FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
Groupadmin@338 | admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to obtain information about services: |
| T1016 System Network Configuration Discovery |
Groupadmin@338 | admin@338 actors used the following command after exploiting a machine with LOWBALL malware to acquire information about local networks: |
| T1036.005 Match Legitimate Resource Name or Location |
Groupadmin@338 | admin@338 actors used the following command to rename one of their tools to a benign file name: |
| T1049 System Network Connections Discovery |
Groupadmin@338 | admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to display network connections: |
| T1059.003 Windows Command Shell |
Groupadmin@338 | Following exploitation with LOWBALL malware, admin@338 actors created a file containing a list of commands to be executed on the compromised computer. |
| T1069.001 Local Groups |
Groupadmin@338 | admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to list local groups: |
| T1071.001 Web Protocols |
MalwareLOWBALL | LOWBALL command and control occurs via HTTPS over port 443. |
| T1071.001 Web Protocols |
MalwareBUBBLEWRAP | BUBBLEWRAP can communicate using HTTP or HTTPS. |
| T1082 System Information Discovery |
MalwareBUBBLEWRAP | BUBBLEWRAP collects system information, including the operating system version and hostname. |
| T1082 System Information Discovery |
Groupadmin@338 | admin@338 actors used the following commands after exploiting a machine with LOWBALL malware to obtain information about the OS: |
| T1083 File and Directory Discovery |
Groupadmin@338 | admin@338 actors used the following commands after exploiting a machine with LOWBALL malware to obtain information about files and directories: |
| T1087.001 Local Account |
Groupadmin@338 | admin@338 actors used the following commands following exploitation of a machine with LOWBALL malware to enumerate user accounts: |
| T1095 Non-Application Layer Protocol |
MalwareBUBBLEWRAP | BUBBLEWRAP can communicate using SOCKS. |
| T1102.002 Bidirectional Communication |
MalwareLOWBALL | LOWBALL uses the Dropbox cloud storage service for command and control. |
| T1105 Ingress Tool Transfer |
MalwareLOWBALL | LOWBALL uses the Dropbox API to request two files, one of which is the same file as the one dropped by the malicious email attachment. This is most likely meant to be a mechanism to update the compromised host with a new version of the LOWBALL malware. |
| T1203 Exploitation for Client Execution |
Groupadmin@338 | admin@338 has exploited client software vulnerabilities for execution, such as Microsoft Word CVE-2012-0158. |
| T1204.002 Malicious File |
Groupadmin@338 | admin@338 has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails. |
| T1566.001 Spearphishing Attachment |
Groupadmin@338 | admin@338 has sent emails with malicious Microsoft Office documents attached. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.