ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0266×

55 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareTrickBot

TrickBot collects local files and information from the victim’s local machine.

T1007
System Service Discovery
MalwareTrickBot

TrickBot collects a list of install programs and services on the system’s machine.

T1008
Fallback Channels
MalwareTrickBot

TrickBot can use secondary C2 servers for communication after establishing connectivity and relaying victim information to primary C2 servers.

T1016
System Network Configuration Discovery
MalwareTrickBot

TrickBot obtains the IP address, location, and other relevant network information from the victim’s machine.

T1018
Remote System Discovery
MalwareTrickBot

TrickBot can enumerate computers and network devices.

T1021.005
VNC
MalwareTrickBot

TrickBot has used a VNC module to monitor the victim and collect information to pivot to valuable systems on the network

T1027
Obfuscated Files or Information
MalwareTrickBot

TrickBot uses non-descriptive names to hide functionality.

T1027.002
Software Packing
MalwareTrickBot

TrickBot leverages a custom packer to obfuscate its functionality.

T1027.013
Encrypted/Encoded File
MalwareTrickBot

TrickBot uses an AES CBC (256 bits) encryption algorithm for its loader and configuration files.

T1033
System Owner/User Discovery
MalwareTrickBot

TrickBot can identify the user and groups the user belongs to on a compromised host.

T1036
Masquerading
MalwareTrickBot

The TrickBot downloader has used an icon to appear as a Microsoft Word document.

T1041
Exfiltration Over C2 Channel
MalwareTrickBot

TrickBot can send information about the compromised host and upload data to a hardcoded C2 server.

T1053.005
Scheduled Task
MalwareTrickBot

TrickBot creates a scheduled task on the system that provides persistence.

T1055
Process Injection
MalwareTrickBot

TrickBot has used Nt* Native API functions to inject code into legitimate processes such as wermgr.exe.

T1055.012
Process Hollowing
MalwareTrickBot

TrickBot injects into the svchost.exe process.

T1056.004
Credential API Hooking
MalwareTrickBot

TrickBot has the ability to capture RDP credentials by capturing the CredEnumerateA API

T1057
Process Discovery
MalwareTrickBot

TrickBot uses module networkDll for process list discovery.

T1059.001
PowerShell
MalwareTrickBot

TrickBot has been known to use PowerShell to download new payloads, open documents, and upload data to command and control servers.

T1059.003
Windows Command Shell
MalwareTrickBot

TrickBot has used macros in Excel documents to download and deploy the malware on the user’s machine.

T1069
Permission Groups Discovery
MalwareTrickBot

TrickBot can identify the groups the user on a compromised host belongs to.

T1071.001
Web Protocols
MalwareTrickBot

TrickBot uses HTTPS to communicate with its C2 servers, to get malware updates, modules that perform most of the malware logic and various configuration files.

T1082
System Information Discovery
MalwareTrickBot

TrickBot gathers the OS version, machine name, CPU type, amount of RAM available, and UEFI/BIOS firmware information from the victim’s machine.

T1083
File and Directory Discovery
MalwareTrickBot

TrickBot searches the system for all of the following file extensions: .avi, .mov, .mkv, .mpeg, .mpeg4, .mp4, .mp3, .wav, .ogg, .jpeg, .jpg, .png, .bmp, .gif, .tiff, .ico, .xlsx, and .zip. It can also obtain browsing history, cookies, and plug-in information.

T1087.001
Local Account
MalwareTrickBot

TrickBot collects the users of the system.

T1087.003
Email Account
MalwareTrickBot

TrickBot collects email addresses from Outlook.

T1090.002
External Proxy
MalwareTrickBot

TrickBot has been known to reach a command and control server via one of nine proxy IP addresses.

T1105
Ingress Tool Transfer
MalwareTrickBot

TrickBot downloads several additional files and saves them to the victim's machine.

T1106
Native API
MalwareTrickBot

TrickBot uses the Windows API call, CreateProcessW(), to manage execution flow. TrickBot has also used Nt* API functions to perform Process Injection.

T1110.004
Credential Stuffing
MalwareTrickBot

TrickBot uses brute-force attack against RDP with rdpscanDll module.

T1112
Modify Registry
MalwareTrickBot

TrickBot can modify registry entries.

T1132.001
Standard Encoding
MalwareTrickBot

TrickBot can Base64-encode C2 commands.

T1135
Network Share Discovery
MalwareTrickBot

TrickBot module shareDll/mshareDll discovers network shares via the WNetOpenEnumA API.

T1140
Deobfuscate/Decode Files or Information
MalwareTrickBot

TrickBot decodes the configuration data and modules.

T1185
Browser Session Hijacking
MalwareTrickBot

TrickBot uses web injects and browser redirection to trick the user into providing their login credentials on a fake or modified web page.

T1204.002
Malicious File
MalwareTrickBot

TrickBot has attempted to get users to launch malicious documents to deliver its payload.

T1210
Exploitation of Remote Services
MalwareTrickBot

TrickBot utilizes EternalBlue and EternalRomance exploits for lateral movement in the modules wormwinDll, wormDll, mwormDll, nwormDll, tabDll.

T1219
Remote Access Tools
MalwareTrickBot

TrickBot uses vncDll module to remote control the victim machine.

T1482
Domain Trust Discovery
MalwareTrickBot

TrickBot can gather information about domain trusts by utilizing Nltest.

T1495
Firmware Corruption
MalwareTrickBot

TrickBot module "Trickboot" can write or erase the UEFI/BIOS firmware of a compromised device.

T1497.003
Time Based Checks
MalwareTrickBot

TrickBot has used printf and file I/O loops to delay process execution as part of API hammering.

T1542.003
Bootkit
MalwareTrickBot

TrickBot can implant malicious code into a compromised device's firmware.

T1543.003
Windows Service
MalwareTrickBot

TrickBot establishes persistence by creating an autostart service that allows it to run whenever the machine boots.

T1547.001
Registry Run Keys / Startup Folder
MalwareTrickBot

TrickBot establishes persistence in the Startup folder.

T1552.001
Credentials In Files
MalwareTrickBot

TrickBot can obtain passwords stored in files from several applications such as Outlook, Filezilla, OpenSSH, OpenVPN and WinSCP. Additionally, it searches for the ".vnc.lnk" affix to steal VNC credentials.

T1552.002
Credentials in Registry
MalwareTrickBot

TrickBot has retrieved PuTTY credentials by querying the Software\SimonTatham\Putty\Sessions registry key

T1553.002
Code Signing
MalwareTrickBot

TrickBot has come with a signed downloader component.

T1555.003
Credentials from Web Browsers
MalwareTrickBot

TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge, sometimes using esentutl.

T1555.005
Password Managers
MalwareTrickBot

TrickBot can steal passwords from the KeePass open source password manager.

T1559.001
Component Object Model
MalwareTrickBot

TrickBot used COM to setup scheduled task for persistence.

T1564.003
Hidden Window
MalwareTrickBot

TrickBot has used a hidden VNC (hVNC) window to monitor the victim and collect information stealthily.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.