FORENSIA

ATT&CK · T1189

Drive-by Compromise

Tactics: initial-access

About

Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including: * A legitimate website is compromised, allowing adversaries to inject malicious code * Script files served to a legitimate website from a publicly writeable cloud storage bucket are modified by an adversary * Malicious ads are paid for and served through legitimate ad providers (i.e., Malvertising) * Built-in web application interfaces that allow user-controllable content are leveraged for the insertion of malicious scripts or iFrames (e.g., cross-site scripting) Browser push notifications may also be abused by adversaries and leveraged for malicious code injection via User Execution. By clicking "allow" on browser push notifications, users may be granting a website permission to run JavaScript code on their browser. Often the website used by an adversary is one visited by a specific community, such as government, a particular industry, or a particular region, where the goal is to compromise a specific user or set of users based on a shared interest. This kind of targeted campaign is often referred to a strategic web compromise or watering hole attack. There are several known examples of this occurring. Typical drive-by compromise process: 1. A user visits a website that is used to host the adversary controlled content. 2. Scripts automatically execute, typically searching versions of the browser and plugins for a potentially vulnerable version. The user may be required to assist in this process by enabling scripting, notifications, or active website components and ignoring warning dialog boxes. 3. Upon finding a vulnerable version, exploit code is delivered to the browser. 4. If exploitation is successful, the adversary will gain code execution on the user's system unless other protections are in place. In some cases, a second visit to the website after the initial scan is required before exploit code is delivered. Unlike Exploit Public-Facing Application, the focus of this technique is to exploit software on a client endpoint upon visiting a website. This will commonly give an adversary access to systems on the internal network instead of external systems that may be in a DMZ.

Platforms: Identity Provider, Linux, macOS, WindowsMITRE ATT&CK ↗

Corpus indicators tagged with this technique

1,248 indicators in the corpus carry T1189.

IndicatorTypeFamilySevSrc
4482fdd6d9269d3b748233ff4a87e9e2hashransomware802
b659389cde06f5e01e592dca458fe1be07a302c40dc2a820c7f76d4ee788bad3hashransomware802
273962821f14982ead6c10823587fd39e89cf2fchashransomware802
4e4a3751581252e210f6f45881d778d1f482146f92dc790504bfbcd2bdfa0129hashransomware802
42a99a5effdc1d02f6b622537de881e1hashransomware802
72bed9b26a7747252156b65d24a9a737d70b9bf6aca069c514c1c7b9e04ef9b6hashransomware802
6190923b28679eb8230010aff9b1d1a4184e8697540cc021a5be38126f3f6d99hashransomware802
16afa928cd820a572bd47e798f481c46hashransomware802
2528df60e55f210a6396dd7740d76afe30d5e9e8684a5b8a02a63bdcb5041bfchashransomware802
185b7a487316454da04e9cc0fe6eb370bb2955cf6096fe3e8c02c46f8989ba37hashphishing802
b0cfa2089802634ffb8c77962cdb18317a6332d4hashransomware802
7890b116d13a52efe696ce1e2c0ed83029775cf4bea836ce551e71d222ee116fhashransomware802
259fd28f9e66159d5a30b86688fec184hashransomware802
8bd16897409ae5d5667c345276d2532f493c0f98hashransomware802
f0b3e112ce4807a28e2b5d66a840ed7fhashransomware802
16474e9e4773fbc1e0b48a5025fad31b7f084b1beffb9a42687b4d01979885fehashransomware802
442af2726e22f512b49f67bcdbf7c0d1e806aa8bhashransomware802
3e62797fd746ce9bd5d49cb833b7d9ac62d6b7a2hashransomware802
b0e292346b4ab3f83fadd8abcce7cfc5b9d50ef73ad141e8bc4a4689fee13504hashransomware802
f8cbe44fde6914bc8d06426c03c92ed536c891470292e567a586b54af29c2442hash802
3a8f6454927b8993aded75de0de2bd00hashphishing802
4650f7dc1a2ddbb6d73bf5bfd1b69dd6b79e0cddhashphishing802
54a6743781fd4ceb720331fce92f16186931192dhashransomware802
edbf152ed9ac79e5d9e0111d1071af48hashransomware802
64a0ab00d90682b1807c5d7da1a4ae67cde4c5757fc7d995d8f126f0ec8ae983hashransomware802
43f4ca1c7474c0476a42d937dc4af01c8ccfc20331baa0465ac0f3408f52b2e2hashransomware802
f962e15c6efebb3c29fe399bb168066042b616affddd83f72570c979184ec55chashransomware802
28a9982cf2b4fc53a1545b6ed0d0c1788ca9369a847750f5652ffa0ca7f7b7d3hashransomware802
2b2e657ae1bc2fdcdfe5201a8e0e5224hashransomware802
e6bff27adbbcfe6b71ac8fad79b8297fhashransomware802

Showing the top 30 by severity of 1,248.