APT29
|
Step
|
ATT&CK Pattern
|
Detection Type |
Detection Note |
|
2.B.1
|
|
|
Minimum detection criteria was not met for this procedure.
|
|
9.B.8
|
|
|
Minimum detection criteria was not met for this procedure.
|
|
Read and downloaded ZIP (Draft.zip) over C2 channel (192.168.0.5 over TCP port 1234)
The rcs.3aka3.doc process reading the file draft.zip while connected to the C2 channel
Read and downloaded ZIP (working.zip on Desktop) over C2 channel (192.168.0.5 over TCP port 8443)
python.exe reading the file working.zip while connected to the C2 channel