ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.005×

69 examples

TechniqueUsed byProcedure example
T1059.005
Visual Basic
MalwareLookBack

LookBack has used VBA macros in Microsoft Word attachments to drop additional files to the host.

T1059.005
Visual Basic
MalwareLokibot

Lokibot has used VBS scripts and XLS macros for execution.

T1059.005
Visual Basic
MalwarePoetRAT

PoetRAT has used Word documents with VBScripts to execute malicious activities.

T1059.005
Visual Basic
MalwareBabyShark

BabyShark can execute additional VisualBasic content.

T1059.005
Visual Basic
MalwareMelcoz

Melcoz can use VBS scripts to execute malicious DLLs.

T1059.005
Visual Basic
MalwareKOCTOPUS

KOCTOPUS has used VBScript to call wscript to execute a PowerShell command.

T1059.005
Visual Basic
MalwareSTARWHALE

STARWHALE can use the VBScript function `GetRef` as part of its persistence mechanism.

T1059.005
Visual Basic
MalwarePOWERSTATS

POWERSTATS can use VBScript (VBE) code for execution.

T1059.005
Visual Basic
MalwareGoopy

Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2.

T1059.005
Visual Basic
MalwareRemexi

Remexi uses AutoIt and VBS scripts throughout its execution process.

T1059.005
Visual Basic
MalwareAstaroth

Astaroth has used malicious VBS e-mail attachments for execution.

T1059.005
Visual Basic
MalwareQakBot

QakBot can use VBS to download and execute malicious files.

T1059.005
Visual Basic
MalwarejRAT

jRAT has been distributed as HTA files with VBScript.

T1059.005
Visual Basic
MalwareHelminth

One version of Helminth consists of VBScript scripts.

T1059.005
Visual Basic
MalwareComnie

Comnie executes VBS scripts.

T1059.005
Visual Basic
MalwareJSS Loader

JSS Loader can download and execute VBScript files.

T1059.005
Visual Basic
ToolRemcos

Remcos can execute VBS remotely.

T1059.005
Visual Basic
ToolDonut

Donut can generate shellcode outputs that execute via VBScript.

T1059.005
Visual Basic
ToolKoadic

Koadic performs most of its operations using Windows Script Host (VBScript) and runs arbitrary shellcode .

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.