ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0129×

85 examples

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
GroupMustang Panda

Mustang Panda has utilized TLS record headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. Mustang Panda has used FakeTLS to communicate with its C2 servers.

T1003
OS Credential Dumping
GroupMustang Panda

Mustang Panda utilized “Hdump” to dump credentials from memory.

T1003.001
LSASS Memory
GroupMustang Panda

Mustang Panda has harvested credentials from memory of lssas.exe with Mimikatz.

T1003.003
NTDS
GroupMustang Panda

Mustang Panda has used vssadmin to create a volume shadow copy and retrieve the NTDS.dit file. Mustang Panda has also used reg save on the SYSTEM file Registry location to help extract the NTDS.dit file.

T1003.006
DCSync
GroupMustang Panda

Mustang Panda has leveraged Mimikatz DCSync feature to obtain user credentials.

T1016
System Network Configuration Discovery
GroupMustang Panda

Mustang Panda has used ipconfig and arp to determine network configuration information. Mustang Panda has also utilized SharpNBTScan to scan the victim environment.

T1018
Remote System Discovery
GroupMustang Panda

Mustang Panda has queried Active Directory for computers using AdFind. Mustang Panda has also utilized SharpNBTScan to scan the victim environment.

T1027
Obfuscated Files or Information
GroupMustang Panda

Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis.

T1027.007
Dynamic API Resolution
GroupMustang Panda

Mustang Panda has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API.

T1027.012
LNK Icon Smuggling
GroupMustang Panda

Mustang Panda has utilized LNK files to hide malicious scripts for execution. Mustang Panda has also leveraged LNK files that were programmed to display a PDF icon to entice the victim to click on the file to execute an office.exe binary.

T1027.016
Junk Code Insertion
GroupMustang Panda

Mustang Panda has used junk code within their DLL files to hinder analysis.

T1036.005
Match Legitimate Resource Name or Location
GroupMustang Panda

Mustang Panda has used names like `adobeupdate.dat` and `PotPlayerDB.dat` to disguise PlugX, and a file named `OneDrive.exe` to load a Cobalt Strike payload. Mustang Panda has also masqueraded legitimate browser plugin updates to include AdobePlugins.exe.

T1036.007
Double File Extension
GroupMustang Panda

Mustang Panda has used an additional filename extension to hide the true file type.

T1036.008
Masquerade File Type
GroupMustang Panda

Mustang Panda has masqueraded malicious executables as legitimate files that download PlugX malware.

T1041
Exfiltration Over C2 Channel
GroupMustang Panda

Mustang Panda has exfiltrated stolen data and files to its C2 server.

T1046
Network Service Discovery
GroupMustang Panda

Mustang Panda has leveraged NBTscan to scan IP networks.

T1047
Windows Management Instrumentation
GroupMustang Panda

Mustang Panda has executed PowerShell scripts via WMI.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupMustang Panda

Mustang Panda has used FTP to exfiltrate archive files.

T1049
System Network Connections Discovery
GroupMustang Panda

Mustang Panda has used netstat -ano to determine network connection information.

T1052.001
Exfiltration over USB
GroupMustang Panda

Mustang Panda has used a customized PlugX variant which could exfiltrate documents from air-gapped networks.

T1053.005
Scheduled Task
GroupMustang Panda

Mustang Panda has created a scheduled task to execute additional malicious software, as well as maintain persistence. Mustang Panda has also created a scheduled task that creates a reverse shell.

T1057
Process Discovery
GroupMustang Panda

Mustang Panda has used tasklist /v to determine active process information. Mustang Panda has also used TONESHELL malware to check the process name and process path to ensure it matches the expected one prior to triggering a custom exception handler.

T1059
Command and Scripting Interpreter
GroupMustang Panda

Mustang Panda has utilized meterpreter shellcode.

T1059.001
PowerShell
GroupMustang Panda

Mustang Panda has used malicious PowerShell scripts to enable execution.

T1059.003
Windows Command Shell
GroupMustang Panda

Mustang Panda has executed HTA files via cmd.exe, and used batch scripts for collection. Mustang Panda has also utilized cmd.exe to execute commands on an infected host such as `cmd.exe /c ping.exe 8.8.8.8 -n 70&&"%temp%\FontEDL.exe"`.

