Unit 42. (2017, December 15). Unit 42 Playbook Viewer. Retrieved December 20, 2017.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareJHUHUGIT | A JHUHUGIT variant gathers network interface card information. |
| T1037.001 Logon Script (Windows) |
GroupAPT28 | An APT28 loader Trojan adds the Registry key |
| T1057 Process Discovery |
GroupAPT28 | An APT28 loader Trojan will enumerate the victim's processes searching for explorer.exe if its current process does not have necessary permissions. |
| T1057 Process Discovery |
MalwareHelminth | |
| T1059.001 PowerShell |
GroupDarkHydrus | DarkHydrus leveraged PowerShell to download and execute additional scripts for execution. |
| T1059.003 Windows Command Shell |
GroupAPT28 | An APT28 loader Trojan uses a cmd.exe and batch script to run its payload. The group has also used macros to execute payloads. |
| T1069.001 Local Groups |
MalwareHelminth | Helminth has checked the local administrators group. |
| T1069.002 Domain Groups |
MalwareHelminth | Helminth has checked for the domain admin group and Exchange Trusted Subsystem groups using the commands |
| T1071.001 Web Protocols |
MalwareJHUHUGIT | JHUHUGIT variants have communicated with C2 servers over HTTP and HTTPS. |
| T1105 Ingress Tool Transfer |
GroupAPT28 | APT28 has downloaded additional files, including by using a first-stage downloader to contact the C2 server to obtain the second-stage implant. |
| T1113 Screen Capture |
MalwareJHUHUGIT | A JHUHUGIT variant takes screenshots by simulating the user pressing the "Take Screenshot" key (VK_SCREENSHOT), accessing the screenshot saved in the clipboard, and converting it to a JPG image. |
| T1115 Clipboard Data |
MalwareJHUHUGIT | A JHUHUGIT variant accesses a screenshot saved in the clipboard and converts it to a JPG image. |
| T1132.001 Standard Encoding |
MalwareJHUHUGIT | A JHUHUGIT variant encodes C2 POST data base64. |
| T1204.002 Malicious File |
GroupDarkHydrus | DarkHydrus has sent malware that required users to hit the enable button in Microsoft Excel to allow an .iqy file to be downloaded. |
| T1218.011 Rundll32 |
GroupAPT28 | APT28 executed CHOPSTICK by using rundll32 commands such as |
| T1566.001 Spearphishing Attachment |
GroupDarkHydrus | DarkHydrus has sent spearphishing emails with password-protected RAR archives containing malicious Excel Web Query files (.iqy). The group has also sent spearphishing emails that contained malicious Microsoft Office documents that use the “attachedTemplate” technique to load a template from a remote server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.