FORENSIA

ATT&CK · T1114.001 · sub-technique

Local Email Collection

Tactics: collection

About

Adversaries may target user email on local systems to collect sensitive information. Files containing email data can be acquired from a user’s local system, such as Outlook storage or cache files. Outlook stores data locally in offline data files with an extension of .ost. Outlook 2010 and later supports .ost file sizes up to 50GB, while earlier versions of Outlook support up to 20GB. IMAP accounts in Outlook 2013 (and earlier) and POP accounts use Outlook Data Files (.pst) as opposed to .ost, whereas IMAP accounts in Outlook 2016 (and later) use .ost files. Both types of Outlook data files are typically stored in `C:\Users\<username>\Documents\Outlook Files` or `C:\Users\<username>\AppData\Local\Microsoft\Outlook`.

Platforms: WindowsParent: T1114 Email CollectionMITRE ATT&CK ↗

Used by actors

8 known groups

Software

11 malware/tools implement this

CarbanakCosmicDukeCrimsonPupySmoke LoaderEmpireEmotetKGH_SPYOut1QakBotLunarMail

Corpus indicators tagged with this technique

32 indicators in the corpus carry T1114.001.

IndicatorTypeFamilySevSrc
308351124c496d4f4effee65ab828506abf70385773c167ab1f32a7f030385achash802
3b6cb20891bce8602ce669187754871e402a1782031ef8b032cd007e3894bc5dhash802
6a69ea2ce3fea0ebfd7a32a1dfc4251bd4d7d8a4fbd44aaa47b82290d0414a9fhash802
6c700ca4e6d917c7aa9d964e98604a0349d9b8b4673df96a3f73a3d2d042635ahash802
d78f64551d1b31a31e5998e442f0debd458e011e05019b3951d9ddde997f8384hash802
44f6101dd8171133f53317bfd752300ehash802
fab69acd743f4111b749e3268690825c38822e62hash802
91e523a46f3bb860ac2e5800b7e1ec89d75a2408410b9cd25eebc17c8d7a92bchash802
99813f3d0625e880158c68039c0e2fbf488db0be3db77cd1ce6d382644193f0ehash802
acf5ed6e5bb90c44683938f35efeca551428064cdedbbaab8be69e3474fb806fhash802
c3405d9c9d593d75d773c0615254e69d0362954384058ee970a3ec0944519c37hash802
cf731b82c471211938b210ae8a6dcc7ece4f44371e716f056fa05151a9910727hash802
d5e42104292513232d26ad7d9d317b5c779577da43e28fe27f8c2fb9318b0e8ehash802
db59813e3f27fb8608a4876e758f60b69d9700dc22d15237ac095bb3166fb622hash802
eaff006ac0eb7f7fe4db5fc6a4b5b1dc272d83ced66d510dcea185b1278bb453hash802
f72a8b71f12eaab6518873f72ea4be4572d9f3fb8e8706ade3b9a7314f236f22hash802
9e5b1e10ad6904d3f5b48d38470cd57263974640a27d13cf793ef026d3d6b886hash802
02048121fd0b3a51751ce7677155aa8818eba9d8ce67ea26fd1d7f43cfcdabd2hash802
1f385acf11f8ea6673d7295be6492ea9913b525da25dcc037ea49ef4f86a9d58hash802
22f335a65c479c26019f6187dae290624117c82a702a96acbb04fa325f730d3ehash802
2587217bc685527480c803ddf34a56ae9d9bf02681828a8a2081acc775312cf3hash802
3aae5a24e63f3cb1ca4759b9e4ee8e503ff139189423f5fd8cc923c6819697cahash802
611db3195d55e871dce67ce5c41e894bbaab88dd0d019af68f5a259f0108aef7hash802
8b283c954d19a839a724961ccaf025c56988c4e745acb2d31a15a006cda072bfhash802
8c0871cd0f60bc603424e948a689945a1828d0bef926a6470ae18cf17d93f7cbhash802
serviceprohub.topdomain652
system-clean.topdomain652
scanseq.topdomain652
updt-scansecurity.topdomain652
info-secure.topdomain652

Showing the top 30 by severity of 32.