ATT&CKReferencesUnit 42 Magic Hound Feb 2017

Unit 42 Magic Hound Feb 2017

Lee, B. and Falcone, R. (2017, February 15). Magic Hound Campaign Attacks Saudi Targets. Retrieved December 27, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples20

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupMagic Hound

Magic Hound malware gathers the victim's local IP address, MAC address, and external IP address.

T1027.010
Command Obfuscation
GroupMagic Hound

Magic Hound has used base64-encoded commands.

T1027.013
Encrypted/Encoded File
GroupMagic Hound

Magic Hound malware has used base64-encoded files and has also encrypted embedded strings with AES.

T1033
System Owner/User Discovery
GroupMagic Hound

Magic Hound malware has obtained the victim username and sent it to the C2 server.

T1056.001
Keylogging
GroupMagic Hound

Magic Hound malware is capable of keylogging.

T1057
Process Discovery
GroupMagic Hound

Magic Hound malware can list running processes.

T1059.001
PowerShell
GroupMagic Hound

Magic Hound has used PowerShell for execution and privilege escalation.

T1059.003
Windows Command Shell
GroupMagic Hound

Magic Hound has used the command-line interface for code execution.

T1059.005
Visual Basic
GroupMagic Hound

Magic Hound malware has used VBS scripts for execution.

T1070.004
File Deletion
GroupMagic Hound

Magic Hound has deleted and overwrote files to cover tracks.

T1071
Application Layer Protocol
GroupMagic Hound

Magic Hound malware has used IRC for C2.

T1071.001
Web Protocols
GroupMagic Hound

Magic Hound has used HTTP for C2.

T1082
System Information Discovery
GroupMagic Hound

Magic Hound malware has used a PowerShell command to check the victim system architecture to determine if it is an x64 machine. Other malware has obtained the OS version, UUID, and computer/host name to send to the C2 server.

T1083
File and Directory Discovery
GroupMagic Hound

Magic Hound malware can list a victim's logical drives and the type, as well the total/free space of the fixed devices. Other malware can list a directory's contents.

T1102.002
Bidirectional Communication
GroupMagic Hound

Magic Hound malware can use a SOAP Web service to communicate with its C2 server.

T1105
Ingress Tool Transfer
GroupMagic Hound

Magic Hound has downloaded additional code and files from servers onto victims.

T1113
Screen Capture
GroupMagic Hound

Magic Hound malware can take a screenshot and upload the file to its C2 server.

T1547.001
Registry Run Keys / Startup Folder
GroupMagic Hound

Magic Hound malware has used Registry Run keys to establish persistence.

T1564.003
Hidden Window
GroupMagic Hound

Magic Hound malware has a function to determine whether the C2 server wishes to execute the newly dropped file in a hidden window.

T1571
Non-Standard Port
GroupMagic Hound

Magic Hound malware has communicated with its C2 server over TCP ports 4443 and 10151 using HTTP.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.