Real-world descriptions of how a group, tool or campaign used a technique.
41 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupRedCurl | |
| T1005 Data from Local System |
GroupRedCurl | RedCurl has collected data from the local disk of compromised hosts. |
| T1020 Automated Exfiltration |
GroupRedCurl | RedCurl has used batch scripts to exfiltrate data. |
| T1027 Obfuscated Files or Information |
GroupRedCurl | RedCurl has used malware with string encryption. RedCurl has also encrypted data and has encoded PowerShell commands using Base64. RedCurl has used `PyArmor` to obfuscate code execution of LaZagne. Additionally, RedCurl has obfuscated downloaded files by renaming them as commonly used tools and has used `echo`, instead of file names themselves, to execute files. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupRedCurl | RedCurl mimicked legitimate file names and scheduled tasks, e.g. ` MicrosoftCurrentupdatesCheck` and |
| T1039 Data from Network Shared Drive |
GroupRedCurl | RedCurl has collected data about network drives. |
| T1046 Network Service Discovery |
GroupRedCurl | RedCurl has used netstat to check if port 4119 is open. |
| T1053.005 Scheduled Task |
GroupRedCurl | RedCurl has created scheduled tasks for persistence. |
| T1056.002 GUI Input Capture |
GroupRedCurl | RedCurl prompts the user for credentials through a Microsoft Outlook pop-up. |
| T1059.001 PowerShell |
GroupRedCurl | RedCurl has used PowerShell to execute commands and to download malware. |
| T1059.003 Windows Command Shell |
GroupRedCurl | RedCurl has used the Windows Command Prompt to execute commands. |
| T1059.005 Visual Basic |
GroupRedCurl | RedCurl has used VBScript to run malicious files. |
| T1059.006 Python |
GroupRedCurl | RedCurl has used a Python script to establish outbound communication and to execute commands using SMB port 445. |
| T1070.004 File Deletion |
GroupRedCurl | RedCurl has deleted files after execution. |
| T1071.001 Web Protocols |
GroupRedCurl | RedCurl has used HTTP, HTTPS and Webdav protocls for C2 communications. |
| T1080 Taint Shared Content |
GroupRedCurl | RedCurl has placed modified LNK files on network drives for lateral movement. |
| T1082 System Information Discovery |
GroupRedCurl | RedCurl has collected information about the target system, such as system information and list of network connections. |
| T1083 File and Directory Discovery |
GroupRedCurl | RedCurl has searched for and collected files on local and network drives. |
| T1087.001 Local Account |
GroupRedCurl | RedCurl has collected information about local accounts. |
| T1087.002 Domain Account |
GroupRedCurl | RedCurl has collected information about domain accounts using SysInternal’s AdExplorer functionality . |
| T1087.003 Email Account |
GroupRedCurl | RedCurl has collected information about email accounts. |
| T1102 Web Service |
GroupRedCurl | RedCurl has used web services to download malicious files. |
| T1114.001 Local Email Collection |
GroupRedCurl | RedCurl has collected emails to use in future phishing campaigns. |
| T1119 Automated Collection |
GroupRedCurl | RedCurl has used batch scripts to collect data. |
| T1199 Trusted Relationship |
GroupRedCurl | RedCurl has gained access to a contractor to pivot to the victim’s infrastructure. |
| T1202 Indirect Command Execution |
GroupRedCurl | RedCurl has used pcalua.exe to obfuscate binary execution and remote connections. |
| T1204.001 Malicious Link |
GroupRedCurl | RedCurl has used malicious links to infect the victim machines. |
| T1204.002 Malicious File |
GroupRedCurl | RedCurl has used malicious files to infect the victim machines. |
| T1218.011 Rundll32 |
GroupRedCurl | RedCurl has used rundll32.exe to execute malicious files. |
| T1537 Transfer Data to Cloud Account |
GroupRedCurl | RedCurl has used cloud storage to exfiltrate data, in particular the megatools utilities were used to exfiltrate data to Mega, a file storage service. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupRedCurl | RedCurl has established persistence by creating entries in `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1552.001 Credentials In Files |
GroupRedCurl | |
| T1552.002 Credentials in Registry |
GroupRedCurl | |
| T1555.003 Credentials from Web Browsers |
GroupRedCurl | |
| T1560.001 Archive via Utility |
GroupRedCurl | RedCurl has downloaded 7-Zip to decompress password protected archives. |
| T1564.001 Hidden Files and Directories |
GroupRedCurl | RedCurl added the “hidden” file attribute to original files, manipulating victims to click on malicious LNK files. |
| T1566.001 Spearphishing Attachment |
GroupRedCurl | RedCurl has used phishing emails with malicious files to gain initial access. |
| T1566.002 Spearphishing Link |
GroupRedCurl | RedCurl has used phishing emails with malicious links to gain initial access. |
| T1573.001 Symmetric Cryptography |
GroupRedCurl | RedCurl has used AES-128 CBC to encrypt C2 communications. |
| T1573.002 Asymmetric Cryptography |
GroupRedCurl | RedCurl has used HTTPS for C2 communication. |
| T1587.001 Malware |
GroupRedCurl | RedCurl has created its own tools to use during operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.