Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Software
  3. BADCALL

BADCALL

BADCALL is a Trojan malware variant used by the groupLazarus Group.[1]

ID: S0245
Type: MALWARE
Platforms: Windows
Version: 1.1
Created: 17 October 2018
Last Modified: 25 April 2025
Enterprise Layer
downloadview

Techniques Used

DomainIDNameUse
EnterpriseT1001.003Data Obfuscation:Protocol or Service Impersonation

BADCALL uses a FakeTLS method during C2.[2]

EnterpriseT1573.001Encrypted Channel:Symmetric Cryptography

BADCALL encrypts C2 traffic using an XOR/ADD cipher.[1]

EnterpriseT1562.004Impair Defenses:Disable or Modify System Firewall

BADCALL disables the Windows firewall before binding to a port.[1]

EnterpriseT1112Modify Registry

BADCALL modifies the firewall Registry keySYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfileGloballyOpenPorts\List.[1]

EnterpriseT1571Non-Standard Port

BADCALL communicates on ports 443 and 8000 with a FakeTLS method.[1]

EnterpriseT1090Proxy

BADCALL functions as a proxy server between the victim and C2 server.[1]

EnterpriseT1082System Information Discovery

BADCALL collects the computer name and host name on the compromised system.[1]

EnterpriseT1016System Network Configuration Discovery

BADCALL collects the network adapter information.[1]

Groups That Use This Software

IDNameReferences
G0032Lazarus Group

[1]

References

×

[8]ページ先頭

©2009-2026 Movatter.jp