Ahl, I. (2017, June 06). Privileges and Credentials: Phished at the Request of Counsel. Retrieved May 17, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
GroupAPT19 | APT19 used Base64 to obfuscate executed commands. |
| T1027.013 Encrypted/Encoded File |
GroupAPT19 | APT19 used Base64 to obfuscate payloads. |
| T1059 Command and Scripting Interpreter |
GroupAPT19 | APT19 downloaded and launched code within a SCT file. |
| T1059.001 PowerShell |
GroupAPT19 | APT19 used PowerShell commands to execute payloads. |
| T1071.001 Web Protocols |
GroupAPT19 | APT19 used HTTP for C2 communications. APT19 also used an HTTP malware variant to communicate over HTTP for C2. |
| T1082 System Information Discovery |
GroupAPT19 | APT19 collected system architecture information. APT19 used an HTTP malware variant and a Port 22 malware variant to gather the hostname and CPU information from the victim’s machine. |
| T1204.002 Malicious File |
GroupAPT19 | APT19 attempted to get users to launch malicious attachments delivered via spearphishing emails. |
| T1218.010 Regsvr32 |
GroupAPT19 | APT19 used Regsvr32 to bypass application control techniques. |
| T1218.011 Rundll32 |
GroupAPT19 | APT19 configured its payload to inject into the rundll32.exe. |
| T1564.003 Hidden Window |
GroupAPT19 | APT19 used |
| T1566.001 Spearphishing Attachment |
GroupAPT19 | APT19 sent spearphishing emails with malicious attachments in RTF and XLSM formats to deliver initial exploits. |
| T1588.002 Tool |
GroupAPT19 | APT19 has obtained and used publicly-available tools like Empire. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.