Real-world descriptions of how a group, tool or campaign used a technique.
26 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
GroupWIRTE | WIRTE has XOR encrypted command line strings to conceal malware execution chains. |
| T1027.015 Compression |
GroupWIRTE | WIRTE has compressed malicious files within RAR and ZIP archives for obfuscation. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupWIRTE | WIRTE has used security service provider naming conventions such as ESET and Kasperky ("Kaspersky Update Agent") in order to appear legitimate. |
| T1041 Exfiltration Over C2 Channel |
GroupWIRTE | WIRTE has exfiltrated collected victim data to C2 infrastructure. |
| T1059.001 PowerShell |
GroupWIRTE | WIRTE has used PowerShell for script execution. |
| T1059.003 Windows Command Shell |
GroupWIRTE | WIRTE has used the Windows command line as part of infection chains to open documents. |
| T1059.005 Visual Basic |
GroupWIRTE | WIRTE has used VBScript in its operations. |
| T1071.001 Web Protocols |
GroupWIRTE | WIRTE has used HTTP for network communication. |
| T1074.001 Local Data Staging |
GroupWIRTE | WIRTE has staged collected documents of interest in `C:\Users\Public folder`. |
| T1105 Ingress Tool Transfer |
GroupWIRTE | WIRTE has downloaded PowerShell code from the C2 server to be executed. |
| T1106 Native API |
GroupWIRTE | WIRTE has used the `RtlIpv4StringToAddressA` to convert IP-formatted string to a byte array. |
| T1114.001 Local Email Collection |
GroupWIRTE | WIRTE has collected documents from victims' email accounts. |
| T1140 Deobfuscate/Decode Files or Information |
GroupWIRTE | WIRTE has used Base64 to decode malicious VBS script. |
| T1204.001 Malicious Link |
GroupWIRTE | WIRTE has used links embedded in emails to lure users into downloading malicious files. |
| T1204.002 Malicious File |
GroupWIRTE | WIRTE has attempted to lure users into opening malicious documents including MS Word and Excel files, at times using a decoy document to encourage execution of malicious payloads. |
| T1218.010 Regsvr32 |
GroupWIRTE | WIRTE has used `regsvr32.exe` to trigger the execution of a malicious script. |
| T1497.001 System Checks |
GroupWIRTE | WIRTE has configured C2 servers to check location and user-agent strings for victim endpoints to prevent sending a payload to sandboxed environments. |
| T1566.001 Spearphishing Attachment |
GroupWIRTE | WIRTE has sent emails to intended victims with malicious MS Word and Excel attachments. |
| T1566.002 Spearphishing Link |
GroupWIRTE | WIRTE has sent targeted spearphishing emails with malicious links directing victims to malware downloads. |
| T1571 Non-Standard Port |
GroupWIRTE | WIRTE has used HTTPS over ports 2083 and 2087 for C2. |
| T1574.001 DLL |
GroupWIRTE | WIRTE has used RAR archives containing a legitimate executable and a lure document to execute malicious DLLs via sideloading. |
| T1583.001 Domains |
GroupWIRTE | WIRTE has registered domains designed to mimic legitimate sites for use in phishing campaigns. |
| T1586.002 Email Accounts |
GroupWIRTE | WIRTE has used compromised emails, including one belonging to an Israel-based technology reseller, to deliver targeted spearphishing messages. |
| T1588.002 Tool |
GroupWIRTE | WIRTE has obtained and used Empire and Rclone for post-exploitation activities. |
| T1608.001 Upload Malware |
GroupWIRTE | WIRTE has directed victims to malicious payloads staged on file sharing services. |
| T1684.001 Impersonation |
GroupWIRTE | WIRTE has used utilized look-alike domains and graphics of trusted security solution providers to entice victims to click on phishing links. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.