Socksbot

Socksbot is a backdoor that abuses Socket Secure (SOCKS) proxies. [1]

ID: S0273
Type: MALWARE
Platforms: Windows
Version: 1.1
Created: 17 October 2018
Last Modified: 30 March 2020

Techniques Used

Domain ID Name Use
Enterprise T1090 代理

Socksbot can start SOCKS proxy threads.[1]

Enterprise T1059 .001 命令与脚本解释器: PowerShell

Socksbot can write and execute PowerShell scripts.[1]

Enterprise T1113 屏幕捕获

Socksbot can take screenshots.[1]

Enterprise T1057 进程发现

Socksbot can list all running processes.[1]

Enterprise T1055 .001 进程注入: Dynamic-link Library Injection

Socksbot creates a suspended svchost process and injects its DLL into it.[1]

References