FIN10
Associated Group Descriptions |
|
Name | Description |
---|---|
Techniques Used |
||||
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1547 | .001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
FIN10 has established persistence by using the Registry option in PowerShell Empire to add a Run key.(Citation: FireEye FIN10 June 2017)(Citation: Github PowerShell Empire) |
Enterprise | T1059 | .001 | Command and Scripting Interpreter: PowerShell |
FIN10 uses PowerShell for execution as well as PowerShell Empire to establish persistence.(Citation: FireEye FIN10 June 2017)(Citation: Github PowerShell Empire) |
.003 | Command and Scripting Interpreter: Windows Command Shell |
FIN10 has executed malicious .bat files containing PowerShell commands.(Citation: FireEye FIN10 June 2017) |
||
Enterprise | T1070 | .004 | Indicator Removal: File Deletion |
FIN10 has used batch scripts and scheduled tasks to delete critical system files.(Citation: FireEye FIN10 June 2017) |
Enterprise | T1588 | .002 | Obtain Capabilities: Tool |
FIN10 has relied on publicly-available software to gain footholds and establish persistence in victim environments.(Citation: FireEye FIN10 June 2017) |
Enterprise | T1021 | .001 | Remote Services: Remote Desktop Protocol |
FIN10 has used RDP to move laterally to systems in the victim environment.(Citation: FireEye FIN10 June 2017) |
Enterprise | T1053 | .005 | Scheduled Task/Job: Scheduled Task |
FIN10 has established persistence by using S4U tasks as well as the Scheduled Task option in PowerShell Empire.(Citation: FireEye FIN10 June 2017)(Citation: Github PowerShell Empire) |
Enterprise | T1078 | .003 | Valid Accounts: Local Accounts |
FIN10 has moved laterally using the Local Administrator account.(Citation: FireEye FIN10 June 2017) |
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.