ATT&CKReferenceshexed osx.dok analysis 2019

hexed osx.dok analysis 2019

fluffybunny. (2019, July 9). OSX.Dok Analysis. Retrieved November 17, 2024.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareDok

Dok is packed with an UPX executable packer.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareDok

Dok exfiltrates logs of its execution stored in the /tmp folder over FTP using the curl command.

T1547.015
Login Items
MalwareDok

Dok uses AppleScript to install a login Item by sending Apple events to the System Events process.

T1548.003
Sudo and Sudo Caching
MalwareDok

Dok adds admin ALL=(ALL) NOPASSWD: ALL to the /etc/sudoers file.

T1553.004
Install Root Certificate
MalwareDok

Dok installs a root certificate to aid in Adversary-in-the-Middle actions using the command add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain /tmp/filename.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.