Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1020 Automated Exfiltration |
Doki has used a script that gathers information from a hardcoded list of IP addresses and uploads to an Ngrok URL. |
| T1036.005 Match Legitimate Resource Name or Location |
Doki has disguised a file as a Linux kernel module. |
| T1041 Exfiltration Over C2 Channel |
Doki has used Ngrok to establish C2 and exfiltrate data. |
| T1057 Process Discovery |
Doki has searched for the current process’s PID. |
| T1059.004 Unix Shell |
Doki has executed shell scripts with /bin/sh. |
| T1071.001 Web Protocols |
Doki has communicated with C2 over HTTPS. |
| T1083 File and Directory Discovery |
Doki has resolved the path of a process PID to use as a script argument. |
| T1102 Web Service |
Doki has used the dogechain.info API to generate a C2 address. |
| T1105 Ingress Tool Transfer |
Doki has downloaded scripts from C2. |
| T1133 External Remote Services |
Doki was executed through an open Docker daemon API port. |
| T1568.002 Domain Generation Algorithms |
Doki has used the DynDNS service and a DGA based on the Dogecoin blockchain to generate C2 domains. |
| T1573.002 Asymmetric Cryptography |
Doki has used the embedTLS library for network communications. |
| T1610 Deploy Container |
Doki was run through a deployed container. |
| T1611 Escape to Host |
Doki’s container was configured to bind the host root directory. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.