ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0126×

28 examples

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
GroupHigaisa

Higaisa used a FakeTLS session for C2 communications.

T1016
System Network Configuration Discovery
GroupHigaisa

Higaisa used ipconfig to gather network configuration information.

T1027.001
Binary Padding
GroupHigaisa

Higaisa performed padding with null bytes before calculating its hash.

T1027.013
Encrypted/Encoded File
GroupHigaisa

Higaisa used Base64 encoded compressed payloads.

T1027.015
Compression
GroupHigaisa

Higaisa used Base64 encoded compressed payloads.

T1029
Scheduled Transfer
GroupHigaisa

Higaisa sent the victim computer identifier in a User-Agent string back to the C2 server every 10 minutes.

T1036.004
Masquerade Task or Service
GroupHigaisa

Higaisa named a shellcode loader binary svchast.exe to spoof the legitimate svchost.exe.

T1041
Exfiltration Over C2 Channel
GroupHigaisa

Higaisa exfiltrated data over its C2 channel.

T1053.005
Scheduled Task
GroupHigaisa

Higaisa dropped and added officeupdate.exe to scheduled tasks.

T1057
Process Discovery
GroupHigaisa

Higaisa’s shellcode attempted to find the process ID of the current process.

T1059.003
Windows Command Shell
GroupHigaisa

Higaisa used cmd.exe for execution.

T1059.005
Visual Basic
GroupHigaisa

Higaisa has used VBScript code on the victim's machine.

T1059.007
JavaScript
GroupHigaisa

Higaisa used JavaScript to execute additional files.

T1071.001
Web Protocols
GroupHigaisa

Higaisa used HTTP and HTTPS to send data back to its C2 server.

T1082
System Information Discovery
GroupHigaisa

Higaisa collected the system GUID and computer name.

T1090.001
Internal Proxy
GroupHigaisa

Higaisa discovered system proxy settings and used them if available.

T1106
Native API
GroupHigaisa

Higaisa has called various native OS APIs.

T1124
System Time Discovery
GroupHigaisa

Higaisa used a function to gather the current time.

T1140
Deobfuscate/Decode Files or Information
GroupHigaisa

Higaisa used certutil to decode Base64 binaries at runtime and a 16-byte XOR key to decrypt data.

T1203
Exploitation for Client Execution
GroupHigaisa

Higaisa has exploited CVE-2018-0798 for execution.

T1204.002
Malicious File
GroupHigaisa

Higaisa used malicious e-mail attachments to lure victims into executing LNK files.

T1220
XSL Script Processing
GroupHigaisa

Higaisa used an XSL file to run VBScript code.

T1547.001
Registry Run Keys / Startup Folder
GroupHigaisa

Higaisa added a spoofed binary to the start-up folder for persistence.

T1564.003
Hidden Window
GroupHigaisa

Higaisa used a payload that creates a hidden window.

T1566.001
Spearphishing Attachment
GroupHigaisa

Higaisa has sent spearphishing emails containing malicious attachments.

T1573.001
Symmetric Cryptography
GroupHigaisa

Higaisa used AES-128 to encrypt C2 traffic.

T1574.001
DLL
GroupHigaisa

Higaisa’s JavaScript file used a legitimate Microsoft Office 2007 package to side-load the OINFO12.OCX dynamic link library.

T1680
Local Storage Discovery
GroupHigaisa

Higaisa collected the system volume serial number.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.