ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0059×

78 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupMagic Hound

Magic Hound has stolen domain credentials by dumping LSASS process memory using Task Manager, comsvcs.dll, and from a Microsoft Active Directory Domain Controller using Mimikatz.

T1005
Data from Local System
GroupMagic Hound

Magic Hound has used a web shell to exfiltrate a ZIP file containing a dump of LSASS memory on a compromised machine.

T1016
System Network Configuration Discovery
GroupMagic Hound

Magic Hound malware gathers the victim's local IP address, MAC address, and external IP address.

T1016.001
Internet Connection Discovery
GroupMagic Hound

Magic Hound has conducted a network call out to a specific website as part of their initial discovery activity.

T1016.002
Wi-Fi Discovery
GroupMagic Hound

Magic Hound has collected names and passwords of all Wi-Fi networks to which a device has previously connected.

T1018
Remote System Discovery
GroupMagic Hound

Magic Hound has used Ping for discovery on targeted networks.

T1021.001
Remote Desktop Protocol
GroupMagic Hound

Magic Hound has used Remote Desktop Services to copy tools on targeted systems.

T1027.010
Command Obfuscation
GroupMagic Hound

Magic Hound has used base64-encoded commands.

T1027.013
Encrypted/Encoded File
GroupMagic Hound

Magic Hound malware has used base64-encoded files and has also encrypted embedded strings with AES.

T1033
System Owner/User Discovery
GroupMagic Hound

Magic Hound malware has obtained the victim username and sent it to the C2 server.

T1036.004
Masquerade Task or Service
GroupMagic Hound

Magic Hound has named a malicious script CacheTask.bat to mimic a legitimate task.

T1036.005
Match Legitimate Resource Name or Location
GroupMagic Hound

Magic Hound has used `dllhost.exe` to mask Fast Reverse Proxy (FRP) and `MicrosoftOutLookUpdater.exe` for Plink.

T1036.010
Masquerade Account Name
GroupMagic Hound

Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines.

T1046
Network Service Discovery
GroupMagic Hound

Magic Hound has used KPortScan 3.0 to perform SMB, RDP, and LDAP scanning.

T1047
Windows Management Instrumentation
GroupMagic Hound

Magic Hound has used a tool to run `cmd /c wmic computersystem get domain` for discovery.

T1049
System Network Connections Discovery
GroupMagic Hound

Magic Hound has used quser.exe to identify existing RDP connections.

T1053.005
Scheduled Task
GroupMagic Hound

Magic Hound has used scheduled tasks to establish persistence and execution.

T1056.001
Keylogging
GroupMagic Hound

Magic Hound malware is capable of keylogging.

T1057
Process Discovery
GroupMagic Hound

Magic Hound malware can list running processes.

T1059.001
PowerShell
GroupMagic Hound

Magic Hound has used PowerShell for execution and privilege escalation.

T1059.003
Windows Command Shell
GroupMagic Hound

Magic Hound has used the command-line interface for code execution.

T1059.005
Visual Basic
GroupMagic Hound

Magic Hound malware has used VBS scripts for execution.

T1070.003
Clear Command History
GroupMagic Hound

Magic Hound has removed mailbox export requests from compromised Exchange servers.

T1070.004
File Deletion
GroupMagic Hound

Magic Hound has deleted and overwrote files to cover tracks.

T1071
Application Layer Protocol
GroupMagic Hound

Magic Hound malware has used IRC for C2.

T1071.001
Web Protocols
GroupMagic Hound

Magic Hound has used HTTP for C2.

T1078.001
Default Accounts
GroupMagic Hound

Magic Hound enabled and used the default system managed account, DefaultAccount, via `"powershell.exe" /c net user DefaultAccount /active:yes` to connect to a targeted Exchange server over RDP.

T1078.002
Domain Accounts
GroupMagic Hound

Magic Hound has used domain administrator accounts after dumping LSASS process memory.

T1082
System Information Discovery
GroupMagic Hound

Magic Hound malware has used a PowerShell command to check the victim system architecture to determine if it is an x64 machine. Other malware has obtained the OS version, UUID, and computer/host name to send to the C2 server.

T1083
File and Directory Discovery
GroupMagic Hound

Magic Hound malware can list a victim's logical drives and the type, as well the total/free space of the fixed devices. Other malware can list a directory's contents.

T1087.003
Email Account
GroupMagic Hound

Magic Hound has used Powershell to discover email accounts.

T1090
Proxy
GroupMagic Hound

Magic Hound has used Fast Reverse Proxy (FRP) for RDP traffic.

T1098.002
Additional Email Delegate Permissions
GroupMagic Hound

Magic Hound granted compromised email accounts read access to the email boxes of additional targeted accounts. The group then was able to authenticate to the intended victim's OWA (Outlook Web Access) portal and read hundreds of email communications for information on Middle East organizations.

T1098.007
Additional Local or Domain Groups
GroupMagic Hound

Magic Hound has added a user named DefaultAccount to the Administrators and Remote Desktop Users groups.

T1102.002
Bidirectional Communication
GroupMagic Hound

Magic Hound malware can use a SOAP Web service to communicate with its C2 server.

T1105
Ingress Tool Transfer
GroupMagic Hound

Magic Hound has downloaded additional code and files from servers onto victims.

T1112
Modify Registry
GroupMagic Hound

Magic Hound has modified Registry settings for security tools.

T1113
Screen Capture
GroupMagic Hound

Magic Hound malware can take a screenshot and upload the file to its C2 server.

T1114
Email Collection
GroupMagic Hound

Magic Hound has compromised email credentials in order to steal sensitive data.

T1114.001
Local Email Collection
GroupMagic Hound

Magic Hound has collected .PST archives.

T1114.002
Remote Email Collection
GroupMagic Hound

Magic Hound has exported emails from compromised Exchange servers including through use of the cmdlet `New-MailboxExportRequest.`

T1136.001
Local Account
GroupMagic Hound

Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines.

T1189
Drive-by Compromise
GroupMagic Hound

Magic Hound has conducted watering-hole attacks through media and magazine websites.

T1190
Exploit Public-Facing Application
GroupMagic Hound

Magic Hound has exploited the Log4j utility (CVE-2021-44228), on-premises MS Exchange servers via "ProxyShell" (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), and Fortios SSL VPNs (CVE-2018-13379).

T1204.001
Malicious Link
GroupMagic Hound

Magic Hound has attempted to lure victims into opening malicious links embedded in emails.

T1204.002
Malicious File
GroupMagic Hound

Magic Hound has attempted to lure victims into opening malicious email attachments.

T1218.011
Rundll32
GroupMagic Hound

Magic Hound has used rundll32.exe to execute MiniDump from comsvcs.dll when dumping LSASS memory.

T1482
Domain Trust Discovery
GroupMagic Hound

Magic Hound has used a web shell to execute `nltest /trusted_domains` to identify trust relationships.

T1486
Data Encrypted for Impact
GroupMagic Hound

Magic Hound has used BitLocker and DiskCryptor to encrypt targeted workstations.

T1505.003
Web Shell
GroupMagic Hound

Magic Hound has used multiple web shells to gain execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.