ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1008×

16 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupSideCopy

SideCopy has identified the IP address of a compromised host.

T1036.005
Match Legitimate Resource Name or Location
GroupSideCopy

SideCopy has used a legitimate DLL file name, `Duser.dll` to disguise a malicious remote access tool.

T1059.005
Visual Basic
GroupSideCopy

SideCopy has sent Microsoft Office Publisher documents to victims that have embedded malicious macros that execute an hta file via calling `mshta.exe`.

T1082
System Information Discovery
GroupSideCopy

SideCopy has identified the OS version of a compromised host.

T1105
Ingress Tool Transfer
GroupSideCopy

SideCopy has delivered trojanized executables via spearphishing emails that contacts actor-controlled servers to download malicious payloads.

T1106
Native API
GroupSideCopy

SideCopy has executed malware by calling the API function `CreateProcessW`.

T1204.002
Malicious File
GroupSideCopy

SideCopy has attempted to lure victims into clicking on malicious embedded archive files sent via spearphishing campaigns.

T1218.005
Mshta
GroupSideCopy

SideCopy has utilized `mshta.exe` to execute a malicious hta file.

T1518
Software Discovery
GroupSideCopy

SideCopy has collected browser information from a compromised host.

T1518.001
Security Software Discovery
GroupSideCopy

SideCopy uses a loader DLL file to collect AV product names from an infected host.

T1566.001
Spearphishing Attachment
GroupSideCopy

SideCopy has sent spearphishing emails with malicious hta file attachments.

T1574.001
DLL
GroupSideCopy

SideCopy has used a malicious loader DLL file to execute the `credwiz.exe` process and side-load the malicious payload `Duser.dll`.

T1584.001
Domains
GroupSideCopy

SideCopy has compromised domains for some of their infrastructure, including for C2 and staging malware.

T1598.002
Spearphishing Attachment
GroupSideCopy

SideCopy has crafted generic lures for spam campaigns to collect emails and credentials for targeting efforts.

T1608.001
Upload Malware
GroupSideCopy

SideCopy has used compromised domains to host its malicious payloads.

T1614
System Location Discovery
GroupSideCopy

SideCopy has identified the country location of a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.