ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1039×

41 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupRedCurl

RedCurl used LaZagne to obtain passwords from memory.

T1005
Data from Local System
GroupRedCurl

RedCurl has collected data from the local disk of compromised hosts.

T1020
Automated Exfiltration
GroupRedCurl

RedCurl has used batch scripts to exfiltrate data.

T1027
Obfuscated Files or Information
GroupRedCurl

RedCurl has used malware with string encryption. RedCurl has also encrypted data and has encoded PowerShell commands using Base64. RedCurl has used `PyArmor` to obfuscate code execution of LaZagne. Additionally, RedCurl has obfuscated downloaded files by renaming them as commonly used tools and has used `echo`, instead of file names themselves, to execute files.

T1036.005
Match Legitimate Resource Name or Location
GroupRedCurl

RedCurl mimicked legitimate file names and scheduled tasks, e.g. ` MicrosoftCurrentupdatesCheck` and
`MdMMaintenenceTask` to mask malicious files and scheduled tasks.

T1039
Data from Network Shared Drive
GroupRedCurl

RedCurl has collected data about network drives.

T1046
Network Service Discovery
GroupRedCurl

RedCurl has used netstat to check if port 4119 is open.

T1053.005
Scheduled Task
GroupRedCurl

RedCurl has created scheduled tasks for persistence.

T1056.002
GUI Input Capture
GroupRedCurl

RedCurl prompts the user for credentials through a Microsoft Outlook pop-up.

T1059.001
PowerShell
GroupRedCurl

RedCurl has used PowerShell to execute commands and to download malware.

T1059.003
Windows Command Shell
GroupRedCurl

RedCurl has used the Windows Command Prompt to execute commands.

T1059.005
Visual Basic
GroupRedCurl

RedCurl has used VBScript to run malicious files.

T1059.006
Python
GroupRedCurl

RedCurl has used a Python script to establish outbound communication and to execute commands using SMB port 445.

T1070.004
File Deletion
GroupRedCurl

RedCurl has deleted files after execution.

T1071.001
Web Protocols
GroupRedCurl

RedCurl has used HTTP, HTTPS and Webdav protocls for C2 communications.

T1080
Taint Shared Content
GroupRedCurl

RedCurl has placed modified LNK files on network drives for lateral movement.

T1082
System Information Discovery
GroupRedCurl

RedCurl has collected information about the target system, such as system information and list of network connections.

T1083
File and Directory Discovery
GroupRedCurl

RedCurl has searched for and collected files on local and network drives.

T1087.001
Local Account
GroupRedCurl

RedCurl has collected information about local accounts.

T1087.002
Domain Account
GroupRedCurl

RedCurl has collected information about domain accounts using SysInternal’s AdExplorer functionality .

T1087.003
Email Account
GroupRedCurl

RedCurl has collected information about email accounts.

T1102
Web Service
GroupRedCurl

RedCurl has used web services to download malicious files.

T1114.001
Local Email Collection
GroupRedCurl

RedCurl has collected emails to use in future phishing campaigns.

T1119
Automated Collection
GroupRedCurl

RedCurl has used batch scripts to collect data.

T1199
Trusted Relationship
GroupRedCurl

RedCurl has gained access to a contractor to pivot to the victim’s infrastructure.

T1202
Indirect Command Execution
GroupRedCurl

RedCurl has used pcalua.exe to obfuscate binary execution and remote connections.

T1204.001
Malicious Link
GroupRedCurl

RedCurl has used malicious links to infect the victim machines.

T1204.002
Malicious File
GroupRedCurl

RedCurl has used malicious files to infect the victim machines.

T1218.011
Rundll32
GroupRedCurl

RedCurl has used rundll32.exe to execute malicious files.

T1537
Transfer Data to Cloud Account
GroupRedCurl

RedCurl has used cloud storage to exfiltrate data, in particular the megatools utilities were used to exfiltrate data to Mega, a file storage service.

T1547.001
Registry Run Keys / Startup Folder
GroupRedCurl

RedCurl has established persistence by creating entries in `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1552.001
Credentials In Files
GroupRedCurl

RedCurl used LaZagne to obtain passwords in files.

T1552.002
Credentials in Registry
GroupRedCurl

RedCurl used LaZagne to obtain passwords in the Registry.

T1555.003
Credentials from Web Browsers
GroupRedCurl

RedCurl used LaZagne to obtain passwords from web browsers.

T1560.001
Archive via Utility
GroupRedCurl

RedCurl has downloaded 7-Zip to decompress password protected archives.

T1564.001
Hidden Files and Directories
GroupRedCurl

RedCurl added the “hidden” file attribute to original files, manipulating victims to click on malicious LNK files.

T1566.001
Spearphishing Attachment
GroupRedCurl

RedCurl has used phishing emails with malicious files to gain initial access.

T1566.002
Spearphishing Link
GroupRedCurl

RedCurl has used phishing emails with malicious links to gain initial access.

T1573.001
Symmetric Cryptography
GroupRedCurl

RedCurl has used AES-128 CBC to encrypt C2 communications.

T1573.002
Asymmetric Cryptography
GroupRedCurl

RedCurl has used HTTPS for C2 communication.

T1587.001
Malware
GroupRedCurl

RedCurl has created its own tools to use during operations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.