T1059.005
Visual Basic
GroupMustang Panda

Mustang Panda has embedded VBScript components in LNK files to download additional files and automate collection. Mustang Panda has also used VBA macros in maldocs to execute malicious DLLs. Mustang Panda also utilized a VBS Script “autorun.vbs” that created persistence through saving the VBS Script in the startup directory which would cause it to run each time the machine was turned on.

T1059.007
JavaScript
GroupMustang Panda

Mustang Panda has executed a JavaScript payload utilizing wscript.exe on the endpoint.

T1069.002
Domain Groups
GroupMustang Panda

Mustang Panda has leveraged AdFind to enumerate domain groups.

T1070
Indicator Removal
GroupMustang Panda

Mustang Panda has deleted registry keys that store data and maintained persistence.

T1070.004
File Deletion
GroupMustang Panda

Mustang Panda will delete their tools and files, and kill processes after their objectives are reached.

T1070.006
Timestomp
GroupMustang Panda

Mustang Panda has modified file timestamps from the export address table (EAT) in malware to make it difficult to identify creation times.

T1071.001
Web Protocols
GroupMustang Panda

Mustang Panda has communicated with its C2 via HTTP POST requests.

T1072
Software Deployment Tools
GroupMustang Panda

Mustang Panda has leveraged legitimate software tools such as AntiVirus Agents, Security Services, and App Development tools to execute scripts and to side-load dlls.

T1074.001
Local Data Staging
GroupMustang Panda

Mustang Panda has stored collected credential files in c:\windows\temp prior to exfiltration. Mustang Panda has also stored documents for exfiltration in a hidden folder on USB drives.

T1082
System Information Discovery
GroupMustang Panda

Mustang Panda has gathered system information using systeminfo.

T1083
File and Directory Discovery
GroupMustang Panda

Mustang Panda has searched the entire target system for DOC, DOCX, PPT, PPTX, XLS, XLSX, and PDF files.

T1087.002
Domain Account
GroupMustang Panda

Mustang Panda has utilized AdFind to identify domain users.

T1091
Replication Through Removable Media
GroupMustang Panda

Mustang Panda has used a customized PlugX variant which could spread through USB connections.

T1095
Non-Application Layer Protocol
GroupMustang Panda

Mustang Panda has utilized TCP-based reverse shells using cmd.exe.

T1102
Web Service
GroupMustang Panda

Mustang Panda has used DropBox URLs to deliver variants of PlugX. Mustang Panda has also used Google Drive to host malicious downloads.

T1105
Ingress Tool Transfer
GroupMustang Panda

Mustang Panda has downloaded additional executables following the initial infection stage. Mustang Panda has also leveraged Visual Studio Code `code.exe` and Dev Tunnels using `DevTunnel.exe` to propagate additional tools and payloads.

T1106
Native API
GroupMustang Panda

Mustang Panda has used various Windows API calls during execution and defense evasion.

T1119
Automated Collection
GroupMustang Panda

Mustang Panda used custom batch scripts to collect files automatically from a targeted system.

T1129
Shared Modules
GroupMustang Panda

Mustang Panda has leveraged `LoadLibrary` to load DLLs.

T1140
Deobfuscate/Decode Files or Information
GroupMustang Panda

Mustang Panda has the ability to decrypt its payload prior to execution. Mustang Panda has also utilized RC4 encryption for malicious payloads.

T1176.002
IDE Extensions
GroupMustang Panda

Mustang Panda has leveraged Visual Studio Code’s (VSCode) embedded reverse shell feature using the command `code.exe tunnel` to execute code and deliver additional payloads.

T1203
Exploitation for Client Execution
GroupMustang Panda

Mustang Panda has exploited CVE-2017-0199 in Microsoft Word to execute code.

T1204.001
Malicious Link
GroupMustang Panda

Mustang Panda has sent malicious links including links directing victims to a Google Drive folder. Mustang Panda has also utilized webpages with Javascript code that downloads malicious payloads to the victim device.

T1204.002
Malicious File
GroupMustang Panda

Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim.

T1205
Traffic Signaling
GroupMustang Panda

Mustang Panda has utilized a magic value in C2 communications and only executes in memory when response packets match specific values of “17 03 03” or “46 77 4d”.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.