FORENSIA

ATT&CK · T1102

Web Service

Tactics: command-and-control

About

Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites, cloud services, and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google, Microsoft, or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection. Use of Web services may also protect back-end C2 infrastructure from discovery through malware binary analysis while also enabling operational resiliency (since this infrastructure may be dynamically changed).

Platforms: ESXi, Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

15 known groups

Software

30 malware/tools implement this

NETWIRECarbonngrokBazarSharpStageDropBookGuLoaderSibotDokiHildegardBoomBoxSMOKEDHAMCharmPowerWhisperGateBumblebeeBrute Ratel C4DarkTortillaBADHATCHSnip3SocGholishRaspberry RobinNightdoorCHIMNEYSWEEPLatrodectusShrinkLockerMOPSLEDRedLine StealerBRICKSTORMPureCrypterAshTag

Corpus indicators tagged with this technique

623 indicators in the corpus carry T1102.

IndicatorTypeFamilySevSrc
a7981dfccd8e4bdc00133dc15b22472c1677d6270826863caa36e7d58ef50de0sha256phishing801
a2c6e01001c62f6198e31a9d603977c6hash802
6c700ca4e6d917c7aa9d964e98604a0349d9b8b4673df96a3f73a3d2d042635ahash802
18683bba19695d325372d195634afd2f76b14896ba68225ba51ea5a039f2f76dsha256phishing802
f8cbe44fde6914bc8d06426c03c92ed536c891470292e567a586b54af29c2442hash802
a8bee6c4a5860b0ae08a984d2a6d62c13d3e91d9514262998924d2e0cef88f7csha256phishing801
50ebf107d522326c9a9db8821fe3263aa5136964faaf5dd183657bbb52725f84sha256phishing802
669002654c264191d4660fbf757860d930175649735f81370b9f1af3658a304csha256phishing802
62a879b0d1c1649cc72b2b6f61a8f6bd888625ce6e8a7aefe0a0461e4f27c525sha256phishing802
6a69ea2ce3fea0ebfd7a32a1dfc4251bd4d7d8a4fbd44aaa47b82290d0414a9fhash802
a4c8a56070fe6f613e79a14554d0a1dba2f70ce2b93319e72972943cc66edf4asha256phishing801
d78f64551d1b31a31e5998e442f0debd458e011e05019b3951d9ddde997f8384hash802
1b25c3d56fdb195b427a9c3bfc1f0e98e77a15322e8d3fc53a18edcc4891847fsha256phishing802
1aaf59f05bb724d501cc9bcd6642ab8fd7347cf274d46c24719c9dced9b22beasha256phishing802
22de84e8f29cba932cf65cf4dc1d333cb8b2e468204f97030712bee32691ac3bsha256phishing802
44a4ac119349f525d877728b53fe38453a516881d577679caf08ab69312a695fsha256phishing802
5115277eabf2d22d49dcef1e155874387d8e783853bd86debf7ff58588aae35dsha256phishing802
5272917261d7091a59e00f9d09cd7eb1d3e111115a5b367f79a66d0d7c7b01f4sha256phishing802
23b37d2ebe683cec3b145b6f2234ee728b99228cf3774399fcfad9502daab9a9sha256phishing802
5ab41cf20315d2ea1385967d588159873a65ef5581a0b78de06c0d8617894194sha256phishing802
43d597783af656a35184021f5e20686896463a1712f9216e0217a2ca740e3935sha256phishing802
60972abf5425c191c81bae117f1dedaea13d39bc52f367d5dff9ad1aa4b9c5casha256phishing802
248ded4723e9f5da793e5e42d1ba7c2293dd704718f149b84b3b9b818a1f51dbsha256phishing802
771a47120b935e218322046e838347d722d265b91f1afdef91194a5bec86a97asha256phishing802
7900c2772680523cadc9fe4e07300d45500191ba64ff5b91573531b133840b14sha256phishing802
7aa76237a7686583cc526b9d1a8486a52bd44a448d75ced51e1df4ba29ddb163sha256phishing802
7b297f18ece81e87608e158288cc9c06cb9f4a8f1b2d2256aecf7bba8d7be2absha256phishing802
3b6cb20891bce8602ce669187754871e402a1782031ef8b032cd007e3894bc5dhash802
308351124c496d4f4effee65ab828506abf70385773c167ab1f32a7f030385achash802
a9287e3452ab09144120ecdd20ed7365de589d5dcad28dcd8e191742d1ce5744sha256phishing801

Showing the top 30 by severity of 623.