ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1218.005
Mshta
GroupEarth Lusca

Earth Lusca has used `mshta.exe` to load an HTA script within a malicious .LNK file.

T1218.005
Mshta
GroupInception

Inception has used malicious HTA files to drop and execute malware.

T1218.005
Mshta
MalwarePteranodon

Pteranodon can use mshta.exe to execute an HTA file hosted on a remote server.

T1218.005
Mshta
MalwareLumma Stealer

Lumma Stealer has used mshta.exe to execute additional content.

T1218.005
Mshta
MalwareXbash

Xbash can use mshta for executing scripts.

T1218.005
Mshta
MalwareNanHaiShu

NanHaiShu uses mshta.exe to load its program and files.

T1218.005
Mshta
MalwareMetamorfo

Metamorfo has used mshta.exe to execute a HTA payload.

T1218.005
Mshta
MalwareSibot

Sibot has been executed via MSHTA application.

T1218.005
Mshta
MalwareRevenge RAT

Revenge RAT uses mshta.exe to run malicious scripts on the system.

T1218.005
Mshta
MalwareBabyShark

BabyShark has used mshta.exe to download and execute applications from a remote server.

T1218.005
Mshta
MalwarePOWERSTATS

POWERSTATS can use Mshta.exe to execute additional payloads on compromised hosts.

T1218.005
Mshta
ToolCovenant

Covenant can create HTA files to install Grunt listeners.

T1218.005
Mshta
ToolKoadic

Koadic can use mshta to serve additional payloads and to help schedule tasks for persistence.

T1218.007
Msiexec
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda initial payloads downloaded a Windows Installer MSI file that in turn dropped follow-on files leading to installation of PlugX during RedDelta Modified PlugX Infection Chain Operations.

T1218.007
Msiexec
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus delivered components using a Windows Installer package (.msi). The MSI installer extracted several files and executed the 3CXDesktopApp.exe, which loaded the malicious library file ffmpeg.dll.

T1218.007
Msiexec
GroupAPT38

APT38 has used `msiexec.exe` to execute malicious files.

T1218.007
Msiexec
GroupMachete

Machete has used msiexec to install the Machete malware.

T1218.007
Msiexec
GroupZIRCONIUM

ZIRCONIUM has used the msiexec.exe command-line utility to download and execute malicious MSI files.

T1218.007
Msiexec
GroupTA505

TA505 has used msiexec to download and execute malicious Windows Installer files.

T1218.007
Msiexec
GroupMolerats

Molerats has used msiexec.exe to execute an MSI payload.

T1218.007
Msiexec
GroupRancor

Rancor has used msiexec to download and execute malicious installer files over HTTP.

T1218.007
Msiexec
MalwareRCSession

RCSession has the ability to execute inside the msiexec.exe process.

T1218.007
Msiexec
MalwareTsundere Botnet

Tsundere Botnet has been distributed via an MSI installer.

T1218.007
Msiexec
MalwareFlawedAmmyy

FlawedAmmyy has been installed via `msiexec.exe`.

T1218.007
Msiexec
MalwareRaspberry Robin

Raspberry Robin uses msiexec.exe for post-installation communication to command and control infrastructure. Msiexec.exe is executed referencing a remote resource for second-stage payload retrieval and execution.

T1218.007
Msiexec
MalwareMispadu

Mispadu has been installed via MSI installer.

T1218.007
Msiexec
MalwareIcedID

IcedID can inject itself into a suspended msiexec.exe process to send beacons to C2 while appearing as a normal msi application. IcedID has also used msiexec.exe to deploy the IcedID loader.

T1218.007
Msiexec
MalwareRagnar Locker

Ragnar Locker has been delivered as an unsigned MSI package that was executed with msiexec.exe.

T1218.007
Msiexec
MalwareJavali

Javali has used the MSI installer to download and execute malicious payloads.

T1218.007
Msiexec
MalwareLatrodectus

Latrodectus has called `msiexec` to install remotely-hosted MSI files.

T1218.007
Msiexec
MalwareChaes

Chaes has used .MSI files as an initial way to start the infection chain.

T1218.007
Msiexec
MalwareMetamorfo

Metamorfo has used MsiExec.exe to automatically execute files.

T1218.007
Msiexec
MalwareRedLine Stealer

RedLine Stealer has been installed via MSI Installer.

T1218.007
Msiexec
MalwareGrandoreiro

Grandoreiro can use MSI files to execute DLLs.

T1218.007
Msiexec
MalwareDEADEYE

DEADEYE can use `msiexec.exe` for execution of malicious DLL.

T1218.007
Msiexec
MalwareClop

Clop can use msiexec.exe to disable security tools on the system.

T1218.007
Msiexec
MalwareMelcoz

Melcoz can use MSI files with embedded VBScript for execution.

T1218.007
Msiexec
MalwareMaze

Maze has delivered components for its ransomware attacks using MSI files, some of which have been executed from the command-line using msiexec.

T1218.007
Msiexec
MalwareAppleJeus

AppleJeus has been installed via MSI installer.

T1218.007
Msiexec
MalwareQakBot

QakBot can use MSIExec to spawn multiple cmd.exe processes.

T1218.007
Msiexec
MalwareDOWNIISSA

DOWNIISSA can create an instance of msiexec.exe and inject LODEINFO shellcode into the memory of the process.

T1218.007
Msiexec
MalwareLoudMiner

LoudMiner used an MSI installer to install the virtualization software.

T1218.007
Msiexec
ToolRemoteUtilities

RemoteUtilities can use Msiexec to install a service.

T1218.007
Msiexec
MalwareDuqu

Duqu has used msiexec to execute malicious Windows Installer packages. Additionally, a PROPERTY=VALUE pair containing a 56-bit encryption key has been used to decrypt the main payload from the installer packages.

T1218.008
Odbcconf
GroupCobalt Group

Cobalt Group has used odbcconf to proxy the execution of malicious DLL files.

T1218.008
Odbcconf
MalwareBumblebee

Bumblebee can use `odbcconf.exe` to run DLLs on targeted hosts.

T1218.008
Odbcconf
MalwareRaspberry Robin

Raspberry Robin uses the Windows utility odbcconf.exe to execute malicious commands, using the regsvr flag to execute DLLs and bypass application control mechanisms that are not monitoring for odbcconf.exe abuse.

T1218.009
Regsvcs/Regasm
MalwareAgent Tesla

Agent Tesla has dropped RegAsm.exe onto systems for performing malicious activity.

T1218.010
Regsvr32
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used `regsvr32` to execute malware.

T1218.010
Regsvr32
CampaignC0015

During C0015, the threat actors employed code that used `regsvr32` for execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.