ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0650×

71 examples

TechniqueUsed byProcedure example
T1218.010
Regsvr32
MalwareQakBot

QakBot can use Regsvr32 to execute malicious DLLs.

T1218.011
Rundll32
MalwareQakBot

QakBot has used Rundll32.exe to drop malicious DLLs including Brute Ratel C4 and to enable C2 communication.

T1482
Domain Trust Discovery
MalwareQakBot

QakBot can run nltest /domain_trusts /all_trusts for domain trust discovery.

T1497.001
System Checks
MalwareQakBot

QakBot can check the compromised host for the presence of multiple executables associated with analysis tools and halt execution if any are found.

T1497.003
Time Based Checks
MalwareQakBot

The QakBot dropper can delay dropping the payload to evade detection.

T1518
Software Discovery
MalwareQakBot

QakBot can enumerate a list of installed programs.

T1518.001
Security Software Discovery
MalwareQakBot

QakBot can identify the installed antivirus product on a targeted system.

T1539
Steal Web Session Cookie
MalwareQakBot

QakBot has the ability to capture web session cookies.

T1543.003
Windows Service
MalwareQakBot

QakBot can remotely create a temporary service on a target host.

T1547.001
Registry Run Keys / Startup Folder
MalwareQakBot

QakBot can maintain persistence by creating an auto-run Registry key.

T1553.002
Code Signing
MalwareQakBot

QakBot can use signed loaders to evade detection.

T1553.005
Mark-of-the-Web Bypass
MalwareQakBot

QakBot has been packaged in ISO files in order to bypass Mark of the Web (MOTW) security measures.

T1555.003
Credentials from Web Browsers
MalwareQakBot

QakBot has collected usernames and passwords from Firefox and Chrome.

T1564.001
Hidden Files and Directories
MalwareQakBot

QakBot has placed its payload in hidden subdirectories.

T1566.001
Spearphishing Attachment
MalwareQakBot

QakBot has spread through emails with malicious attachments.

T1566.002
Spearphishing Link
MalwareQakBot

QakBot has spread through emails with malicious links.

T1568.002
Domain Generation Algorithms
MalwareQakBot

QakBot can use domain generation algorithms in C2 communication.

T1572
Protocol Tunneling
MalwareQakBot

The QakBot proxy module can encapsulate SOCKS5 protocol within its own proxy protocol.

T1573.001
Symmetric Cryptography
MalwareQakBot

QakBot can RC4 encrypt strings in C2 communication.

T1574.001
DLL
MalwareQakBot

QakBot has the ability to use DLL side-loading for execution.

T1685
Disable or Modify Tools
MalwareQakBot

QakBot has the ability to modify the Registry to add its binaries to the Windows Defender exclusion list.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.