DFIR Report. (2021, November 15). Exchange Exploit Leads to Domain Wide Ransomware. Retrieved January 5, 2023.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupMagic Hound | Magic Hound has stolen domain credentials by dumping LSASS process memory using Task Manager, comsvcs.dll, and from a Microsoft Active Directory Domain Controller using Mimikatz. |
| T1005 Data from Local System |
GroupMagic Hound | Magic Hound has used a web shell to exfiltrate a ZIP file containing a dump of LSASS memory on a compromised machine. |
| T1016 System Network Configuration Discovery |
GroupMagic Hound | Magic Hound malware gathers the victim's local IP address, MAC address, and external IP address. |
| T1016.001 Internet Connection Discovery |
GroupMagic Hound | Magic Hound has conducted a network call out to a specific website as part of their initial discovery activity. |
| T1018 Remote System Discovery |
GroupMagic Hound | Magic Hound has used Ping for discovery on targeted networks. |
| T1021.001 Remote Desktop Protocol |
GroupMagic Hound | Magic Hound has used Remote Desktop Services to copy tools on targeted systems. |
| T1033 System Owner/User Discovery |
GroupMagic Hound | Magic Hound malware has obtained the victim username and sent it to the C2 server. |
| T1036.004 Masquerade Task or Service |
GroupMagic Hound | Magic Hound has named a malicious script CacheTask.bat to mimic a legitimate task. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMagic Hound | Magic Hound has used `dllhost.exe` to mask Fast Reverse Proxy (FRP) and `MicrosoftOutLookUpdater.exe` for Plink. |
| T1046 Network Service Discovery |
GroupMagic Hound | Magic Hound has used KPortScan 3.0 to perform SMB, RDP, and LDAP scanning. |
| T1053.005 Scheduled Task |
GroupMagic Hound | Magic Hound has used scheduled tasks to establish persistence and execution. |
| T1059.001 PowerShell |
GroupMagic Hound | Magic Hound has used PowerShell for execution and privilege escalation. |
| T1059.003 Windows Command Shell |
GroupMagic Hound | Magic Hound has used the command-line interface for code execution. |
| T1070.004 File Deletion |
GroupMagic Hound | Magic Hound has deleted and overwrote files to cover tracks. |
| T1071 Application Layer Protocol |
GroupMagic Hound | Magic Hound malware has used IRC for C2. |
| T1071.001 Web Protocols |
GroupMagic Hound | Magic Hound has used HTTP for C2. |
| T1078.001 Default Accounts |
GroupMagic Hound | Magic Hound enabled and used the default system managed account, DefaultAccount, via `"powershell.exe" /c net user DefaultAccount /active:yes` to connect to a targeted Exchange server over RDP. |
| T1078.002 Domain Accounts |
GroupMagic Hound | Magic Hound has used domain administrator accounts after dumping LSASS process memory. |
| T1082 System Information Discovery |
GroupMagic Hound | Magic Hound malware has used a PowerShell command to check the victim system architecture to determine if it is an x64 machine. Other malware has obtained the OS version, UUID, and computer/host name to send to the C2 server. |
| T1090 Proxy |
GroupMagic Hound | Magic Hound has used Fast Reverse Proxy (FRP) for RDP traffic. |
| T1105 Ingress Tool Transfer |
GroupMagic Hound | Magic Hound has downloaded additional code and files from servers onto victims. |
| T1114.002 Remote Email Collection |
GroupMagic Hound | Magic Hound has exported emails from compromised Exchange servers including through use of the cmdlet `New-MailboxExportRequest.` |
| T1190 Exploit Public-Facing Application |
GroupMagic Hound | Magic Hound has exploited the Log4j utility (CVE-2021-44228), on-premises MS Exchange servers via "ProxyShell" (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), and Fortios SSL VPNs (CVE-2018-13379). |
| T1482 Domain Trust Discovery |
GroupMagic Hound | Magic Hound has used a web shell to execute `nltest /trusted_domains` to identify trust relationships. |
| T1486 Data Encrypted for Impact |
GroupMagic Hound | Magic Hound has used BitLocker and DiskCryptor to encrypt targeted workstations. |
| T1505.003 Web Shell |
GroupMagic Hound | Magic Hound has used multiple web shells to gain execution. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupMagic Hound | Magic Hound malware has used Registry Run keys to establish persistence. |
| T1560.001 Archive via Utility |
GroupMagic Hound | Magic Hound has used gzip to archive dumped LSASS process memory and RAR to stage and compress local folders. |
| T1570 Lateral Tool Transfer |
GroupMagic Hound | Magic Hound has copied tools within a compromised network using RDP. |
| T1571 Non-Standard Port |
GroupMagic Hound | Magic Hound malware has communicated with its C2 server over TCP ports 4443 and 10151 using HTTP. |
| T1572 Protocol Tunneling |
GroupMagic Hound | Magic Hound has used Plink to tunnel RDP over SSH. |
| T1573 Encrypted Channel |
GroupMagic Hound | Magic Hound has used an encrypted http proxy in C2 communications. |
| T1588.002 Tool |
GroupMagic Hound | Magic Hound has obtained and used tools like Havij, sqlmap, Metasploit, Mimikatz, and Plink. |
| T1685.001 Disable or Modify Windows Event Log |
GroupMagic Hound | Magic Hound has executed scripts to disable the event log service. |
| T1686.003 Windows Host Firewall |
GroupMagic Hound | Magic Hound has added the following rule to a victim's Windows firewall to allow RDP traffic - `"netsh" advfirewall firewall add rule name="Terminal Server" dir=in action=allow protocol=TCP localport=3389`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.