ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0045×

46 examples

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
GroupmenuPass

menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials.

T1003.003
NTDS
GroupmenuPass

menuPass has used Ntdsutil to dump credentials.

T1003.004
LSA Secrets
GroupmenuPass

menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials.

T1005
Data from Local System
GroupmenuPass

menuPass has collected various files from the compromised computers.

T1016
System Network Configuration Discovery
GroupmenuPass

menuPass has used several tools to scan for open NetBIOS nameservers and enumerate NetBIOS sessions.

T1018
Remote System Discovery
GroupmenuPass

menuPass uses scripts to enumerate IP ranges on the victim network. menuPass has also issued the command net view /domain to a PlugX implant to gather information about remote systems on the network.

T1021.001
Remote Desktop Protocol
GroupmenuPass

menuPass has used RDP connections to move across the victim network.

T1021.004
SSH
GroupmenuPass

menuPass has used Putty Secure Copy Client (PSCP) to transfer data.

T1027.013
Encrypted/Encoded File
GroupmenuPass

menuPass has encoded strings in its malware with base64 as well as with a simple, single-byte XOR obfuscation using key 0x40.

T1036
Masquerading
GroupmenuPass

menuPass has used esentutl to change file extensions to their true type that were masquerading as .txt files.

T1036.003
Rename Legitimate Utilities
GroupmenuPass

menuPass has renamed certutil and moved it to a different location on the system to avoid detection based on use of the tool.

T1036.005
Match Legitimate Resource Name or Location
GroupmenuPass

menuPass has been seen changing malicious files to appear legitimate.

T1039
Data from Network Shared Drive
GroupmenuPass

menuPass has collected data from remote systems by mounting network shares with net use and using Robocopy to transfer data.

T1046
Network Service Discovery
GroupmenuPass

menuPass has used tcping.exe, similar to Ping, to probe port status on systems of interest.

T1047
Windows Management Instrumentation
GroupmenuPass

menuPass has used a modified version of pentesting script wmiexec.vbs, which logs into a remote machine using WMI.

T1049
System Network Connections Discovery
GroupmenuPass

menuPass has used net use to conduct connectivity checks to machines.

T1053.005
Scheduled Task
GroupmenuPass

menuPass has used a script (atexec.py) to execute a command on a target machine via Task Scheduler.

T1055.012
Process Hollowing
GroupmenuPass

menuPass has used process hollowing in iexplore.exe to load the RedLeaves implant.

T1056.001
Keylogging
GroupmenuPass

menuPass has used key loggers to steal usernames and passwords.

T1059.001
PowerShell
GroupmenuPass

menuPass uses PowerSploit to inject shellcode into PowerShell.

T1059.003
Windows Command Shell
GroupmenuPass

menuPass executes commands using a command-line interface and reverse shell. The group has used a modified version of pentesting script wmiexec.vbs to execute commands. menuPass has used malicious macros embedded inside Office documents to execute files.

T1070.003
Clear Command History
GroupmenuPass

menuPass has used Wevtutil to remove PowerShell execution logs.

T1070.004
File Deletion
GroupmenuPass

A menuPass macro deletes files after it has decoded and decompressed them.

T1074.001
Local Data Staging
GroupmenuPass

menuPass stages data prior to exfiltration in multi-part archives, often saved in the Recycle Bin.

T1074.002
Remote Data Staging
GroupmenuPass

menuPass has staged data on remote MSP systems or other victim networks prior to exfiltration.

T1078
Valid Accounts
GroupmenuPass

menuPass has used valid accounts including shared between Managed Service Providers and clients to move between the two environments.

T1083
File and Directory Discovery
GroupmenuPass

menuPass has searched compromised systems for folders of interest including those related to HR, audit and expense, and meeting memos.

T1087.002
Domain Account
GroupmenuPass

menuPass has used the Microsoft administration tool csvde.exe to export Active Directory data.

T1090.002
External Proxy
GroupmenuPass

menuPass has used a global service provider's IP as a proxy for C2 traffic from a victim.

T1105
Ingress Tool Transfer
GroupmenuPass

menuPass has installed updates and new malware on victims.

T1106
Native API
GroupmenuPass

menuPass has used native APIs including GetModuleFileName, lstrcat, CreateFile, and ReadFile.

T1119
Automated Collection
GroupmenuPass

menuPass has used the Csvde tool to collect Active Directory files and data.

T1140
Deobfuscate/Decode Files or Information
GroupmenuPass

menuPass has used certutil in a macro to decode base64-encoded content contained in a dropper document attached to an email. The group has also used certutil -decode to decode files on the victim’s machine when dropping UPPERCUT.

T1190
Exploit Public-Facing Application
GroupmenuPass

menuPass has leveraged vulnerabilities in Pulse Secure VPNs to hijack sessions.

T1199
Trusted Relationship
GroupmenuPass

menuPass has used legitimate access granted to Managed Service Providers in order to access victims of interest.

T1204.002
Malicious File
GroupmenuPass

menuPass has attempted to get victims to open malicious files such as Windows Shortcuts (.lnk) and/or Microsoft Office documents, sent via email as part of spearphishing campaigns.

T1210
Exploitation of Remote Services
GroupmenuPass

menuPass has used tools to exploit the ZeroLogon vulnerability (CVE-2020-1472).

T1218.004
InstallUtil
GroupmenuPass

menuPass has used InstallUtil.exe to execute malicious software.

T1553.002
Code Signing
GroupmenuPass

menuPass has resized and added data to the certificate table to enable the signing of modified files with legitimate signatures.

T1560
Archive Collected Data
GroupmenuPass

menuPass has encrypted files and information before exfiltration.

T1560.001
Archive via Utility
GroupmenuPass

menuPass has compressed files before exfiltration using TAR and RAR.

T1566.001
Spearphishing Attachment
GroupmenuPass

menuPass has sent malicious Office documents via email as part of spearphishing campaigns as well as executables disguised as documents.

T1568.001
Fast Flux DNS
GroupmenuPass

menuPass has used dynamic DNS service providers to host malicious domains.

T1574.001
DLL
GroupmenuPass

menuPass has used DLL side-loading to launch versions of Mimikatz and PwDump6 as well as UPPERCUT. menuPass has also used DLL search order hijacking.

T1583.001
Domains
GroupmenuPass

menuPass has registered malicious domains for use in intrusion campaigns.

T1588.002
Tool
GroupmenuPass

menuPass has used and modified open-source tools like Impacket, Mimikatz, and pwdump.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.