Eoin Miller. (2021, March 23). Defending Against the Zero Day: Analyzing Attacker Behavior Post-Exploitation of Microsoft Exchange. Retrieved October 27, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupHAFNIUM | HAFNIUM has used |
| T1005 Data from Local System |
MalwareChina Chopper | China Chopper's server component can upload local files. |
| T1005 Data from Local System |
GroupHAFNIUM | HAFNIUM has collected data and files from a compromised machine. |
| T1016 System Network Configuration Discovery |
GroupHAFNIUM | HAFNIUM has collected IP information via IPInfo. |
| T1016.001 Internet Connection Discovery |
GroupHAFNIUM | HAFNIUM has checked for network connectivity from a compromised host using `ping`, including attempts to contact `google[.]com`. |
| T1018 Remote System Discovery |
GroupHAFNIUM | HAFNIUM has enumerated domain controllers using `net group "Domain computers"` and `nltest /dclist`. |
| T1033 System Owner/User Discovery |
GroupHAFNIUM | HAFNIUM has used `whoami` to gather user information. |
| T1057 Process Discovery |
GroupHAFNIUM | HAFNIUM has used `tasklist` to enumerate processes. |
| T1059.003 Windows Command Shell |
GroupHAFNIUM | HAFNIUM has used `cmd.exe` to execute commands on the victim's machine. |
| T1083 File and Directory Discovery |
GroupHAFNIUM | HAFNIUM has searched file contents on a compromised host. |
| T1083 File and Directory Discovery |
MalwareChina Chopper | China Chopper's server component can list directory contents. |
| T1105 Ingress Tool Transfer |
GroupHAFNIUM | HAFNIUM has downloaded malware and tools--including Nishang and PowerCat--onto a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareChina Chopper | China Chopper's server component can download remote files. |
| T1505.003 Web Shell |
GroupHAFNIUM | HAFNIUM has deployed multiple web shells on compromised servers including SIMPLESEESHARP, SPORTSBALL, China Chopper, and ASPXSpy. |
| T1564.001 Hidden Files and Directories |
GroupHAFNIUM | HAFNIUM has hidden files on a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.