ATT&CKReferencesDFIR Report APT35 ProxyShell March 2022

DFIR Report APT35 ProxyShell March 2022

DFIR Report. (2022, March 21). APT35 Automates Initial Access Using ProxyShell. Retrieved May 25, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples27

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupMagic Hound

Magic Hound has stolen domain credentials by dumping LSASS process memory using Task Manager, comsvcs.dll, and from a Microsoft Active Directory Domain Controller using Mimikatz.

T1005
Data from Local System
GroupMagic Hound

Magic Hound has used a web shell to exfiltrate a ZIP file containing a dump of LSASS memory on a compromised machine.

T1016
System Network Configuration Discovery
GroupMagic Hound

Magic Hound malware gathers the victim's local IP address, MAC address, and external IP address.

T1021.001
Remote Desktop Protocol
GroupMagic Hound

Magic Hound has used Remote Desktop Services to copy tools on targeted systems.

T1033
System Owner/User Discovery
GroupMagic Hound

Magic Hound malware has obtained the victim username and sent it to the C2 server.

T1036.005
Match Legitimate Resource Name or Location
GroupMagic Hound

Magic Hound has used `dllhost.exe` to mask Fast Reverse Proxy (FRP) and `MicrosoftOutLookUpdater.exe` for Plink.

T1036.010
Masquerade Account Name
GroupMagic Hound

Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines.

T1047
Windows Management Instrumentation
GroupMagic Hound

Magic Hound has used a tool to run `cmd /c wmic computersystem get domain` for discovery.

T1049
System Network Connections Discovery
GroupMagic Hound

Magic Hound has used quser.exe to identify existing RDP connections.

T1053.005
Scheduled Task
GroupMagic Hound

Magic Hound has used scheduled tasks to establish persistence and execution.

T1059.001
PowerShell
GroupMagic Hound

Magic Hound has used PowerShell for execution and privilege escalation.

T1059.003
Windows Command Shell
GroupMagic Hound

Magic Hound has used the command-line interface for code execution.

T1070.003
Clear Command History
GroupMagic Hound

Magic Hound has removed mailbox export requests from compromised Exchange servers.

T1071.001
Web Protocols
GroupMagic Hound

Magic Hound has used HTTP for C2.

T1082
System Information Discovery
GroupMagic Hound

Magic Hound malware has used a PowerShell command to check the victim system architecture to determine if it is an x64 machine. Other malware has obtained the OS version, UUID, and computer/host name to send to the C2 server.

T1087.003
Email Account
GroupMagic Hound

Magic Hound has used Powershell to discover email accounts.

T1098.007
Additional Local or Domain Groups
GroupMagic Hound

Magic Hound has added a user named DefaultAccount to the Administrators and Remote Desktop Users groups.

T1105
Ingress Tool Transfer
GroupMagic Hound

Magic Hound has downloaded additional code and files from servers onto victims.

T1112
Modify Registry
GroupMagic Hound

Magic Hound has modified Registry settings for security tools.

T1114.002
Remote Email Collection
GroupMagic Hound

Magic Hound has exported emails from compromised Exchange servers including through use of the cmdlet `New-MailboxExportRequest.`

T1136.001
Local Account
GroupMagic Hound

Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines.

T1190
Exploit Public-Facing Application
GroupMagic Hound

Magic Hound has exploited the Log4j utility (CVE-2021-44228), on-premises MS Exchange servers via "ProxyShell" (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), and Fortios SSL VPNs (CVE-2018-13379).

T1218.011
Rundll32
GroupMagic Hound

Magic Hound has used rundll32.exe to execute MiniDump from comsvcs.dll when dumping LSASS memory.

T1505.003
Web Shell
GroupMagic Hound

Magic Hound has used multiple web shells to gain execution.

T1560.001
Archive via Utility
GroupMagic Hound

Magic Hound has used gzip to archive dumped LSASS process memory and RAR to stage and compress local folders.

T1685
Disable or Modify Tools
GroupMagic Hound

Magic Hound has disabled antivirus services on targeted systems in order to upload malicious payloads.

T1686.003
Windows Host Firewall
GroupMagic Hound

Magic Hound has added the following rule to a victim's Windows firewall to allow RDP traffic - `"netsh" advfirewall firewall add rule name="Terminal Server" dir=in action=allow protocol=TCP localport=3389`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.