ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0106×

36 examples

TechniqueUsed byProcedure example
T1014
Rootkit
GroupRocke

Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists.

T1018
Remote System Discovery
GroupRocke

Rocke has looked for IP addresses in the known_hosts file on the infected system and attempted to SSH into them.

T1021.004
SSH
GroupRocke

Rocke has spread its coinminer via SSH.

T1027
Obfuscated Files or Information
GroupRocke

Rocke has modified UPX headers after packing files to break unpackers.

T1027.002
Software Packing
GroupRocke

Rocke's miner has created UPX-packed files in the Windows Start Menu Folder.

T1027.004
Compile After Delivery
GroupRocke

Rocke has compiled malware, delivered to victims as .c files, with the GNU Compiler Collection (GCC).

T1036.005
Match Legitimate Resource Name or Location
GroupRocke

Rocke has used shell scripts which download mining executables and saves them with the filename "java".

T1037
Boot or Logon Initialization Scripts
GroupRocke

Rocke has installed an "init.d" startup script to maintain persistence.

T1046
Network Service Discovery
GroupRocke

Rocke conducted scanning for exposed TCP port 7001 as well as SSH and Redis servers.

T1053.003
Cron
GroupRocke

Rocke installed a cron job that downloaded and executed files from the C2.

T1055.002
Portable Executable Injection
GroupRocke

Rocke's miner, "TermsHost.exe", evaded defenses by injecting itself into Windows processes, including Notepad.exe.

T1057
Process Discovery
GroupRocke

Rocke can detect a running process's PID on the infected machine.

T1059.004
Unix Shell
GroupRocke

Rocke used shell scripts to run commands which would obtain persistence and execute the cryptocurrency mining malware.

T1059.006
Python
GroupRocke

Rocke has used Python-based malware to install and spread their coinminer.

T1070.004
File Deletion
GroupRocke

Rocke has deleted files on infected machines.

T1070.006
Timestomp
GroupRocke

Rocke has changed the time stamp of certain files.

T1071
Application Layer Protocol
GroupRocke

Rocke issued wget requests from infected systems to the C2.

T1071.001
Web Protocols
GroupRocke

Rocke has executed wget and curl commands to Pastebin over the HTTPS protocol.

T1082
System Information Discovery
GroupRocke

Rocke has used uname -m to collect the name and information about the infected system's kernel.

T1102
Web Service
GroupRocke

Rocke has used Pastebin, Gitee, and GitLab for Command and Control.

T1102.001
Dead Drop Resolver
GroupRocke

Rocke has used Pastebin to check the version of beaconing malware and redirect to another Pastebin hosting updated malware.

T1105
Ingress Tool Transfer
GroupRocke

Rocke used malware to download additional malicious files to the target system.

T1140
Deobfuscate/Decode Files or Information
GroupRocke

Rocke has extracted tar.gz files after downloading them from a C2 server.

T1190
Exploit Public-Facing Application
GroupRocke

Rocke exploited Apache Struts, Oracle WebLogic (CVE-2017-10271), and Adobe ColdFusion (CVE-2017-3066) vulnerabilities to deliver malware.

T1222.002
Linux and Mac Permissions
GroupRocke

Rocke has changed file permissions of files so they could not be modified.

T1496.001
Compute Hijacking
GroupRocke

Rocke has distributed cryptomining malware.

T1518.001
Security Software Discovery
GroupRocke

Rocke used scripts which detected and uninstalled antivirus software.

T1543.002
Systemd Service
GroupRocke

Rocke has installed a systemd service script to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupRocke

Rocke's miner has created UPX-packed files in the Windows Start Menu Folder.

T1552.004
Private Keys
GroupRocke

Rocke has used SSH private keys on the infected machine to spread its coinminer throughout a network.

T1564.001
Hidden Files and Directories
GroupRocke

Rocke downloaded a file "libprocesshider", which could hide files on the target system.

T1571
Non-Standard Port
GroupRocke

Rocke's miner connects to a C2 server using port 51640.

T1574.006
Dynamic Linker Hijacking
GroupRocke

Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists.

T1685
Disable or Modify Tools
GroupRocke

Rocke used scripts which detected and uninstalled antivirus software.

T1685.006
Clear Linux or Mac System Logs
GroupRocke

Rocke has cleared log files within the /var/log/ folder.

T1686
Disable or Modify System Firewall
GroupRocke

Rocke used scripts which killed processes and added firewall rules to block traffic related to other cryptominers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.