FORENSIA

ATT&CK · T1025

Data from Removable Media

Tactics: collection

About

Adversaries may search connected removable media on computers they have compromised to find files of interest. Sensitive data can be collected from any removable media (optical disk drive, USB memory, etc.) connected to the compromised system prior to Exfiltration. Interactive command shells may be in use, and common functionality within cmd may be used to gather information. Some adversaries may also use Automated Collection on removable media.

Platforms: Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

4 known groups

Software

20 malware/tools implement this

FLASHFLOODCosmicDukeRoverPrikormkaCrimsonRemsecBADNEWSUSBStealerGravityRATInvisiMoleMacheteAria-bodyRamsayTajMahalCrutchExplosiveAppleSeedObliqueRATFunnyDreamMgBot

Corpus indicators tagged with this technique

17 indicators in the corpus carry T1025.

IndicatorTypeFamilySevSrc
7cef19f9c4480adac0cd4702ff98f46chashphishing803
3715092aa00f380cefe8b4d2eddb7d08hashphishing803
7eb9cee1f696727752169f25cf79a338hashphishing803
b6b0602310bb2d4360c52685119aac1bhashphishing803
https://justsstop.ru/url753
http://www.novel21.co.kr/data/editor/2110/index.phpurlphishing753
121.254.222.80ipphishing702
218.150.78.198ipphishing702
218.150.78.231ipphishing702
165.22.170.129ip702
61.100.9.206ipphishing702
211.239.157.126ipphishing702
novel21.co.krdomainphishing653
www.novel21.co.krdomainphishing653
crwellfood.comdomainphishing653
justsstop.rudomain653
webhostingkorea.comdomainphishing653