ATT&CKReferencesDFIR Phosphorus November 2021

DFIR Phosphorus November 2021

DFIR Report. (2021, November 15). Exchange Exploit Leads to Domain Wide Ransomware. Retrieved January 5, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples35

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupMagic Hound

Magic Hound has stolen domain credentials by dumping LSASS process memory using Task Manager, comsvcs.dll, and from a Microsoft Active Directory Domain Controller using Mimikatz.

T1005
Data from Local System
GroupMagic Hound

Magic Hound has used a web shell to exfiltrate a ZIP file containing a dump of LSASS memory on a compromised machine.

T1016
System Network Configuration Discovery
GroupMagic Hound

Magic Hound malware gathers the victim's local IP address, MAC address, and external IP address.

T1016.001
Internet Connection Discovery
GroupMagic Hound

Magic Hound has conducted a network call out to a specific website as part of their initial discovery activity.

T1018
Remote System Discovery
GroupMagic Hound

Magic Hound has used Ping for discovery on targeted networks.

T1021.001
Remote Desktop Protocol
GroupMagic Hound

Magic Hound has used Remote Desktop Services to copy tools on targeted systems.

T1033
System Owner/User Discovery
GroupMagic Hound

Magic Hound malware has obtained the victim username and sent it to the C2 server.

T1036.004
Masquerade Task or Service
GroupMagic Hound

Magic Hound has named a malicious script CacheTask.bat to mimic a legitimate task.

T1036.005
Match Legitimate Resource Name or Location
GroupMagic Hound

Magic Hound has used `dllhost.exe` to mask Fast Reverse Proxy (FRP) and `MicrosoftOutLookUpdater.exe` for Plink.

T1046
Network Service Discovery
GroupMagic Hound

Magic Hound has used KPortScan 3.0 to perform SMB, RDP, and LDAP scanning.

T1053.005
Scheduled Task
GroupMagic Hound

Magic Hound has used scheduled tasks to establish persistence and execution.

T1059.001
PowerShell
GroupMagic Hound

Magic Hound has used PowerShell for execution and privilege escalation.

T1059.003
Windows Command Shell
GroupMagic Hound

Magic Hound has used the command-line interface for code execution.

T1070.004
File Deletion
GroupMagic Hound

Magic Hound has deleted and overwrote files to cover tracks.

T1071
Application Layer Protocol
GroupMagic Hound

Magic Hound malware has used IRC for C2.

T1071.001
Web Protocols
GroupMagic Hound

Magic Hound has used HTTP for C2.

T1078.001
Default Accounts
GroupMagic Hound

Magic Hound enabled and used the default system managed account, DefaultAccount, via `"powershell.exe" /c net user DefaultAccount /active:yes` to connect to a targeted Exchange server over RDP.

T1078.002
Domain Accounts
GroupMagic Hound

Magic Hound has used domain administrator accounts after dumping LSASS process memory.

T1082
System Information Discovery
GroupMagic Hound

Magic Hound malware has used a PowerShell command to check the victim system architecture to determine if it is an x64 machine. Other malware has obtained the OS version, UUID, and computer/host name to send to the C2 server.

T1090
Proxy
GroupMagic Hound

Magic Hound has used Fast Reverse Proxy (FRP) for RDP traffic.

T1105
Ingress Tool Transfer
GroupMagic Hound

Magic Hound has downloaded additional code and files from servers onto victims.

T1114.002
Remote Email Collection
GroupMagic Hound

Magic Hound has exported emails from compromised Exchange servers including through use of the cmdlet `New-MailboxExportRequest.`

T1190
Exploit Public-Facing Application
GroupMagic Hound

Magic Hound has exploited the Log4j utility (CVE-2021-44228), on-premises MS Exchange servers via "ProxyShell" (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), and Fortios SSL VPNs (CVE-2018-13379).

T1482
Domain Trust Discovery
GroupMagic Hound

Magic Hound has used a web shell to execute `nltest /trusted_domains` to identify trust relationships.

T1486
Data Encrypted for Impact
GroupMagic Hound

Magic Hound has used BitLocker and DiskCryptor to encrypt targeted workstations.

T1505.003
Web Shell
GroupMagic Hound

Magic Hound has used multiple web shells to gain execution.

T1547.001
Registry Run Keys / Startup Folder
GroupMagic Hound

Magic Hound malware has used Registry Run keys to establish persistence.

T1560.001
Archive via Utility
GroupMagic Hound

Magic Hound has used gzip to archive dumped LSASS process memory and RAR to stage and compress local folders.

T1570
Lateral Tool Transfer
GroupMagic Hound

Magic Hound has copied tools within a compromised network using RDP.

T1571
Non-Standard Port
GroupMagic Hound

Magic Hound malware has communicated with its C2 server over TCP ports 4443 and 10151 using HTTP.

T1572
Protocol Tunneling
GroupMagic Hound

Magic Hound has used Plink to tunnel RDP over SSH.

T1573
Encrypted Channel
GroupMagic Hound

Magic Hound has used an encrypted http proxy in C2 communications.

T1588.002
Tool
GroupMagic Hound

Magic Hound has obtained and used tools like Havij, sqlmap, Metasploit, Mimikatz, and Plink.

T1685.001
Disable or Modify Windows Event Log
GroupMagic Hound

Magic Hound has executed scripts to disable the event log service.

T1686.003
Windows Host Firewall
GroupMagic Hound

Magic Hound has added the following rule to a victim's Windows firewall to allow RDP traffic - `"netsh" advfirewall firewall add rule name="Terminal Server" dir=in action=allow protocol=TCP localport=3389`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.