Real-world descriptions of how a group, tool or campaign used a technique.
71 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1218.010 Regsvr32 |
MalwareQakBot | QakBot can use Regsvr32 to execute malicious DLLs. |
| T1218.011 Rundll32 |
MalwareQakBot | QakBot has used Rundll32.exe to drop malicious DLLs including Brute Ratel C4 and to enable C2 communication. |
| T1482 Domain Trust Discovery |
MalwareQakBot | QakBot can run |
| T1497.001 System Checks |
MalwareQakBot | QakBot can check the compromised host for the presence of multiple executables associated with analysis tools and halt execution if any are found. |
| T1497.003 Time Based Checks |
MalwareQakBot | The QakBot dropper can delay dropping the payload to evade detection. |
| T1518 Software Discovery |
MalwareQakBot | QakBot can enumerate a list of installed programs. |
| T1518.001 Security Software Discovery |
MalwareQakBot | QakBot can identify the installed antivirus product on a targeted system. |
| T1539 Steal Web Session Cookie |
MalwareQakBot | QakBot has the ability to capture web session cookies. |
| T1543.003 Windows Service |
MalwareQakBot | QakBot can remotely create a temporary service on a target host. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareQakBot | QakBot can maintain persistence by creating an auto-run Registry key. |
| T1553.002 Code Signing |
MalwareQakBot | QakBot can use signed loaders to evade detection. |
| T1553.005 Mark-of-the-Web Bypass |
MalwareQakBot | QakBot has been packaged in ISO files in order to bypass Mark of the Web (MOTW) security measures. |
| T1555.003 Credentials from Web Browsers |
MalwareQakBot | QakBot has collected usernames and passwords from Firefox and Chrome. |
| T1564.001 Hidden Files and Directories |
MalwareQakBot | QakBot has placed its payload in hidden subdirectories. |
| T1566.001 Spearphishing Attachment |
MalwareQakBot | QakBot has spread through emails with malicious attachments. |
| T1566.002 Spearphishing Link |
MalwareQakBot | QakBot has spread through emails with malicious links. |
| T1568.002 Domain Generation Algorithms |
MalwareQakBot | QakBot can use domain generation algorithms in C2 communication. |
| T1572 Protocol Tunneling |
MalwareQakBot | The QakBot proxy module can encapsulate SOCKS5 protocol within its own proxy protocol. |
| T1573.001 Symmetric Cryptography |
MalwareQakBot | QakBot can RC4 encrypt strings in C2 communication. |
| T1574.001 DLL |
MalwareQakBot | QakBot has the ability to use DLL side-loading for execution. |
| T1685 Disable or Modify Tools |
MalwareQakBot | QakBot has the ability to modify the Registry to add its binaries to the Windows Defender exclusion list. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.