Lee, B. and Falcone, R. (2017, February 15). Magic Hound Campaign Attacks Saudi Targets. Retrieved December 27, 2017.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupMagic Hound | Magic Hound malware gathers the victim's local IP address, MAC address, and external IP address. |
| T1027.010 Command Obfuscation |
GroupMagic Hound | Magic Hound has used base64-encoded commands. |
| T1027.013 Encrypted/Encoded File |
GroupMagic Hound | Magic Hound malware has used base64-encoded files and has also encrypted embedded strings with AES. |
| T1033 System Owner/User Discovery |
GroupMagic Hound | Magic Hound malware has obtained the victim username and sent it to the C2 server. |
| T1056.001 Keylogging |
GroupMagic Hound | Magic Hound malware is capable of keylogging. |
| T1057 Process Discovery |
GroupMagic Hound | Magic Hound malware can list running processes. |
| T1059.001 PowerShell |
GroupMagic Hound | Magic Hound has used PowerShell for execution and privilege escalation. |
| T1059.003 Windows Command Shell |
GroupMagic Hound | Magic Hound has used the command-line interface for code execution. |
| T1059.005 Visual Basic |
GroupMagic Hound | Magic Hound malware has used VBS scripts for execution. |
| T1070.004 File Deletion |
GroupMagic Hound | Magic Hound has deleted and overwrote files to cover tracks. |
| T1071 Application Layer Protocol |
GroupMagic Hound | Magic Hound malware has used IRC for C2. |
| T1071.001 Web Protocols |
GroupMagic Hound | Magic Hound has used HTTP for C2. |
| T1082 System Information Discovery |
GroupMagic Hound | Magic Hound malware has used a PowerShell command to check the victim system architecture to determine if it is an x64 machine. Other malware has obtained the OS version, UUID, and computer/host name to send to the C2 server. |
| T1083 File and Directory Discovery |
GroupMagic Hound | Magic Hound malware can list a victim's logical drives and the type, as well the total/free space of the fixed devices. Other malware can list a directory's contents. |
| T1102.002 Bidirectional Communication |
GroupMagic Hound | Magic Hound malware can use a SOAP Web service to communicate with its C2 server. |
| T1105 Ingress Tool Transfer |
GroupMagic Hound | Magic Hound has downloaded additional code and files from servers onto victims. |
| T1113 Screen Capture |
GroupMagic Hound | Magic Hound malware can take a screenshot and upload the file to its C2 server. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupMagic Hound | Magic Hound malware has used Registry Run keys to establish persistence. |
| T1564.003 Hidden Window |
GroupMagic Hound | Magic Hound malware has a function to determine whether the C2 server wishes to execute the newly dropped file in a hidden window. |
| T1571 Non-Standard Port |
GroupMagic Hound | Magic Hound malware has communicated with its C2 server over TCP ports 4443 and 10151 using HTTP. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.