FORENSIA

ATT&CK · T1204.003 · sub-technique

Malicious Image

Tactics: execution

About

Adversaries may rely on a user running a malicious image to facilitate execution. Amazon Web Services (AWS) Amazon Machine Images (AMIs), Google Cloud Platform (GCP) Images, and Azure Images as well as popular container runtimes such as Docker can be backdoored. Backdoored images may be uploaded to a public repository via Upload Malware, and users may then download and deploy an instance or container from the image without realizing the image is malicious, thus bypassing techniques that specifically achieve Initial Access. This can lead to the execution of malicious code, such as code that executes cryptocurrency mining, in the instance or container. Adversaries may also name images a certain way to increase the chance of users mistakenly deploying an instance or container from the image (ex: Match Legitimate Resource Name or Location).

Platforms: IaaS, ContainersParent: T1204 User ExecutionMITRE ATT&CK ↗

Used by actors

1 known groups

Software

0 malware/tools implement this

None mapped.

Corpus indicators tagged with this technique

56 indicators in the corpus carry T1204.003.

IndicatorTypeFamilySevSrc
09c121225fe254676a27c21943506714hashphishing802
33760b2aa86deea5805e647197c34ef5hashphishing802
9abebe5a34eefb80db12bf8d51bfe7f7hashphishing802
3a87cab1e8c6868a7939eb422f1851ecc746405cda6b3d3502b9d8eedc360898hashphishing802
5f7bb80bf85c1fae7413eb534cc2f022402c8753f75666525adb1dc85a677f4chashphishing802
cf94ff2ecc4f3157704c9cfed5e446c405e7729141019045cb05ef6ffad122d5hashphishing802
d3beab2e2252a13d5689e9911c2b2b2fc3a41086hash801
deb4b5841eea43cb8c5777ee33ee09bf294a670dhash801
e1ec76a0e1f48901566d53828c34b5dchash801
ea690c3acfa6592c601e4b5dd6122805063bac53hash801
83b7a106a5e810a1781e62b278909396hash801
1fc0a876a121882ffaad6677f444cf5bhash801
86db2530298e6335d3ecc66c2818cfbd0a6b11fcdfcb75f575b9fcce1faa00f1hash801
f79d05065a2ba7937b8781e69b5859d78d5f65f01fb291ae27d28277a5e37f9bhash801
ab6677fcbbb1ff4a22cc3e7355e1c36768ba30bbf5cce36f4ec7ae99f850e6c5hash801
b1b2f1e36dcaa36bc587fda1ddc3cbb8e04c3df5f1e3f1341c9d2ec0b0b0ffafhash801
b31f62e1d3b28808daad3ec5efa5df54ae56898dhashphishing802
https://amazonattention.com/verifyurlphishing752
http://45.207.216.55:8084/slturl751
http://103.177.110.202/bot_x64.exeurl751
https://amazonalert.xyz/download/code.txturlphishing752
https://loserrq0j1sha8.com/debug/loader.sh?build=a39427f9d5bfda11277f1a58c89b7c2durl752
185.193.127.44ipphishing701
debank.auctiondomaindependency_confusion651
identity-breach-response.orgdomaindependency_confusion651
market-insight-global.comdomaindependency_confusion651
py-lib-repository.devdomaindependency_confusion651
visual-media-rights-group.orgdomaindependency_confusion651
permits.global-transit-authority.orgdomaindependency_confusion651
20claude.aidomain652

Showing the top 30 by severity of 56.