FORENSIA

ATT&CK · T1583.006 · sub-technique

Web Services

Tactics: resource-development

About

Adversaries may register for web services that can be used during targeting. A variety of popular websites exist for adversaries to register for a web-based service that can be abused during later stages of the adversary lifecycle, such as during Command and Control (Web Service), Exfiltration Over Web Service, or Phishing. Using common services, such as those offered by Google, GitHub, or Twitter, makes it easier for adversaries to hide in expected noise. By utilizing a web service, adversaries can make it difficult to physically tie back operations to them.

Corpus indicators tagged with this technique

224 indicators in the corpus carry T1583.006.

IndicatorTypeFamilySevSrc
97448688b292bfec6d83b153588076fe59b111c35ac4e42a916238df16a71e2fsha256802
2e5fd01b7949a45937b853eabcf4b03195614cf84338dcaaa97240d1c5301ddcsha256802
1c693bcdaf1da636eb21c274b21cc2f6c52c62ddd514700783eee83fe13acb0asha256802
b7f46b192cd83a1d2487cb048cca645f6e8855b9673d500d50bbdb04eebc6beasha256802
f629311734b7c6e6579f8e1d0e1e3f3bf72c9ac6c301b631ba4df7f393c41b14sha256802
6580de3b74fd635a1d7a887b8f6e5b0c9ac9e90d6e20466ad41489203119cca9sha256802
da4b72764ae929050353f3da759c839e2a061a8b9a8dd3c3b2e909d4a8a3291csha256802
06a2888c1f07119873ccb051221bd8717281494b33585f4242556e6e5e227969sha256802
89934cb1494cf0327f0ab82fe644c74caf687814379cad116bd7adaca74c1028sha256802
c5baa0c16b0074a1e94b48aa0177e9bfc23746aca8a5b42848a6685da85658b5sha256802
63565f15a99769bbcd527a4d53e5cc259d80e1254463ef9c878c2074685558aesha256802
bd6805782df15e53581096b99bd6bbb81f4d4a5e2d2b30954df63175a4075be9sha256802
98825c0c7764f45c891275b2f038ea559e84b340df30b41c2cc77b8d4215c6c8sha256802
49cc0e0c3ec060fb354cacee244d4f297aaefb6db66e67a21262d6c4d2eae1bdsha256802
4fe8bec780537aa223406965415c1f85e83eec1f4e2181cf82e2a7b7516026e6hashphishing801
9f10e3b6e5745784f26d18c38ce01fba054b19749c17260978ac11472564aee2sha256802
1f8daffec5945a13a1e9231f4a76655d4c7ef4560d0c64ca3abfe48f38297cbdsha256802
3f66634f103b80412d1d670b91befab2a74425d2ea76d904c4a7ffae2ae94b44sha256802
8e5546c83d764e1287b55cbe868a45344a6f0afa9782d798d03b2b7cfc53ec38hashphishing801
04ec44f2618460f5c77c5e56014a512cc03a123c9c5b6b6b1273e2a1681ac2e1sha256802
83e970feb3f10692c164f6889f7a026f135c2433e5bf8e662a6e63a3b81267b7sha256802
ff4edf35349eb7af8edc60f01eede469bee54efbsha1781
b77835ab95bd5c25472fa352c5204cf15ab42d09sha1781
9db9b3e55f58553735a25db6702d272cf48495easha1781
29e3cd6c5f1d8a7ad0ce9a4bb5d6e95e6bc33010sha1781
c2d5d410a37d0c51546b1ef4962aff57md5761
ba8600d349779c4ba0ea37da2e109f11md5761
0e5be13d3339b4b2561e5d88127e1bd3md5761
01eb459a28a329aaf6b5fa6fc5acdc7emd5761
25908558764390958596189327204542md5762

Showing the top 30 by severity of 224.