CrowdStrike. (2022, May). ICEAPPLE: A NOVEL INTERNET INFORMATION SERVICES (IIS) POST-EXPLOITATION FRAMEWORK. Retrieved June 27, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
MalwareIceApple | IceApple's Credential Dumper module can dump encrypted password hashes from SAM registry keys, including `HKLM\SAM\SAM\Domains\Account\F` and `HKLM\SAM\SAM\Domains\Account\Users\*\V`. |
| T1003.004 LSA Secrets |
MalwareIceApple | IceApple's Credential Dumper module can dump LSA secrets from registry keys, including: `HKLM\SECURITY\Policy\PolEKList\default`, `HKLM\SECURITY\Policy\Secrets\*\CurrVal`, and `HKLM\SECURITY\Policy\Secrets\*\OldVal`. |
| T1005 Data from Local System |
MalwareIceApple | IceApple can collect files, passwords, and other data from a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareIceApple | The IceApple ifconfig module can iterate over all network interfaces on the host and retrieve the name, description, MAC address, DNS suffix, DNS servers, gateways, IPv4 addresses, and subnet masks. |
| T1027.010 Command Obfuscation |
MalwareIceApple | IceApple can use Base64 and "junk" JavaScript code to obfuscate information. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareIceApple | IceApple .NET assemblies have used `App_Web_` in their file names to appear legitimate. |
| T1041 Exfiltration Over C2 Channel |
MalwareIceApple | IceApple's Multi File Exfiltrator module can exfiltrate multiple files from a compromised host as an HTTP response over C2. |
| T1056.003 Web Portal Capture |
MalwareIceApple | The IceApple OWA credential logger can monitor for OWA authentication requests and log the credentials. |
| T1070.004 File Deletion |
MalwareIceApple | IceApple can delete files and directories from targeted systems. |
| T1071.001 Web Protocols |
MalwareIceApple | IceApple can use HTTP GET to request and pull information from C2. |
| T1082 System Information Discovery |
MalwareIceApple | The IceApple Server Variable Dumper module iterates over all server variables present for the current request and returns them to the adversary. |
| T1083 File and Directory Discovery |
MalwareIceApple | The IceApple Directory Lister module can list information about files and directories including creation time, last write time, name, and size. |
| T1087.002 Domain Account |
MalwareIceApple | The IceApple Active Directory Querier module can perform authenticated requests against an Active Directory server. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareIceApple | IceApple can use a Base64-encoded AES key to decrypt tasking. |
| T1505.004 IIS Components |
MalwareIceApple | IceApple is an IIS post-exploitation framework, consisting of 18 modules that provide several functionalities. |
| T1552.002 Credentials in Registry |
MalwareIceApple | IceApple can harvest credentials from local and remote host registries. |
| T1560.001 Archive via Utility |
MalwareIceApple | IceApple can encrypt and compress files using Gzip prior to exfiltration. |
| T1573.001 Symmetric Cryptography |
MalwareIceApple | The IceApple Result Retriever module can AES encrypt C2 responses. |
| T1620 Reflective Code Loading |
MalwareIceApple | IceApple can use reflective code loading to load .NET assemblies into `MSExchangeOWAAppPool` on targeted Exchange servers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.