DanBot

S1014

Malware.View on attack.mitre.org

About this malware

DanBot is a first-stage remote access Trojan written in C# that has been used by HEXANE since at least 2018.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1005
Data from Local System

DanBot can upload files from compromised hosts.

T1021.005
VNC

DanBot can use VNC for remote access to targeted systems.

T1027.013
Encrypted/Encoded File

DanBot can Base64 encode its payload.

T1036.005
Match Legitimate Resource Name or Location

DanBot files have been named `UltraVNC.exe` and `WINVNC.exe` to appear as legitimate VNC tools.

T1053.005
Scheduled Task

DanBot can use a scheduled task for installation.

T1059.003
Windows Command Shell

DanBot has the ability to execute arbitrary commands via `cmd.exe`.

T1059.005
Visual Basic

DanBot can use a VBA macro embedded in an Excel file to drop the payload.

T1070.004
File Deletion

DanBot can delete its configuration file after installation.

T1071.001
Web Protocols

DanBot can use HTTP in C2 communication.

T1071.004
DNS

DanBot can use use IPv4 A records and IPv6 AAAA DNS records in C2 communications.

T1105
Ingress Tool Transfer

DanBot can download additional files to a targeted system.

T1140
Deobfuscate/Decode Files or Information

DanBot can use a VBA macro to decode its payload prior to installation and execution.

T1204.002
Malicious File

DanBot has relied on victims' opening a malicious file for initial execution.

T1566.001
Spearphishing Attachment

DanBot has been distributed within a malicious Excel attachment via spearphishing emails.

Groups that use it1

Campaigns0

None recorded.

References1

  1. SecureWorks August 2019 Open source
    SecureWorks 2019, August 27 LYCEUM Takes Center Stage in Middle East Campaign Retrieved. 2019/11/19

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.