FORENSIA

ATT&CK · T1048

Exfiltration Over Alternative Protocol

Tactics: exfiltration

About

Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server. Alternate protocols include FTP, SMTP, HTTP/S, DNS, SMB, or any other network protocol not being used as the main command and control channel. Adversaries may also opt to encrypt and/or obfuscate these alternate channels. Exfiltration Over Alternative Protocol can be done using various common operating system utilities such as Net/SMB or FTP. On macOS and Linux <code>curl</code> may be used to invoke protocols such as HTTP/S or FTP/S to exfiltrate data from a system. Many IaaS and SaaS platforms (such as Microsoft Exchange, Microsoft SharePoint, GitHub, and AWS S3) support the direct download of files, emails, source code, and other sensitive information via the web console or Cloud API.

Platforms: ESXi, IaaS, Linux, macOS, Network Devices, Office Suite, SaaS, WindowsMITRE ATT&CK ↗

Used by actors

2 known groups

Software

7 malware/tools implement this

HydraqPoetRATBundloreFrameworkPOSChaesKobalosAADInternals

Corpus indicators tagged with this technique

33 indicators in the corpus carry T1048.

IndicatorTypeFamilySevSrc
24b9ee242f21a73b55f7bb3297eafb33c60840907386b542ed79fc6b72365168sha256supply_chain802
082d733db0687dcd768104972b065d4b58cb1e6043688c6c20fa3702337f36absha256supply_chain803
b9993a8ad0518849416798cf29668256ccb96598fc4423501ccab5312812653asha256supply_chain802
bfaeb987faa6de2b5a5eb63b1233d055215b09b0349a9394f2175fd7cdf385e4sha256supply_chain803
6e78713b75bd34828d49896176627f7face7aa9036cd874f2e02d9f23a9a9c71sha256supply_chain802
9b2e65db653ca8575c9b10eefb9a80c6006404812c2ec212bf5675e3c690233bsha256supply_chain803
d425e4583cc6185d41e95c45eda00550045a5d1919b9a012236a4520d009dbd7sha256supply_chain803
34014776d3d3ff11bc4439b02fd7ac0f02a887eb3a052eeafff236e2f6db8ad1sha256supply_chain803
b270bdf8e2274ea1af0a6eed74d8f10e5fe61012d6cc226a43cc7cc7fd9f6292sha256supply_chain802
9f1a709310824f9110c6203d861a721ebefba8b204a8657057fe57efb961c850sha256supply_chain801
8351d251cf0b5a0bd82242deaa0a14e3e1394418d55c0f4259dac4303b79fc0csha256supply_chain803
9e214f38537e69bf51c7fa1ddd35ae495e9cb897231ec010baf9e4f29407ee9asha256supply_chain801
550af477c12192a22f5c9edb9c8081c0a789b3a1a2992a7ecb157cca1c975e10sha256supply_chain801
3eab3ec9304aa26081358330491d3cfeb55cc245sha1supply_chain781
http://85.137.53.71:8080/api/v1/file-content/urlsupply_chain751
http://lnstagram.com/wlsperrrrr/url752
https://ethereum-rpc.publicnode.comurlsupply_chain751
http://85.137.53.71:8080/api/v1/beaconurlsupply_chain751
http://85.137.53.71:8080/api/v1/file-resulturlsupply_chain751
172.86.75.235ip701
203.237.119.147ip702
45.225.135.54ip702
miscrsosoft.comdomain652
ebsummlt.eudomain652
msget.rundomain651
justicehomeland.infodomain652
justicehomeland.orgdomain652
handala-hack.twdomain652
handala.reddomain652
justicehomeland.rudomain652

Showing the top 30 by severity of 33.