Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved November 15, 2018.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
GroupAPT18 | APT18 obfuscates strings in the payload. |
| T1059.003 Windows Command Shell |
GroupAPT18 | APT18 uses cmd.exe to execute commands on the victim’s machine. |
| T1071.001 Web Protocols |
GroupAPT18 | APT18 uses HTTP for C2 communications. |
| T1071.004 DNS |
GroupAPT18 | APT18 uses DNS for C2 communications. |
| T1082 System Information Discovery |
GroupAPT18 | APT18 can collect system information from the victim’s machine. |
| T1083 File and Directory Discovery |
GroupAPT18 | APT18 can list files information for specific directories. |
| T1105 Ingress Tool Transfer |
GroupAPT18 | APT18 can upload a file to the victim’s machine. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT18 | APT18 establishes persistence via the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.