FORENSIA

ATT&CK · T1560

Archive Collected Data

Tactics: collection

About

An adversary may compress and/or encrypt data that is collected prior to exfiltration. Compressing the data can help to obfuscate the collected data and minimize the amount of data sent over the network. Encryption can be used to hide information that is being exfiltrated from detection or make exfiltration less conspicuous upon inspection by a defender. Both compression and encryption are done prior to exfiltration, and can be performed using a utility, 3rd party library, or custom method.

Platforms: Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

13 known groups

Software

43 malware/tools implement this

LuridADVSTORESHELLEpicBackdoor.OldreaPrikormkaDaserfNETWIREGold DragonZebrocyRunningRATVERMINFELIXROOTProtonAgent TeslaExaramel for WindowsKONNIEmpireRemexiLightNeuronMacheteShimRatReporterCadelspyAria-bodyKesselWellMailPillowmintBloodHoundDtrackTAINTEDSCRIBEAppleSeedBLUELIGHTXCSSETChrommmeLizarPowerLessBumblebeeLoFiSeSpicaRaccoon StealerTroll StealerJumbledPathMuddyViperLP-Notes

Corpus indicators tagged with this technique

51 indicators in the corpus carry T1560.

IndicatorTypeFamilySevSrc
8a5dadc5faf424df1e8a0efad023df81hash801
a2421f7fd4be6b12382150033507af7aa8bf6241hash802
fc586cad94e5a10dd5be6a6ae6096bd02dfbfd094365bec87e788ed0798d6f67hashcryptojacking804
59868381885b33f6c8809cd3d945da7d167439a3hashcryptojacking804
ded08ae5df7f1b12e5fdb767dbbed0b1hashcryptojacking804
4eebc38297a307d18784d6f9ebc8aa6e6f69860be970cc70d9e544deb1ff6ce0hash801
74bb6ad7e1310f30a3e24fd3cbbffa2c0c41c64e89e5d0dd1d6900e96b914183hash801
f4d4b8cac004bb63834c6df436721babd9464c09787c80b268d839e0aada9f87hash801
c133c3dd9f7d6934598025047df41abfhashcryptojacking804
47854deb456cb08c651b7f9ae2f9d87c72d0719de6af233340632efb3c1980f4sha256phishing801
f57e010541fb4ccbf23aefc4a827f753a6ff3f8792d9c04c3eea83f6963c6baesha256phishing801
95856f2ce428c728d9781d3296558068hashcryptojacking804
8c2cc585ad8a13a72a704c0fda0c9854hashcryptojacking804
74414ed4b63aadec039b603c32762b80hashcryptojacking804
18dedc0009f0927cba6425c84cce9883hashcryptojacking804
e5f6d9d405819e6b05b5d8268a2e973294859ad65237ede36ab612b536d0ac2bhash801
5620f01284329f561b1839a36be55355hashcryptojacking804
7709d8c34d490509f3624104611eb75a862944dd9d7a642f44514ada16c85ee9hash801
8bfa2df2110c38dff2359a416ce14693hash802
22d051c9cc458012b98e9bdca501759ehash802
442e0f4e822842922e7e4685840194e99fd68c7f0ec38c1925914b8f724d5865hash801
4a1a6ed11fd50b621659d7976899d050ba2e15d3hash801
5144bf4e32c5832c426ad3da55d45f026f66bc95hash802
523388567630e4fbdc359f75232bf2ad82671a680d4bfdce0237fc30dfec4c80hash801
7d415612a00d99617bd89670e1570c145863ad08sha1phishing781
ee577f1880397a00480b210fcd6bc84d2330a19esha1phishing781
eabd440c996846d0992e37ab01d01208md5phishing761
6cc3c68c56e099792fdeadde76256d56md5phishing761
e5c9bb3938f2a24e755ee39073fc3acamd5phishing761
https://avipstudios.com/contacturl752

Showing the top 30 by severity of 51.