ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1074.001×

95 examples

TechniqueUsed byProcedure example
T1074.001
Local Data Staging
MalwareOopsIE

OopsIE stages the output from command execution and collected files in specific folders before exfiltration.

T1074.001
Local Data Staging
MalwareAttor

Attor has staged collected data in a central upload directory prior to exfiltration.

T1074.001
Local Data Staging
MalwareBoxCaon

BoxCaon has created a working folder for collected files that it sends to the C2 server.

T1074.001
Local Data Staging
MalwareNightClub

NightClub has copied captured files and keystrokes to the `%TEMP%` directory of compromised hosts.

T1074.001
Local Data Staging
MalwareCrutch

Crutch has staged stolen files in the C:\AMD\Temp directory.

T1074.001
Local Data Staging
MalwareRawPOS

Data captured by RawPOS is placed in a temporary file under a directory named "memdump".

T1074.001
Local Data Staging
MalwareBadPatch

BadPatch stores collected data in log files before exfiltration.

T1074.001
Local Data Staging
MalwareMESSAGETAP

MESSAGETAP stored targeted SMS messages that matched its target list in CSV files on the compromised system.

T1074.001
Local Data Staging
MalwareSUGARDUMP

SUGARDUMP has stored collected data under `%<malware_execution_folder>%\\CrashLog.txt`.

T1074.001
Local Data Staging
MalwareMoonWind

MoonWind saves information from its keylogging routine as a .zip file in the present working directory.

T1074.001
Local Data Staging
MalwareCorKLOG

CorKLOG has stored the captured data in an encrypted file using a 48-character RC4 key.

T1074.001
Local Data Staging
Malwareccf32

ccf32 can temporarily store files in a hidden directory on the local host.

T1074.001
Local Data Staging
MalwareZebrocy

Zebrocy stores all collected information in a single file before exfiltration.

T1074.001
Local Data Staging
MalwareLunarMail

LunarMail can create a directory in `%TEMP%\` to stage data prior to exfilration.

T1074.001
Local Data Staging
MalwareSampleCheck5000

SampleCheck5000 can log the output from C2 commands in an encrypted and compressed format on disk prior to exfiltration.

T1074.001
Local Data Staging
MalwareMilan

Milan has saved files prior to upload from a compromised host to folders beginning with the characters `a9850d2f`.

T1074.001
Local Data Staging
MalwareUSBStealer

USBStealer collects files matching certain criteria from the victim and stores them in a local directory for later exfiltration.

T1074.001
Local Data Staging
MalwareOilBooster

OilBooster can stage files in the `tempFiles` directory for exfiltration.

T1074.001
Local Data Staging
MalwarePoisonIvy

PoisonIvy stages collected data in a text file.

T1074.001
Local Data Staging
MalwareCarbon

Carbon creates a base directory that contains the files and folders that are collected.

T1074.001
Local Data Staging
MalwareCalisto

Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration.

T1074.001
Local Data Staging
MalwareGold Dragon

Gold Dragon stores information gathered from the endpoint in a file named 1.hwp.

T1074.001
Local Data Staging
MalwareRamsay

Ramsay can stage data prior to exfiltration in %APPDATA%\Microsoft\UserSetting and %APPDATA%\Microsoft\UserSetting\MediaCache.

T1074.001
Local Data Staging
MalwareMacMa

MacMa has stored collected files locally before exfiltration.

T1074.001
Local Data Staging
MalwareFunnyDream

FunnyDream can stage collected information including screen captures and logged keystrokes locally.

T1074.001
Local Data Staging
MalwarePUNCHTRACK

PUNCHTRACK aggregates collected data in a tmp file.

T1074.001
Local Data Staging
MalwareLAMEHUG

LAMEHUG can save collected data and files of interest in `C:\ProgramData\info\` to consolidate for exfiltration.

T1074.001
Local Data Staging
MalwareRIFLESPINE

RIFLESPINE can stage the output from executed C2 commands to a temporary file.

T1074.001
Local Data Staging
MalwareSLIGHTPULSE

SLIGHTPULSE has piped the output from executed commands to `/tmp/1`.

T1074.001
Local Data Staging
MalwareTroll Stealer

Troll Stealer encrypts gathered information on victim devices prior to exfiltrating it through command and control infrastructure.

T1074.001
Local Data Staging
MalwaremetaMain

metaMain has stored the collected system files in a working directory.

T1074.001
Local Data Staging
MalwareMis-Type

Mis-Type has temporarily stored collected information to the files `“%AppData%\{Unique Identifier}\HOSTRURKLSR”` and `“%AppData%\{Unique Identifier}\NEWERSSEMP”`.

T1074.001
Local Data Staging
MalwareOctopus

Octopus has stored collected information in the Application Data directory on a compromised host.

T1074.001
Local Data Staging
MalwareSTARWHALE

STARWHALE has stored collected data in a file called `stari.txt`.

T1074.001
Local Data Staging
MalwareECCENTRICBANDWAGON

ECCENTRICBANDWAGON has stored keystrokes and screenshots within the %temp%\GoogleChrome, %temp%\Downloads, and %temp%\TrendMicroUpdate directories.

T1074.001
Local Data Staging
MalwareBADNEWS

BADNEWS copies documents under 15MB found on the victim system to is the user's %temp%\SMB\ folder. It also copies files from USB devices to a predefined directory.

T1074.001
Local Data Staging
MalwareDRYHOOK

DRYHOOK has stored stolen credentials for future use in the temp folder of a victimized Ivanti Connect Secure VPN device, specifically in the file location `/tmp/cmmmap.kumMW`.

T1074.001
Local Data Staging
MalwareAstaroth

Astaroth collects data in a plaintext file named r1.log before exfiltration.

T1074.001
Local Data Staging
MalwareQakBot

QakBot has stored stolen emails and other data into new folders prior to exfiltration.

T1074.001
Local Data Staging
MalwareHelminth

Helminth creates folders to store output from batch scripts prior to sending the information to its C2 server.

T1074.001
Local Data Staging
MalwareDtrack

Dtrack can save collected data to disk, different file formats, and network shares.

T1074.001
Local Data Staging
MalwareSLOWPULSE

SLOWPULSE can write logged ACE credentials to `/home/perl/PAUS.pm` in append mode, using the format string `%s:%s\n`.

T1074.001
Local Data Staging
MalwareADVSTORESHELL

ADVSTORESHELL stores output from command execution in a .dat file in the %TEMP% directory.

T1074.001
Local Data Staging
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has created a staging file in `/tmp` for collected data.

T1074.001
Local Data Staging
MalwareDuqu

Modules can be pushed to and executed by Duqu that copy data to a staging area, compress it, and XOR encrypt it.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.