Real-world descriptions of how a group, tool or campaign used a technique.
36 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1014 Rootkit |
GroupRocke | Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists. |
| T1018 Remote System Discovery |
GroupRocke | Rocke has looked for IP addresses in the known_hosts file on the infected system and attempted to SSH into them. |
| T1021.004 SSH |
GroupRocke | Rocke has spread its coinminer via SSH. |
| T1027 Obfuscated Files or Information |
GroupRocke | Rocke has modified UPX headers after packing files to break unpackers. |
| T1027.002 Software Packing |
GroupRocke | Rocke's miner has created UPX-packed files in the Windows Start Menu Folder. |
| T1027.004 Compile After Delivery |
GroupRocke | Rocke has compiled malware, delivered to victims as .c files, with the GNU Compiler Collection (GCC). |
| T1036.005 Match Legitimate Resource Name or Location |
GroupRocke | Rocke has used shell scripts which download mining executables and saves them with the filename "java". |
| T1037 Boot or Logon Initialization Scripts |
GroupRocke | Rocke has installed an "init.d" startup script to maintain persistence. |
| T1046 Network Service Discovery |
GroupRocke | Rocke conducted scanning for exposed TCP port 7001 as well as SSH and Redis servers. |
| T1053.003 Cron |
GroupRocke | Rocke installed a cron job that downloaded and executed files from the C2. |
| T1055.002 Portable Executable Injection |
GroupRocke | Rocke's miner, "TermsHost.exe", evaded defenses by injecting itself into Windows processes, including Notepad.exe. |
| T1057 Process Discovery |
GroupRocke | Rocke can detect a running process's PID on the infected machine. |
| T1059.004 Unix Shell |
GroupRocke | Rocke used shell scripts to run commands which would obtain persistence and execute the cryptocurrency mining malware. |
| T1059.006 Python |
GroupRocke | Rocke has used Python-based malware to install and spread their coinminer. |
| T1070.004 File Deletion |
GroupRocke | Rocke has deleted files on infected machines. |
| T1070.006 Timestomp |
GroupRocke | Rocke has changed the time stamp of certain files. |
| T1071 Application Layer Protocol |
GroupRocke | Rocke issued wget requests from infected systems to the C2. |
| T1071.001 Web Protocols |
GroupRocke | Rocke has executed wget and curl commands to Pastebin over the HTTPS protocol. |
| T1082 System Information Discovery |
GroupRocke | Rocke has used uname -m to collect the name and information about the infected system's kernel. |
| T1102 Web Service |
GroupRocke | Rocke has used Pastebin, Gitee, and GitLab for Command and Control. |
| T1102.001 Dead Drop Resolver |
GroupRocke | Rocke has used Pastebin to check the version of beaconing malware and redirect to another Pastebin hosting updated malware. |
| T1105 Ingress Tool Transfer |
GroupRocke | Rocke used malware to download additional malicious files to the target system. |
| T1140 Deobfuscate/Decode Files or Information |
GroupRocke | Rocke has extracted tar.gz files after downloading them from a C2 server. |
| T1190 Exploit Public-Facing Application |
GroupRocke | Rocke exploited Apache Struts, Oracle WebLogic (CVE-2017-10271), and Adobe ColdFusion (CVE-2017-3066) vulnerabilities to deliver malware. |
| T1222.002 Linux and Mac Permissions |
GroupRocke | Rocke has changed file permissions of files so they could not be modified. |
| T1496.001 Compute Hijacking |
GroupRocke | Rocke has distributed cryptomining malware. |
| T1518.001 Security Software Discovery |
GroupRocke | Rocke used scripts which detected and uninstalled antivirus software. |
| T1543.002 Systemd Service |
GroupRocke | Rocke has installed a systemd service script to maintain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupRocke | Rocke's miner has created UPX-packed files in the Windows Start Menu Folder. |
| T1552.004 Private Keys |
GroupRocke | Rocke has used SSH private keys on the infected machine to spread its coinminer throughout a network. |
| T1564.001 Hidden Files and Directories |
GroupRocke | Rocke downloaded a file "libprocesshider", which could hide files on the target system. |
| T1571 Non-Standard Port |
GroupRocke | Rocke's miner connects to a C2 server using port 51640. |
| T1574.006 Dynamic Linker Hijacking |
GroupRocke | Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists. |
| T1685 Disable or Modify Tools |
GroupRocke | Rocke used scripts which detected and uninstalled antivirus software. |
| T1685.006 Clear Linux or Mac System Logs |
GroupRocke | Rocke has cleared log files within the /var/log/ folder. |
| T1686 Disable or Modify System Firewall |
GroupRocke | Rocke used scripts which killed processes and added firewall rules to block traffic related to other cryptominers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.