ATT&CKReferencesFireEye admin@338

FireEye admin@338

FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1007
System Service Discovery
Groupadmin@338

admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to obtain information about services: net start >> %temp%\download

T1016
System Network Configuration Discovery
Groupadmin@338

admin@338 actors used the following command after exploiting a machine with LOWBALL malware to acquire information about local networks: ipconfig /all >> %temp%\download

T1036.005
Match Legitimate Resource Name or Location
Groupadmin@338

admin@338 actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe

T1049
System Network Connections Discovery
Groupadmin@338

admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to display network connections: netstat -ano >> %temp%\download

T1059.003
Windows Command Shell
Groupadmin@338

Following exploitation with LOWBALL malware, admin@338 actors created a file containing a list of commands to be executed on the compromised computer.

T1069.001
Local Groups
Groupadmin@338

admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to list local groups: net localgroup administrator >> %temp%\download

T1071.001
Web Protocols
MalwareLOWBALL

LOWBALL command and control occurs via HTTPS over port 443.

T1071.001
Web Protocols
MalwareBUBBLEWRAP

BUBBLEWRAP can communicate using HTTP or HTTPS.

T1082
System Information Discovery
MalwareBUBBLEWRAP

BUBBLEWRAP collects system information, including the operating system version and hostname.

T1082
System Information Discovery
Groupadmin@338

admin@338 actors used the following commands after exploiting a machine with LOWBALL malware to obtain information about the OS: ver >> %temp%\download systeminfo >> %temp%\download

T1083
File and Directory Discovery
Groupadmin@338

admin@338 actors used the following commands after exploiting a machine with LOWBALL malware to obtain information about files and directories: dir c:\ >> %temp%\download dir "c:\Documents and Settings" >> %temp%\download dir "c:\Program Files\" >> %temp%\download dir d:\ >> %temp%\download

T1087.001
Local Account
Groupadmin@338

admin@338 actors used the following commands following exploitation of a machine with LOWBALL malware to enumerate user accounts: net user >> %temp%\download net user /domain >> %temp%\download

T1095
Non-Application Layer Protocol
MalwareBUBBLEWRAP

BUBBLEWRAP can communicate using SOCKS.

T1102.002
Bidirectional Communication
MalwareLOWBALL

LOWBALL uses the Dropbox cloud storage service for command and control.

T1105
Ingress Tool Transfer
MalwareLOWBALL

LOWBALL uses the Dropbox API to request two files, one of which is the same file as the one dropped by the malicious email attachment. This is most likely meant to be a mechanism to update the compromised host with a new version of the LOWBALL malware.

T1203
Exploitation for Client Execution
Groupadmin@338

admin@338 has exploited client software vulnerabilities for execution, such as Microsoft Word CVE-2012-0158.

T1204.002
Malicious File
Groupadmin@338

admin@338 has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails.

T1566.001
Spearphishing Attachment
Groupadmin@338

admin@338 has sent emails with malicious Microsoft Office documents attached.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.