FORENSIA

ATT&CK · T1010

Application Window Discovery

Tactics: discovery

About

Adversaries may attempt to get a listing of open application windows. Window listings could convey information about how the system is used. For example, information about application windows could be used identify potential data to collect as well as identifying security tooling (Security Software Discovery) to evade. Adversaries typically abuse system features for this type of enumeration. For example, they may gather information through native system features such as Command and Scripting Interpreter commands and Native API functions.

Platforms: Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

3 known groups

Software

34 malware/tools implement this

PoisonIvyNetTravelerDuquTrojan.KaraganyPowerDukeSOUNDBITENETWIREWINERACKROKRATInvisiMoleCatchamasQuasarRATKazuarRemcosRemexinjRATMacheteHotCroissantPLEADAttorCadelspyMetamorfoAria-bodyGrandoreiroQakBotDarkWatchmanSILENTTRINITYFlagproFunnyDreamNightClubDarkGateDUSTTRAPPAKLOGTONESHELL

Corpus indicators tagged with this technique

47 indicators in the corpus carry T1010.

IndicatorTypeFamilySevSrc
19ca5fe04ca45a18c5bad9658ff73a8f39fe20ced78f690595f1b4c5a90af324sha256phishing802
34d1231a3bf1e13a9b90daecb5c74d52aea94ca54427b203d77e1adc61a5c4f9sha256phishing802
4a040770fd81d0db9e04cb8dbd2e07e61969072962bb4e736b7c7001444cc2fasha256phishing802
5e97f7c17bf0466355be0438c7cc3e2e4d125e31368f2fbcb8e1d79cb97f137asha256phishing802
7e142c8fa614cc39d0453aa648b12209821c6bcbb77ee02094f70161b40d50aesha256phishing802
a8614dfad5fd2a79302a7c4829a0fed6f3a0a46b11beb28f89531cdfa83d32b3sha256phishing802
c6651d6ce31c3a00357e579981d48c0da942b5bbe1582bf3d612a07dc3bc0ff6sha256phishing802
6c774188a54ae07ae896abdf1ea6695cc29f529388888665e05322af3e9178e1sha256phishing802
589aa1f7252cae74538343cd35443c0a8f58ed280f2016918b6e539a0c09529asha256phishing802
2f2f8f92af86fb962c30c4c1c9d673f9d94886373d0fcf78f8d105c051ffc643sha256phishing802
44f6101dd8171133f53317bfd752300ehash802
fab69acd743f4111b749e3268690825c38822e62hash802
91e523a46f3bb860ac2e5800b7e1ec89d75a2408410b9cd25eebc17c8d7a92bchash802
99813f3d0625e880158c68039c0e2fbf488db0be3db77cd1ce6d382644193f0ehash802
fc17d5b4d64cb61a5aa8fb6bbe1e94885f129b2bf8ee91bca1ccca2b537f6616sha256phishing802
eccff5c026a01cbe91db45cd0289f8822985aa5183f096d8add69762696d100dsha256phishing802
ec5d4103b3d97885e9575ad045b2ef5467bf9fccf71828e418e6488d78983146sha256phishing802
c6fc06db6a1318152c09200352b40c8fa794f1089988835c1df92174347be8ecsha256phishing802
b0fcd7d9396e70b89e8292f6b80f933607b6fc9a9d3d4dd4ca69b408a2625932sha256phishing802
9e5b1e10ad6904d3f5b48d38470cd57263974640a27d13cf793ef026d3d6b886hash802
8ed95259300ca268279867d2999d9c4f6585c6c45308635fc39af87da27546b5sha256phishing802
5a00485968679dc0ed6d80b659f48287603864c223e952918d2c2aaddfa2d280sha256phishing802
ac2eeef05f568ad36bdcd807159313862a84387dsha1phishing782
5260ac8e82c1280950425bb12ddfb5435ff20539sha1phishing782
7d06bac0114e4c1e9a300d6310a29cf92956c933sha1phishing782
b26c01dfcc0cdcb30f4a9058f880fb80md5phishing762
7ec462f138432f4da43d942488d3d428md5phishing762
dda082a12bb43eb34b9b37bf9e62d5f0md5phishing762
http://govtop.one/incometaxurlphishing752
204.194.48.250ipphishing703

Showing the top 30 by severity of 47.