | Anchor can create and execute services to load its payload. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.