ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0092×

34 examples

TechniqueUsed byProcedure example
T1027.002
Software Packing
GroupTA505

TA505 has used UPX to obscure malicious code.

T1027.010
Command Obfuscation
GroupTA505

TA505 has used base64 encoded PowerShell commands.

T1027.013
Encrypted/Encoded File
GroupTA505

TA505 has password-protected malicious Word documents.

T1055.001
Dynamic-link Library Injection
GroupTA505

TA505 has been seen injecting a DLL into winword.exe.

T1059.001
PowerShell
GroupTA505

TA505 has used PowerShell to download and execute malware and reconnaissance scripts.

T1059.003
Windows Command Shell
GroupTA505

TA505 has executed commands using cmd.exe.

T1059.005
Visual Basic
GroupTA505

TA505 has used VBS for code execution.

T1059.007
JavaScript
GroupTA505

TA505 has used JavaScript for code execution.

T1069
Permission Groups Discovery
GroupTA505

TA505 has used TinyMet to enumerate members of privileged groups. TA505 has also run net group /domain.

T1071.001
Web Protocols
GroupTA505

TA505 has used HTTP to communicate with C2 nodes.

T1078.002
Domain Accounts
GroupTA505

TA505 has used stolen domain admin accounts to compromise additional hosts.

T1087.003
Email Account
GroupTA505

TA505 has used the tool EmailStealer to steal and send lists of e-mail addresses to a remote server.

T1105
Ingress Tool Transfer
GroupTA505

TA505 has downloaded additional malware to execute on victim systems.

T1106
Native API
GroupTA505

TA505 has deployed payloads that use Windows API calls on a compromised host.

T1112
Modify Registry
GroupTA505

TA505 has used malware to disable Windows Defender through modification of the Registry.

T1140
Deobfuscate/Decode Files or Information
GroupTA505

TA505 has decrypted packed DLLs with an XOR key.

T1204.001
Malicious Link
GroupTA505

TA505 has used lures to get users to click links in emails and attachments. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files.

T1204.002
Malicious File
GroupTA505

TA505 has used lures to get users to enable content in malicious attachments and execute malicious files contained in archives. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files.

T1218.007
Msiexec
GroupTA505

TA505 has used msiexec to download and execute malicious Windows Installer files.

T1218.011
Rundll32
GroupTA505

TA505 has leveraged rundll32.exe to execute malicious DLLs.

T1486
Data Encrypted for Impact
GroupTA505

TA505 has used a wide variety of ransomware, such as Clop, Locky, Jaff, Bart, Philadelphia, and GlobeImposter, to encrypt victim files and demand a ransom payment.

T1552.001
Credentials In Files
GroupTA505

TA505 has used malware to gather credentials from FTP clients and Outlook.

T1553.002
Code Signing
GroupTA505

TA505 has signed payloads with code signing certificates from Thawte and Sectigo.

T1553.005
Mark-of-the-Web Bypass
GroupTA505

TA505 has used .iso files to deploy malicious .lnk files.

T1555.003
Credentials from Web Browsers
GroupTA505

TA505 has used malware to gather credentials from Internet Explorer.

T1559.002
Dynamic Data Exchange
GroupTA505

TA505 has leveraged malicious Word documents that abused DDE.

T1566.001
Spearphishing Attachment
GroupTA505

TA505 has used spearphishing emails with malicious attachments to initially compromise victims.

T1566.002
Spearphishing Link
GroupTA505

TA505 has sent spearphishing emails containing malicious links.

T1568.001
Fast Flux DNS
GroupTA505

TA505 has used fast flux to mask botnets by distributing payloads across multiple IPs.

T1583.001
Domains
GroupTA505

TA505 has registered domains to impersonate services such as Dropbox to distribute malware.

T1588.001
Malware
GroupTA505

TA505 has used malware such as Azorult and Cobalt Strike in their operations.

T1588.002
Tool
GroupTA505

TA505 has used a variety of tools in their operations, including AdFind, BloodHound, Mimikatz, and PowerSploit.

T1608.001
Upload Malware
GroupTA505

TA505 has staged malware on actor-controlled domains.

T1685
Disable or Modify Tools
GroupTA505

TA505 has used malware to disable Windows Defender.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.