ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0090×

26 examples

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
GroupWIRTE

WIRTE has XOR encrypted command line strings to conceal malware execution chains.

T1027.015
Compression
GroupWIRTE

WIRTE has compressed malicious files within RAR and ZIP archives for obfuscation.

T1036.005
Match Legitimate Resource Name or Location
GroupWIRTE

WIRTE has used security service provider naming conventions such as ESET and Kasperky ("Kaspersky Update Agent") in order to appear legitimate.

T1041
Exfiltration Over C2 Channel
GroupWIRTE

WIRTE has exfiltrated collected victim data to C2 infrastructure.

T1059.001
PowerShell
GroupWIRTE

WIRTE has used PowerShell for script execution.

T1059.003
Windows Command Shell
GroupWIRTE

WIRTE has used the Windows command line as part of infection chains to open documents.

T1059.005
Visual Basic
GroupWIRTE

WIRTE has used VBScript in its operations.

T1071.001
Web Protocols
GroupWIRTE

WIRTE has used HTTP for network communication.

T1074.001
Local Data Staging
GroupWIRTE

WIRTE has staged collected documents of interest in `C:\Users\Public folder`.

T1105
Ingress Tool Transfer
GroupWIRTE

WIRTE has downloaded PowerShell code from the C2 server to be executed.

T1106
Native API
GroupWIRTE

WIRTE has used the `RtlIpv4StringToAddressA` to convert IP-formatted string to a byte array.

T1114.001
Local Email Collection
GroupWIRTE

WIRTE has collected documents from victims' email accounts.

T1140
Deobfuscate/Decode Files or Information
GroupWIRTE

WIRTE has used Base64 to decode malicious VBS script.

T1204.001
Malicious Link
GroupWIRTE

WIRTE has used links embedded in emails to lure users into downloading malicious files.

T1204.002
Malicious File
GroupWIRTE

WIRTE has attempted to lure users into opening malicious documents including MS Word and Excel files, at times using a decoy document to encourage execution of malicious payloads.

T1218.010
Regsvr32
GroupWIRTE

WIRTE has used `regsvr32.exe` to trigger the execution of a malicious script.

T1497.001
System Checks
GroupWIRTE

WIRTE has configured C2 servers to check location and user-agent strings for victim endpoints to prevent sending a payload to sandboxed environments.

T1566.001
Spearphishing Attachment
GroupWIRTE

WIRTE has sent emails to intended victims with malicious MS Word and Excel attachments.

T1566.002
Spearphishing Link
GroupWIRTE

WIRTE has sent targeted spearphishing emails with malicious links directing victims to malware downloads.

T1571
Non-Standard Port
GroupWIRTE

WIRTE has used HTTPS over ports 2083 and 2087 for C2.

T1574.001
DLL
GroupWIRTE

WIRTE has used RAR archives containing a legitimate executable and a lure document to execute malicious DLLs via sideloading.

T1583.001
Domains
GroupWIRTE

WIRTE has registered domains designed to mimic legitimate sites for use in phishing campaigns.

T1586.002
Email Accounts
GroupWIRTE

WIRTE has used compromised emails, including one belonging to an Israel-based technology reseller, to deliver targeted spearphishing messages.

T1588.002
Tool
GroupWIRTE

WIRTE has obtained and used Empire and Rclone for post-exploitation activities.

T1608.001
Upload Malware
GroupWIRTE

WIRTE has directed victims to malicious payloads staged on file sharing services.

T1684.001
Impersonation
GroupWIRTE

WIRTE has used utilized look-alike domains and graphics of trusted security solution providers to entice victims to click on phishing links.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.