VBShower

S0442

Malware.View on attack.mitre.org

About this malware

VBShower is a backdoor that has been used by Inception since at least 2019. VBShower has been used as a downloader for second stage payloads, including PowerShower.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1059.005
Visual Basic

VBShower has the ability to execute VBScript files.

T1070.004
File Deletion

VBShower has attempted to complicate forensic analysis by deleting all the files contained in %APPDATA%\..\Local\Temporary Internet Files\Content.Word and %APPDATA%\..\Local Settings\Temporary Internet Files\Content.Word\.

T1071.001
Web Protocols

VBShower has attempted to obtain a VBS script from command and control (C2) nodes over HTTP.

T1105
Ingress Tool Transfer

VBShower has the ability to download VBS files to the target computer.

T1547.001
Registry Run Keys / Startup Folder

VBShower used HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\[a-f0-9A-F]{8} to maintain persistence.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Kaspersky Cloud Atlas August 2019 Open source
    GReAT. (2019, August 12). Recent Cloud Atlas activity. Retrieved May 8, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.