DFIR Report. (2022, March 21). APT35 Automates Initial Access Using ProxyShell. Retrieved May 25, 2022.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupMagic Hound | Magic Hound has stolen domain credentials by dumping LSASS process memory using Task Manager, comsvcs.dll, and from a Microsoft Active Directory Domain Controller using Mimikatz. |
| T1005 Data from Local System |
GroupMagic Hound | Magic Hound has used a web shell to exfiltrate a ZIP file containing a dump of LSASS memory on a compromised machine. |
| T1016 System Network Configuration Discovery |
GroupMagic Hound | Magic Hound malware gathers the victim's local IP address, MAC address, and external IP address. |
| T1021.001 Remote Desktop Protocol |
GroupMagic Hound | Magic Hound has used Remote Desktop Services to copy tools on targeted systems. |
| T1033 System Owner/User Discovery |
GroupMagic Hound | Magic Hound malware has obtained the victim username and sent it to the C2 server. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMagic Hound | Magic Hound has used `dllhost.exe` to mask Fast Reverse Proxy (FRP) and `MicrosoftOutLookUpdater.exe` for Plink. |
| T1036.010 Masquerade Account Name |
GroupMagic Hound | Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines. |
| T1047 Windows Management Instrumentation |
GroupMagic Hound | Magic Hound has used a tool to run `cmd /c wmic computersystem get domain` for discovery. |
| T1049 System Network Connections Discovery |
GroupMagic Hound | Magic Hound has used quser.exe to identify existing RDP connections. |
| T1053.005 Scheduled Task |
GroupMagic Hound | Magic Hound has used scheduled tasks to establish persistence and execution. |
| T1059.001 PowerShell |
GroupMagic Hound | Magic Hound has used PowerShell for execution and privilege escalation. |
| T1059.003 Windows Command Shell |
GroupMagic Hound | Magic Hound has used the command-line interface for code execution. |
| T1070.003 Clear Command History |
GroupMagic Hound | Magic Hound has removed mailbox export requests from compromised Exchange servers. |
| T1071.001 Web Protocols |
GroupMagic Hound | Magic Hound has used HTTP for C2. |
| T1082 System Information Discovery |
GroupMagic Hound | Magic Hound malware has used a PowerShell command to check the victim system architecture to determine if it is an x64 machine. Other malware has obtained the OS version, UUID, and computer/host name to send to the C2 server. |
| T1087.003 Email Account |
GroupMagic Hound | Magic Hound has used Powershell to discover email accounts. |
| T1098.007 Additional Local or Domain Groups |
GroupMagic Hound | Magic Hound has added a user named DefaultAccount to the Administrators and Remote Desktop Users groups. |
| T1105 Ingress Tool Transfer |
GroupMagic Hound | Magic Hound has downloaded additional code and files from servers onto victims. |
| T1112 Modify Registry |
GroupMagic Hound | Magic Hound has modified Registry settings for security tools. |
| T1114.002 Remote Email Collection |
GroupMagic Hound | Magic Hound has exported emails from compromised Exchange servers including through use of the cmdlet `New-MailboxExportRequest.` |
| T1136.001 Local Account |
GroupMagic Hound | Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines. |
| T1190 Exploit Public-Facing Application |
GroupMagic Hound | Magic Hound has exploited the Log4j utility (CVE-2021-44228), on-premises MS Exchange servers via "ProxyShell" (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), and Fortios SSL VPNs (CVE-2018-13379). |
| T1218.011 Rundll32 |
GroupMagic Hound | Magic Hound has used rundll32.exe to execute MiniDump from comsvcs.dll when dumping LSASS memory. |
| T1505.003 Web Shell |
GroupMagic Hound | Magic Hound has used multiple web shells to gain execution. |
| T1560.001 Archive via Utility |
GroupMagic Hound | Magic Hound has used gzip to archive dumped LSASS process memory and RAR to stage and compress local folders. |
| T1685 Disable or Modify Tools |
GroupMagic Hound | Magic Hound has disabled antivirus services on targeted systems in order to upload malicious payloads. |
| T1686.003 Windows Host Firewall |
GroupMagic Hound | Magic Hound has added the following rule to a victim's Windows firewall to allow RDP traffic - `"netsh" advfirewall firewall add rule name="Terminal Server" dir=in action=allow protocol=TCP localport=3389`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.