ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0010×

68 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupTurla

Turla RPC backdoors can upload files from victim machines.

T1007
System Service Discovery
GroupTurla

Turla surveys a system upon check-in to discover running services and associated processes using the tasklist /svc command.

T1012
Query Registry
GroupTurla

Turla surveys a system upon check-in to discover information in the Windows Registry with the reg query command. Turla has also retrieved PowerShell payloads hidden in Registry keys as well as checking keys associated with null session named pipes .

T1016
System Network Configuration Discovery
GroupTurla

Turla surveys a system upon check-in to discover network configuration details using the arp -a, nbtstat -n, net config, ipconfig /all, and route commands, as well as NBTscan. Turla RPC backdoors have also retrieved registered RPC interface information from process memory.

T1016.001
Internet Connection Discovery
GroupTurla

Turla has used tracert to check internet connectivity.

T1018
Remote System Discovery
GroupTurla

Turla surveys a system upon check-in to discover remote systems on a local network using the net view and net view /DOMAIN commands. Turla has also used net group "Domain Computers" /domain, net group "Domain Controllers" /domain, and net group "Exchange Servers" /domain to enumerate domain computers, including the organization's DC and Exchange Server.

T1021.002
SMB/Windows Admin Shares
GroupTurla

Turla used net use commands to connect to lateral systems within a network.

T1025
Data from Removable Media
GroupTurla

Turla RPC backdoors can collect files from USB thumb drives.

T1027.005
Indicator Removal from Tools
GroupTurla

Based on comparison of Gazer versions, Turla made an effort to obfuscate strings in the malware that could be used as IoCs, including the mutex name and named pipe.

T1027.010
Command Obfuscation
GroupTurla

Turla has used encryption (including salted 3DES via PowerSploit's Out-EncryptedScript.ps1), random variable names, and base64 encoding to obfuscate PowerShell commands and payloads.

T1027.011
Fileless Storage
GroupTurla

Turla has used the Registry to store encrypted and encoded payloads.

T1036.005
Match Legitimate Resource Name or Location
GroupTurla

Turla has named components of LunarWeb to mimic Zabbix agent logs.

T1049
System Network Connections Discovery
GroupTurla

Turla surveys a system upon check-in to discover active local network connections using the netstat -an, net use, net file, and net session commands. Turla RPC backdoors have also enumerated the IPv4 TCP connection table via the GetTcpTable2 API call.

T1055
Process Injection
GroupTurla

Turla has also used PowerSploit's Invoke-ReflectivePEInjection.ps1 to reflectively load a PowerShell payload into a random process on the victim system.

T1055.001
Dynamic-link Library Injection
GroupTurla

Turla has used Metasploit to perform reflective DLL injection in order to escalate privileges.

T1057
Process Discovery
GroupTurla

Turla surveys a system upon check-in to discover running processes using the tasklist /v command. Turla RPC backdoors have also enumerated processes associated with specific open ports or named pipes.

T1059.001
PowerShell
GroupTurla

Turla has used PowerShell to execute commands/scripts, in some cases via a custom executable or code from Empire's PSInject. Turla has also used PowerShell scripts to load and execute malware in memory.

T1059.003
Windows Command Shell
GroupTurla

Turla RPC backdoors have used cmd.exe to execute commands.

T1059.005
Visual Basic
GroupTurla

Turla has used VBS scripts throughout its operations.

T1059.006
Python
GroupTurla

Turla has used IronPython scripts as part of the IronNetInjector toolchain to drop payloads.

T1059.007
JavaScript
GroupTurla

Turla has used various JavaScript-based backdoors.

T1068
Exploitation for Privilege Escalation
GroupTurla

Turla has exploited vulnerabilities in the VBoxDrv.sys driver to obtain kernel mode privileges.

T1069.001
Local Groups
GroupTurla

Turla has used net localgroup and net localgroup Administrators to enumerate group information, including members of the local administrators group.

T1069.002
Domain Groups
GroupTurla

Turla has used net group "Domain Admins" /domain to identify domain administrators.

T1071.001
Web Protocols
GroupTurla

Turla has used HTTP and HTTPS for C2 communications.

T1071.003
Mail Protocols
GroupTurla

Turla has used multiple backdoors which communicate with a C2 server via email attachments.

T1078.003
Local Accounts
GroupTurla

Turla has abused local accounts that have the same password across the victim’s network.

T1082
System Information Discovery
GroupTurla

Turla surveys a system upon check-in to discover operating system configuration details using the systeminfo and set commands.

T1083
File and Directory Discovery
GroupTurla

Turla surveys a system upon check-in to discover files in specific locations on the hard disk %TEMP% directory, the current user's desktop, the Program Files directory, and Recent. Turla RPC backdoors have also searched for files matching the lPH*.dll pattern.

T1087.001
Local Account
GroupTurla

Turla has used net user to enumerate local accounts on the system.

T1087.002
Domain Account
GroupTurla

Turla has used net user /domain to enumerate domain accounts.

T1090
Proxy
GroupTurla

Turla RPC backdoors have included local UPnP RPC proxies.

T1090.001
Internal Proxy
GroupTurla

Turla has compromised internal network systems to act as a proxy to forward traffic to C2.

T1102
Web Service
GroupTurla

Turla has used legitimate web services including Pastebin, Dropbox, and GitHub for C2 communications.

T1102.002
Bidirectional Communication
GroupTurla

A Turla JavaScript backdoor has used Google Apps Script as its C2 server.

T1105
Ingress Tool Transfer
GroupTurla

Turla has used shellcode to download Meterpreter after compromising a victim.

T1106
Native API
GroupTurla

Turla and its RPC backdoors have used APIs calls for various tasks related to subverting AMSI and accessing then executing commands through RPC and/or named pipes.

T1110
Brute Force
GroupTurla

Turla may attempt to connect to systems within a victim's network using net use commands and a predefined list or collection of passwords.

T1112
Modify Registry
GroupTurla

Turla has modified Registry values to store payloads.

T1120
Peripheral Device Discovery
GroupTurla

Turla has used fsutil fsinfo drives to list connected drives.

T1124
System Time Discovery
GroupTurla

Turla surveys a system upon check-in to discover the system time by using the net time command.

T1134.002
Create Process with Token
GroupTurla

Turla RPC backdoors can impersonate or steal process tokens before executing commands.

T1140
Deobfuscate/Decode Files or Information
GroupTurla

Turla has used a custom decryption routine, which pulls key and salt values from other artifacts such as a WMI filter or PowerShell Profile, to decode encrypted PowerShell payloads.

T1189
Drive-by Compromise
GroupTurla

Turla has infected victims using watering holes.

T1201
Password Policy Discovery
GroupTurla

Turla has used net accounts and net accounts /domain to acquire password policy information.

T1204.001
Malicious Link
GroupTurla

Turla has used spearphishing via a link to get users to download and run their malware.

T1213.006
Databases
GroupTurla

Turla has used a custom .NET tool to collect documents from an organization's internal central database.

T1518.001
Security Software Discovery
GroupTurla

Turla has obtained information on security software, including security logging information that may indicate whether their malware has been detected.

T1546.003
Windows Management Instrumentation Event Subscription
GroupTurla

Turla has used WMI event filters and consumers to establish persistence.

T1546.013
PowerShell Profile
GroupTurla

Turla has used PowerShell profiles to maintain persistence on an infected machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.