ATT&CKReferencesPaloAlto DNS Requests May 2016

PaloAlto DNS Requests May 2016

Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved November 15, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
GroupAPT18

APT18 obfuscates strings in the payload.

T1059.003
Windows Command Shell
GroupAPT18

APT18 uses cmd.exe to execute commands on the victim’s machine.

T1071.001
Web Protocols
GroupAPT18

APT18 uses HTTP for C2 communications.

T1071.004
DNS
GroupAPT18

APT18 uses DNS for C2 communications.

T1082
System Information Discovery
GroupAPT18

APT18 can collect system information from the victim’s machine.

T1083
File and Directory Discovery
GroupAPT18

APT18 can list files information for specific directories.

T1105
Ingress Tool Transfer
GroupAPT18

APT18 can upload a file to the victim’s machine.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT18

APT18 establishes persistence via the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.