Fishbein, N., Kajiloti, M.. (2020, July 28). Watch Your Containers: Doki Infecting Docker Servers in the Cloud. Retrieved March 30, 2021.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1020 Automated Exfiltration |
MalwareDoki | Doki has used a script that gathers information from a hardcoded list of IP addresses and uploads to an Ngrok URL. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareDoki | Doki has disguised a file as a Linux kernel module. |
| T1041 Exfiltration Over C2 Channel |
MalwareDoki | Doki has used Ngrok to establish C2 and exfiltrate data. |
| T1057 Process Discovery |
MalwareDoki | Doki has searched for the current process’s PID. |
| T1059.004 Unix Shell |
MalwareDoki | Doki has executed shell scripts with /bin/sh. |
| T1071.001 Web Protocols |
MalwareDoki | Doki has communicated with C2 over HTTPS. |
| T1083 File and Directory Discovery |
MalwareDoki | Doki has resolved the path of a process PID to use as a script argument. |
| T1102 Web Service |
MalwareDoki | Doki has used the dogechain.info API to generate a C2 address. |
| T1105 Ingress Tool Transfer |
MalwareDoki | Doki has downloaded scripts from C2. |
| T1133 External Remote Services |
MalwareDoki | Doki was executed through an open Docker daemon API port. |
| T1568.002 Domain Generation Algorithms |
MalwareDoki | Doki has used the DynDNS service and a DGA based on the Dogecoin blockchain to generate C2 domains. |
| T1573.002 Asymmetric Cryptography |
MalwareDoki | Doki has used the embedTLS library for network communications. |
| T1610 Deploy Container |
MalwareDoki | Doki was run through a deployed container. |
| T1611 Escape to Host |
MalwareDoki | Doki’s container was configured to bind the host root directory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.