ATT&CKReferencesUnit 42 PingPull Jun 2022

Unit 42 PingPull Jun 2022

Unit 42. (2022, June 13). GALLIUM Expands Targeting Across Telecommunications, Government and Finance Sectors With New PingPull Tool. Retrieved August 7, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwarePingPull

PingPull can collect data from a compromised host.

T1016
System Network Configuration Discovery
MalwarePingPull

PingPull can retrieve the IP address of a compromised host.

T1036.004
Masquerade Task or Service
MalwarePingPull

PingPull can mimic the names and descriptions of legitimate services such as `iphlpsvc`, `IP Helper`, and `Onedrive` to evade detection.

T1041
Exfiltration Over C2 Channel
MalwarePingPull

PingPull has the ability to exfiltrate stolen victim data through its C2 channel.

T1059.003
Windows Command Shell
MalwarePingPull

PingPull can use `cmd.exe` to run various commands as a reverse shell.

T1070.006
Timestomp
MalwarePingPull

PingPull has the ability to timestomp a file.

T1071.001
Web Protocols
MalwarePingPull

A PingPull variant can communicate with its C2 servers by using HTTPS.

T1082
System Information Discovery
MalwarePingPull

PingPull can retrieve the hostname of a compromised host.

T1083
File and Directory Discovery
MalwarePingPull

PingPull can enumerate storage volumes and folder contents of a compromised host.

T1095
Non-Application Layer Protocol
MalwarePingPull

PingPull variants have the ability to communicate with C2 servers using ICMP or TCP.

T1132.001
Standard Encoding
MalwarePingPull

PingPull can encode C2 traffic with Base64.

T1140
Deobfuscate/Decode Files or Information
MalwarePingPull

PingPull can decrypt received data from its C2 server by using AES.

T1543.003
Windows Service
MalwarePingPull

PingPull has the ability to install itself as a service.

T1571
Non-Standard Port
MalwarePingPull

PingPull can use HTTPS over port 8080 for C2.

T1573.001
Symmetric Cryptography
MalwarePingPull

PingPull can use AES, in cipher block chaining (CBC) mode padded with PKCS5, to encrypt C2 server communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.