FORENSIA

ATT&CK · T1204

User Execution

Tactics: execution

About

An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from forms of Phishing. While User Execution frequently occurs shortly after Initial Access it may occur at other phases of an intrusion, such as when an adversary places a file in a shared directory or on a user's desktop hoping that a user will click on it. This activity may also be seen shortly after Internal Spearphishing. Adversaries may also deceive users into performing actions such as: * Enabling Remote Access Tools, allowing direct control of the system to the adversary * Running malicious JavaScript in their browser, allowing adversaries to Steal Web Session Cookies * Downloading and executing malware for User Execution * Coerceing users to copy, paste, and execute malicious code manually For example, tech support scams can be facilitated through Phishing, vishing, or various forms of user interaction. Adversaries can use a combination of these methods, such as spoofing and promoting toll-free numbers or call centers that are used to direct victims to malicious websites, to deliver and execute payloads containing malware or Remote Access Tools.

Platforms: Linux, Windows, macOS, IaaS, ContainersMITRE ATT&CK ↗

Used by actors

2 known groups

Software

2 malware/tools implement this

Raspberry RobinLumma Stealer

Corpus indicators tagged with this technique

1,167 indicators in the corpus carry T1204.

IndicatorTypeFamilySevSrc
a08d8e63b0cd3638fb40b8e6da546e26da69439597565827f9cec87915f78568sha256ransomware801
87480b151e465b73151220533c965f3a77046138f079ca3ceb961a7d5fee9a33hash801
a14bed1c46ba7406d5240e979251ccd394dfe3b5hashcryptojacking802
3d1158884fb339b3328bd330fcc27598e1f1c94bcac39e75d1a272afa4deee1asha256ransomware801
a40ee8ff313e59aa92d48592c494a4c3d81449afhash802
b0e292346b4ab3f83fadd8abcce7cfc5b9d50ef73ad141e8bc4a4689fee13504hashransomware802
c5a53c02d531c5e46f9cc2fc0afbb88dhashcryptojacking802
89930bd18e0f9c9c98dfb1662cb87aa98348e87164ab62b1f39e86ebf2ce24cbhashcryptojacking802
e84b1e2c432b2394c403b524b8361ffa9923a022eb05215f1dc811bc167c3c5ehashcryptojacking802
d35695f2366a43628231e73ffa83ca106306a8fahash802
b6a77b7892ef22d6afd91eb980a3f3d8hashcryptojacking802
ce62d1b6116f34f9ba815db1e2016d2ahashcryptojacking802
69315b7a1c4bf5ee56cba1de29d1761ehashcryptojacking802
c2eb1033bc01ab0fd732a7ba4967be02c0690bf0hash802
93b3d3925ccc201ab0f16017153a79ef05b8f5c2hashcryptojacking802
b5da6ffa5f85aa5016fbc02a3122361c85d21192c45df9544099d13e6ff84c36hashcryptojacking802
462af0a3a9094d44c30cc65544ec1171a62365cff09e67f5e87e061a3d604bd0hashcryptojacking802
579a82dde4425d95e20a22171be0a37702c833fdca6e5e04f69099a025863136hashcryptojacking802
bd46890121106b43f0c01ab82629400chashcryptojacking802
d42aecf76fb1531cd5b7139e669910b2fd82a90b7e11448128e226775bf5d42ehashcryptojacking802
7105caa6d4fd8a2c67523d385277528e556ae4f6hash802
82e579bd49d69845133c9aa8585f8bd26736437bhash802
41f581f7d2c09ab0edfea850b9db506fhashcryptojacking802
5d253cc263851ec68c0a988bf86afbb3e9f0b491hashcryptojacking802
f96bcd875836da89800912de1e557891697c7cf4hash802
50eda29bfbeeb8b0429718447725016ahashcryptojacking802
fe0161fb8a26a0bf4afad746c7ebf89499dcd3a7hash802
1fc5e6458316277fae8272cbe9f3dfc86b681635hashcryptojacking802
a37f6403fbf28fa0b48863287f4c5a5dhashcryptojacking802
b371fbdce6935039218d4b4272db3521881c9cec48ef82dec1e9e0188a32d3adhash801

Showing the top 30 by severity of 1,167.