Malware.View on attack.mitre.org
VBShower is a backdoor that has been used by Inception since at least 2019. VBShower has been used as a downloader for second stage payloads, including PowerShower.
| Technique | Procedure example |
|---|---|
| T1059.005 Visual Basic |
VBShower has the ability to execute VBScript files. |
| T1070.004 File Deletion |
VBShower has attempted to complicate forensic analysis by deleting all the files contained in |
| T1071.001 Web Protocols |
VBShower has attempted to obtain a VBS script from command and control (C2) nodes over HTTP. |
| T1105 Ingress Tool Transfer |
VBShower has the ability to download VBS files to the target computer. |
| T1547.001 Registry Run Keys / Startup Folder |
VBShower used |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.