ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1218.005
Mshta
MalwarePteranodon

Pteranodon can use mshta.exe to execute an HTA file hosted on a remote server.

T1218.005
Mshta
MalwareLumma Stealer

Lumma Stealer has used mshta.exe to execute additional content.

T1218.005
Mshta
MalwareXbash

Xbash can use mshta for executing scripts.

T1218.005
Mshta
MalwareNanHaiShu

NanHaiShu uses mshta.exe to load its program and files.

T1218.005
Mshta
MalwareMetamorfo

Metamorfo has used mshta.exe to execute a HTA payload.

T1218.005
Mshta
MalwareSibot

Sibot has been executed via MSHTA application.

T1218.005
Mshta
MalwareRevenge RAT

Revenge RAT uses mshta.exe to run malicious scripts on the system.

T1218.005
Mshta
MalwareBabyShark

BabyShark has used mshta.exe to download and execute applications from a remote server.

T1218.005
Mshta
MalwarePOWERSTATS

POWERSTATS can use Mshta.exe to execute additional payloads on compromised hosts.

T1218.005
Mshta
ToolCovenant

Covenant can create HTA files to install Grunt listeners.

T1218.005
Mshta
ToolKoadic

Koadic can use mshta to serve additional payloads and to help schedule tasks for persistence.

T1218.007
Msiexec
MalwareRCSession

RCSession has the ability to execute inside the msiexec.exe process.

T1218.007
Msiexec
MalwareTsundere Botnet

Tsundere Botnet has been distributed via an MSI installer.

T1218.007
Msiexec
MalwareFlawedAmmyy

FlawedAmmyy has been installed via `msiexec.exe`.

T1218.007
Msiexec
MalwareRaspberry Robin

Raspberry Robin uses msiexec.exe for post-installation communication to command and control infrastructure. Msiexec.exe is executed referencing a remote resource for second-stage payload retrieval and execution.

T1218.007
Msiexec
MalwareMispadu

Mispadu has been installed via MSI installer.

T1218.007
Msiexec
MalwareIcedID

IcedID can inject itself into a suspended msiexec.exe process to send beacons to C2 while appearing as a normal msi application. IcedID has also used msiexec.exe to deploy the IcedID loader.

T1218.007
Msiexec
MalwareRagnar Locker

Ragnar Locker has been delivered as an unsigned MSI package that was executed with msiexec.exe.

T1218.007
Msiexec
MalwareJavali

Javali has used the MSI installer to download and execute malicious payloads.

T1218.007
Msiexec
MalwareLatrodectus

Latrodectus has called `msiexec` to install remotely-hosted MSI files.

T1218.007
Msiexec
MalwareChaes

Chaes has used .MSI files as an initial way to start the infection chain.

T1218.007
Msiexec
MalwareMetamorfo

Metamorfo has used MsiExec.exe to automatically execute files.

T1218.007
Msiexec
MalwareRedLine Stealer

RedLine Stealer has been installed via MSI Installer.

T1218.007
Msiexec
MalwareGrandoreiro

Grandoreiro can use MSI files to execute DLLs.

T1218.007
Msiexec
MalwareDEADEYE

DEADEYE can use `msiexec.exe` for execution of malicious DLL.

T1218.007
Msiexec
MalwareClop

Clop can use msiexec.exe to disable security tools on the system.

T1218.007
Msiexec
MalwareMelcoz

Melcoz can use MSI files with embedded VBScript for execution.

T1218.007
Msiexec
MalwareMaze

Maze has delivered components for its ransomware attacks using MSI files, some of which have been executed from the command-line using msiexec.

T1218.007
Msiexec
MalwareAppleJeus

AppleJeus has been installed via MSI installer.

T1218.007
Msiexec
MalwareQakBot

QakBot can use MSIExec to spawn multiple cmd.exe processes.

T1218.007
Msiexec
MalwareDOWNIISSA

DOWNIISSA can create an instance of msiexec.exe and inject LODEINFO shellcode into the memory of the process.

T1218.007
Msiexec
MalwareLoudMiner

LoudMiner used an MSI installer to install the virtualization software.

T1218.007
Msiexec
ToolRemoteUtilities

RemoteUtilities can use Msiexec to install a service.

T1218.007
Msiexec
MalwareDuqu

Duqu has used msiexec to execute malicious Windows Installer packages. Additionally, a PROPERTY=VALUE pair containing a 56-bit encryption key has been used to decrypt the main payload from the installer packages.

T1218.008
Odbcconf
MalwareBumblebee

Bumblebee can use `odbcconf.exe` to run DLLs on targeted hosts.

T1218.008
Odbcconf
MalwareRaspberry Robin

Raspberry Robin uses the Windows utility odbcconf.exe to execute malicious commands, using the regsvr flag to execute DLLs and bypass application control mechanisms that are not monitoring for odbcconf.exe abuse.

T1218.009
Regsvcs/Regasm
MalwareAgent Tesla

Agent Tesla has dropped RegAsm.exe onto systems for performing malicious activity.

T1218.010
Regsvr32
MalwareOrz

Some Orz versions have an embedded DLL known as MockDll that uses Process Hollowing and regsvr32 to execute another payload.

T1218.010
Regsvr32
MalwareTONESHELL

TONESHELL has used regsvr32.exe to execute the windows `DLLRegisterServer` function.

T1218.010
Regsvr32
MalwareAppleSeed

AppleSeed can call regsvr32.exe for execution.

T1218.010
Regsvr32
MalwareEmotet

Emotet uses RegSvr32 to execute the DLL payload.

T1218.010
Regsvr32
MalwareSquirrelwaffle

Squirrelwaffle has been executed using `regsvr32.exe`.

T1218.010
Regsvr32
MalwareRaspberry Robin

Raspberry Robin uses regsvr32.exe execution without any command line parameters for command and control requests to IP addresses associated with Tor nodes.

T1218.010
Regsvr32
MalwareRagnar Locker

Ragnar Locker has used regsvr32.exe to execute components of VirtualBox.

T1218.010
Regsvr32
MalwareHi-Zor

Hi-Zor executes using regsvr32.exe called from the Registry Run Keys / Startup Folder persistence mechanism.

T1218.010
Regsvr32
MalwareXbash

Xbash can use regsvr32 for executing scripts.

T1218.010
Regsvr32
MalwareSaint Bot

Saint Bot has used `regsvr32` to execute scripts.

T1218.010
Regsvr32
MalwareEVILNUM

EVILNUM can run a remote scriptlet that drops a file and executes it via regsvr32.exe.

T1218.010
Regsvr32
MalwareMori

Mori can use `regsvr32.exe` for DLL execution.

T1218.010
Regsvr32
MalwareRogueRobin

RogueRobin uses regsvr32.exe to run a .sct file for execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.