| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1036 | .005 | 伪装: Match Legitimate Name or Location | |
| Enterprise | T1573 | .002 | 加密通道: Asymmetric Cryptography |
Doki has used the embedTLS library for network communications.[1] |
| Enterprise | T1568 | .002 | 动态解析: Domain Generation Algorithms |
Doki has used the DynDNS service and a DGA based on the Dogecoin blockchain to generate C2 domains.[1] |
| Enterprise | T1059 | .004 | 命令与脚本解释器: Unix Shell | |
| Enterprise | T1133 | 外部远程服务 |
Doki was executed through an open Docker daemon API port.[1] |
|
| Enterprise | T1071 | .001 | 应用层协议: Web Protocols | |
| Enterprise | T1083 | 文件和目录发现 |
Doki has resolved the path of a process PID to use as a script argument.[1] |
|
| Enterprise | T1102 | 网络服务 |
Doki has used the dogechain.info API to generate a C2 address.[1] |
|
| Enterprise | T1020 | 自动化渗出 |
Doki has used a script that gathers information from a hardcoded list of IP addresses and uploads to an Ngrok URL.[1] |
|
| Enterprise | T1105 | 输入工具传输 | ||
| Enterprise | T1057 | 进程发现 | ||
| Enterprise | T1611 | 逃逸至主机 |
Doki’s container was configured to bind the host root directory.[1] |
|
| Enterprise | T1041 | 通过C2信道渗出 | ||
| Enterprise | T1610 | 部署容器 | ||