ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0121×

30 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupSidewinder

Sidewinder has used malware to collect information on network interfaces, including the MAC address.

T1020
Automated Exfiltration
GroupSidewinder

Sidewinder has configured tools to automatically send collected files to attacker controlled servers.

T1027.010
Command Obfuscation
GroupSidewinder

Sidewinder has used base64 encoding for scripts.

T1027.013
Encrypted/Encoded File
GroupSidewinder

Sidewinder has used base64 encoding and ECDH-P256 encryption for payloads.

T1033
System Owner/User Discovery
GroupSidewinder

Sidewinder has used tools to identify the user of a compromised host.

T1036.005
Match Legitimate Resource Name or Location
GroupSidewinder

Sidewinder has named malicious files rekeywiz.exe to match the name of a legitimate Windows executable.

T1057
Process Discovery
GroupSidewinder

Sidewinder has used tools to identify running processes on the victim's machine.

T1059.001
PowerShell
GroupSidewinder

Sidewinder has used PowerShell to drop and execute malware loaders.

T1059.005
Visual Basic
GroupSidewinder

Sidewinder has used VBScript to drop and execute malware loaders.

T1059.007
JavaScript
GroupSidewinder

Sidewinder has used JavaScript to drop and execute malware loaders.

T1071.001
Web Protocols
GroupSidewinder

Sidewinder has used HTTP in C2 communications.

T1074.001
Local Data Staging
GroupSidewinder

Sidewinder has collected stolen files in a temporary folder in preparation for exfiltration.

T1082
System Information Discovery
GroupSidewinder

Sidewinder has used tools to collect the computer name, OS version, installed hotfixes, as well as information regarding the memory and processor on a compromised host.

T1083
File and Directory Discovery
GroupSidewinder

Sidewinder has used malware to collect information on files and directories.

T1105
Ingress Tool Transfer
GroupSidewinder

Sidewinder has used LNK files to download remote files to the victim's network.

T1119
Automated Collection
GroupSidewinder

Sidewinder has used tools to automatically collect system and network configuration information.

T1124
System Time Discovery
GroupSidewinder

Sidewinder has used tools to obtain the current system time.

T1203
Exploitation for Client Execution
GroupSidewinder

Sidewinder has exploited vulnerabilities to gain execution including CVE-2017-11882 and CVE-2020-0674.

T1204.001
Malicious Link
GroupSidewinder

Sidewinder has lured targets to click on malicious links to gain execution in the target environment.

T1204.002
Malicious File
GroupSidewinder

Sidewinder has lured targets to click on malicious files to gain execution in the target environment.

T1218.005
Mshta
GroupSidewinder

Sidewinder has used mshta.exe to execute malicious payloads.

T1518
Software Discovery
GroupSidewinder

Sidewinder has used tools to enumerate software installed on an infected host.

T1518.001
Security Software Discovery
GroupSidewinder

Sidewinder has used the Windows service winmgmts:\\.\root\SecurityCenter2 to check installed antivirus products.

T1547.001
Registry Run Keys / Startup Folder
GroupSidewinder

Sidewinder has added paths to executables in the Registry to establish persistence.

T1559.002
Dynamic Data Exchange
GroupSidewinder

Sidewinder has used the ActiveXObject utility to create OLE objects to obtain execution through Internet Explorer.

T1566.001
Spearphishing Attachment
GroupSidewinder

Sidewinder has sent e-mails with malicious attachments often crafted for specific targets.

T1566.002
Spearphishing Link
GroupSidewinder

Sidewinder has sent e-mails with malicious links often crafted for specific targets.

T1574.001
DLL
GroupSidewinder

Sidewinder has used DLL side-loading to drop and execute malicious payloads including the hijacking of the legitimate Windows application file rekeywiz.exe.

T1598.002
Spearphishing Attachment
GroupSidewinder

Sidewinder has sent e-mails with malicious attachments that lead victims to credential harvesting websites.

T1598.003
Spearphishing Link
GroupSidewinder

Sidewinder has sent e-mails with malicious links to credential harvesting websites.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.