Real-world descriptions of how a group, tool or campaign used a technique.
28 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
GroupHigaisa | Higaisa used a FakeTLS session for C2 communications. |
| T1016 System Network Configuration Discovery |
GroupHigaisa | Higaisa used |
| T1027.001 Binary Padding |
GroupHigaisa | Higaisa performed padding with null bytes before calculating its hash. |
| T1027.013 Encrypted/Encoded File |
GroupHigaisa | Higaisa used Base64 encoded compressed payloads. |
| T1027.015 Compression |
GroupHigaisa | Higaisa used Base64 encoded compressed payloads. |
| T1029 Scheduled Transfer |
GroupHigaisa | Higaisa sent the victim computer identifier in a User-Agent string back to the C2 server every 10 minutes. |
| T1036.004 Masquerade Task or Service |
GroupHigaisa | Higaisa named a shellcode loader binary |
| T1041 Exfiltration Over C2 Channel |
GroupHigaisa | Higaisa exfiltrated data over its C2 channel. |
| T1053.005 Scheduled Task |
GroupHigaisa | Higaisa dropped and added |
| T1057 Process Discovery |
GroupHigaisa | Higaisa’s shellcode attempted to find the process ID of the current process. |
| T1059.003 Windows Command Shell |
GroupHigaisa | Higaisa used |
| T1059.005 Visual Basic |
GroupHigaisa | Higaisa has used VBScript code on the victim's machine. |
| T1059.007 JavaScript |
GroupHigaisa | Higaisa used JavaScript to execute additional files. |
| T1071.001 Web Protocols |
GroupHigaisa | Higaisa used HTTP and HTTPS to send data back to its C2 server. |
| T1082 System Information Discovery |
GroupHigaisa | Higaisa collected the system GUID and computer name. |
| T1090.001 Internal Proxy |
GroupHigaisa | Higaisa discovered system proxy settings and used them if available. |
| T1106 Native API |
GroupHigaisa | Higaisa has called various native OS APIs. |
| T1124 System Time Discovery |
GroupHigaisa | Higaisa used a function to gather the current time. |
| T1140 Deobfuscate/Decode Files or Information |
GroupHigaisa | Higaisa used certutil to decode Base64 binaries at runtime and a 16-byte XOR key to decrypt data. |
| T1203 Exploitation for Client Execution |
GroupHigaisa | Higaisa has exploited CVE-2018-0798 for execution. |
| T1204.002 Malicious File |
GroupHigaisa | Higaisa used malicious e-mail attachments to lure victims into executing LNK files. |
| T1220 XSL Script Processing |
GroupHigaisa | Higaisa used an XSL file to run VBScript code. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupHigaisa | Higaisa added a spoofed binary to the start-up folder for persistence. |
| T1564.003 Hidden Window |
GroupHigaisa | Higaisa used a payload that creates a hidden window. |
| T1566.001 Spearphishing Attachment |
GroupHigaisa | Higaisa has sent spearphishing emails containing malicious attachments. |
| T1573.001 Symmetric Cryptography |
GroupHigaisa | Higaisa used AES-128 to encrypt C2 traffic. |
| T1574.001 DLL |
GroupHigaisa | Higaisa’s JavaScript file used a legitimate Microsoft Office 2007 package to side-load the |
| T1680 Local Storage Discovery |
GroupHigaisa | Higaisa collected the system volume serial number. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.