ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0112×

19 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
GroupWindshift

Windshift has used string encoding with floating point calculations.

T1033
System Owner/User Discovery
GroupWindshift

Windshift has used malware to identify the username on a compromised host.

T1036
Masquerading
GroupWindshift

Windshift has used icons mimicking MS Office files to mask malicious executables. Windshift has also attempted to hide executables by changing the file extension to ".scr" to mimic Windows screensavers.

T1036.001
Invalid Code Signature
GroupWindshift

Windshift has used revoked certificates to sign malware.

T1047
Windows Management Instrumentation
GroupWindshift

Windshift has used WMI to collect information about target machines.

T1057
Process Discovery
GroupWindshift

Windshift has used malware to enumerate active processes.

T1059.005
Visual Basic
GroupWindshift

Windshift has used Visual Basic 6 (VB6) payloads.

T1071.001
Web Protocols
GroupWindshift

Windshift has used tools that communicate with C2 over HTTP.

T1082
System Information Discovery
GroupWindshift

Windshift has used malware to identify the computer name of a compromised host.

T1105
Ingress Tool Transfer
GroupWindshift

Windshift has used tools to deploy additional payloads to compromised hosts.

T1189
Drive-by Compromise
GroupWindshift

Windshift has used compromised websites to register custom URL schemes on a remote system.

T1204.001
Malicious Link
GroupWindshift

Windshift has used links embedded in e-mails to lure victims into executing malicious code.

T1204.002
Malicious File
GroupWindshift

Windshift has used e-mail attachments to lure victims into executing malicious code.

T1518
Software Discovery
GroupWindshift

Windshift has used malware to identify installed software.

T1518.001
Security Software Discovery
GroupWindshift

Windshift has used malware to identify installed AV and commonly used forensic and malware analysis tools.

T1547.001
Registry Run Keys / Startup Folder
GroupWindshift

Windshift has created LNK files in the Startup folder to establish persistence.

T1566.001
Spearphishing Attachment
GroupWindshift

Windshift has sent spearphishing emails with attachment to harvest credentials and deliver malware.

T1566.002
Spearphishing Link
GroupWindshift

Windshift has sent spearphishing emails with links to harvest credentials and deliver malware.

T1566.003
Spearphishing via Service
GroupWindshift

Windshift has used fake personas on social media to engage and target victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.