Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
FoggyWeb can retrieve configuration data from a compromised AD FS server. |
| T1027.004 Compile After Delivery |
FoggyWeb can compile and execute source code sent to the compromised AD FS server via a specific HTTP POST. |
| T1027.013 Encrypted/Encoded File |
FoggyWeb has been XOR-encoded. |
| T1036 Masquerading |
FoggyWeb can masquerade the output of C2 commands as a fake, but legitimately formatted WebP file. |
| T1036.005 Match Legitimate Resource Name or Location |
FoggyWeb can be disguised as a Visual Studio file such as `Windows.Data.TimeZones.zh-PH.pri` to evade detection. Also, FoggyWeb's loader can mimic a genuine `dll` file that carries out the same import functions as the legitimate Windows `version.dll` file. |
| T1040 Network Sniffing |
FoggyWeb can configure custom listeners to passively monitor all incoming HTTP GET and POST requests sent to the AD FS server from the intranet/internet and intercept HTTP requests that match the custom URI patterns defined by the actor. |
| T1041 Exfiltration Over C2 Channel |
FoggyWeb can remotely exfiltrate sensitive information from a compromised AD FS server. |
| T1057 Process Discovery |
FoggyWeb's loader can enumerate all Common Language Runtimes (CLRs) and running Application Domains in the compromised AD FS server's |
| T1071.001 Web Protocols |
FoggyWeb has the ability to communicate with C2 servers over HTTP GET/POST requests. |
| T1083 File and Directory Discovery |
FoggyWeb's loader can check for the FoggyWeb backdoor .pri file on a compromised AD FS server. |
| T1105 Ingress Tool Transfer |
FoggyWeb can receive additional malicious components from an actor controlled C2 server and execute them on a compromised AD FS server. |
| T1106 Native API |
FoggyWeb's loader can use API functions to load the FoggyWeb backdoor into the same Application Domain within which the legitimate AD FS managed code is executed. |
| T1129 Shared Modules |
FoggyWeb's loader can call the |
| T1140 Deobfuscate/Decode Files or Information |
FoggyWeb can be decrypted in memory using a Lightweight Encryption Algorithm (LEA)-128 key and decoded using a XOR key. |
| T1550 Use Alternate Authentication Material |
FoggyWeb can allow abuse of a compromised AD FS server's SAML token. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.