FORENSIA

ATT&CK · T1560.001 · sub-technique

Archive via Utility

Tactics: collection

About

Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, encrypt, or otherwise package data into a format that is easier/more secure to transport. Adversaries may abuse various utilities to compress or encrypt data before exfiltration. Some third party utilities may be preinstalled, such as <code>tar</code> on Linux and macOS or <code>zip</code> on Windows systems. On Windows, <code>diantz</code> or <code> makecab</code> may be used to package collected files into a cabinet (.cab) file. <code>diantz</code> may also be used to download and compress files from remote locations (i.e. Remote Data Staging). <code>xcopy</code> on Windows can copy files and directories with a variety of options. Additionally, adversaries may use certutil to Base64 encode collected data before exfiltration. Adversaries may use also third party utilities, such as 7-Zip, WinRAR, and WinZip, to perform similar activities.

Platforms: Linux, macOS, WindowsParent: T1560 Archive Collected DataMITRE ATT&CK ↗

Corpus indicators tagged with this technique

145 indicators in the corpus carry T1560.001.

IndicatorTypeFamilySevSrc
449e4265979b5fdb2d3446c021af437e815debd66de7da2fe54f1ad93cbcc75ehashsupply_chain801
00cc86d1144020c24c8fbb3a8dc6b908926497ebd23be3bf854360f93d1c8f4csha256supply_chain801
ebcf977806f68af3147e0b78b55f6aedhash802
131877a052f62750d815cf55d4c14f606a26025e3094e1b8bb18bd1668e3beaahashransomware801
00e09754526d0fe836ba27e3144ae161b0ecd3774abec5560504a16a67f0087csha256802
9b481b69cd91b09fa7bae7428f646dd89473a4c03393e43da81fe756cde1c472sha256802
d3fd32f915c239872c9e7ed9408b1f36dfcef03aa68f9a396d05c437667cdb43sha256802
dce5df29bddff5a4ddaea5c4fec14da91f7b69063a6e1c45ed61e5da4fc6c87bsha256802
1a2ca8b8e0344fe3d80da7352206a470245443e2349a237bc093df934ddc011fsha256802
cc19e502e4201cc974c753b96429027925224f53hash802
96097e0612d9575cb133021017fb1a5c68a03b60f9f3d24ebdc0e628d9034144hashsupply_chain801
c2f4dc64aec4631540a568e88932b61daebbfb7e8281b812fa01b7215f9be9eahashsupply_chain801
cbfe8de6ffadbb1d396f61e63eb18e8b11c29527c1528641e3223d4c516cf7c3sha256802
4e1f8888d020decd09799ec946f1bf677cac6612b24582ddbf4d8ede425d8384sha256802
99813f3d0625e880158c68039c0e2fbf488db0be3db77cd1ce6d382644193f0ehash802
7b7981c99d59595fe15377df84695bb72ce0b85560a3935f930657b2d162e5efsha256phishing801
f04f43b6f7c2d86109c495179b497f7fb45fd95816623de1b77900f71b4f99edsha256802
9e5b1e10ad6904d3f5b48d38470cd57263974640a27d13cf793ef026d3d6b886hash802
78a82d93b4f580835f5823b85a3d9ee1f03a15ee6f0e01b4eac86252a7002981hashsupply_chain801
adcd15f3d6b87f84d106ea426fa824fd20c9d64f6d199ce92580884290785f30sha256phishing801
1682e8d82016b3f10434d2ebac995fd3b6aa812f079bfd7888652e94a994d851sha256802
e316b1e13154dc6115e1e0c023f6fe3d17861cae839d4a4a81779b6aad9a24f8sha256802
d7d2f0ee187549f3f4a114d716be12521fbf62d6d26e2ac23d2a32d521d08fd8sha256phishing801
b287347a5bff8af360ce0e6500c336b6fe6d97920abc26202c9d843ffebc5f89sha256802
44f6101dd8171133f53317bfd752300ehash802
bf9d8c0c3ed3ceaa831a13de27f1b1c7c7b7f01d2db4103bfdba4191940b0301hashsupply_chain801
fab69acd743f4111b749e3268690825c38822e62hash802
f34bd1d485de437fe18360d1e850c3fd64415e49d691e610711d8d232071a0b1sha256802
91e523a46f3bb860ac2e5800b7e1ec89d75a2408410b9cd25eebc17c8d7a92bchash802
f4a72600a3735c2a4d843875ea61bbb6f935a1af51a81f2fbc992ce11ba94afcsha256supply_chain801

Showing the top 30 by severity of 145.