fluffybunny. (2019, July 9). OSX.Dok Analysis. Retrieved November 17, 2024.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareDok | Dok is packed with an UPX executable packer. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareDok | Dok exfiltrates logs of its execution stored in the |
| T1547.015 Login Items |
MalwareDok | Dok uses AppleScript to install a login Item by sending Apple events to the |
| T1548.003 Sudo and Sudo Caching |
MalwareDok | Dok adds |
| T1553.004 Install Root Certificate |
MalwareDok | Dok installs a root certificate to aid in Adversary-in-the-Middle actions using the command |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.