Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1497.003 Time Based Checks |
MalwareGoldMax | GoldMax has set an execution trigger date and time, stored as an ASCII Unix/Epoch time value. |
| T1497.003 Time Based Checks |
MalwareDarkTortilla | DarkTortilla can implement the `kernel32.dll` Sleep function to delay execution for up to 300 seconds before implementing persistence or processing an addon package. |
| T1497.003 Time Based Checks |
MalwareBisonal | Bisonal has checked if the malware is running in a virtual environment with the anti-debug function GetTickCount() to compare the timing. |
| T1497.003 Time Based Checks |
MalwareClambling | Clambling can wait 30 minutes before initiating contact with C2. |
| T1497.003 Time Based Checks |
MalwareSVCReady | SVCReady can enter a sleep stage for 30 minutes to evade detection. |
| T1497.003 Time Based Checks |
MalwareThiefQuest | ThiefQuest invokes |
| T1497.003 Time Based Checks |
MalwareSaint Bot | Saint Bot has used the command `timeout 20` to pause the execution of its initial loader. |
| T1497.003 Time Based Checks |
MalwareP8RAT | P8RAT has the ability to "sleep" for a specified time to evade detection. |
| T1497.003 Time Based Checks |
MalwareBendyBear | BendyBear can check for analysis environments and signs of debugging using the Windows API |
| T1497.003 Time Based Checks |
MalwareSodaMaster | SodaMaster has the ability to put itself to "sleep" for a specified time. |
| T1497.003 Time Based Checks |
MalwareLiteDuke | LiteDuke can wait 30 seconds before executing additional code if security software is detected. |
| T1497.003 Time Based Checks |
MalwareBazar | Bazar can use a timer to delay execution of core functionality. |
| T1497.003 Time Based Checks |
MalwareHiddenFace | HiddenFace can sleep randomly between 30 and 60 seconds to avoid behavioral analysis. |
| T1497.003 Time Based Checks |
MalwareHermeticWiper | HermeticWiper has the ability to receive a command parameter to sleep prior to carrying out destructive actions on a targeted host. |
| T1497.003 Time Based Checks |
MalwareSUNBURST | SUNBURST remained dormant after initial access for a period of up to two weeks. |
| T1497.003 Time Based Checks |
MalwareEvilBunny | EvilBunny has used time measurements from 3 different APIs before and after performing sleep operations to check and abort if the malware is running in a sandbox. |
| T1497.003 Time Based Checks |
MalwareIPsec Helper | IPsec Helper will sleep for a random number of seconds, iterating 200 times over sleeps between one to three seconds, before continuing execution flow. |
| T1497.003 Time Based Checks |
MalwareGoldenSpy | GoldenSpy's installer has delayed installation of GoldenSpy for two hours after it reaches a victim system. |
| T1497.003 Time Based Checks |
MalwareGrimAgent | GrimAgent can sleep for 195 - 205 seconds after payload execution and before deleting its task. |
| T1497.003 Time Based Checks |
MalwareClop | Clop has used the |
| T1497.003 Time Based Checks |
MalwareLokibot | Lokibot has performed a time-based anti-debug check before downloading its third stage. |
| T1497.003 Time Based Checks |
MalwareEgregor | Egregor can perform a long sleep (greater than or equal to 3 minutes) to evade detection. |
| T1497.003 Time Based Checks |
MalwaremetaMain | metaMain has delayed execution for five to six minutes during its persistence establishment process. |
| T1497.003 Time Based Checks |
MalwareLunarWeb | LunarWeb can pause for a number of hours before entering its C2 communication loop. |
| T1497.003 Time Based Checks |
MalwareXCSSET | Using the machine's local time, XCSSET waits 43200 seconds (12 hours) from the initial creation timestamp of a specific file, |
| T1497.003 Time Based Checks |
MalwareAppleJeus | AppleJeus has waited a specified time before downloading a second stage payload. |
| T1497.003 Time Based Checks |
MalwareQakBot | The QakBot dropper can delay dropping the payload to evade detection. |
| T1497.003 Time Based Checks |
MalwareStrifeWater | StrifeWater can modify its sleep time responses from the default of 20-22 seconds. |
| T1497.003 Time Based Checks |
Toolevilginx2 | evilginx2 has the ability to hide phishing lures for a set time to avoid scanning by sandboxes. |
| T1497.003 Time Based Checks |
ToolBrute Ratel C4 | Brute Ratel C4 can call `NtDelayExecution` to pause execution. |
| T1497.003 Time Based Checks |
MalwareCanisterWorm | CanisterWorm has leveraged a Sleep setting of five minutes before executing tasks to evade sandbox environments. |
| T1497.003 Time Based Checks |
MalwareBADFLICK | BADFLICK has delayed communication to the actor-controlled IP address by 5 minutes. |
| T1498 Network Denial of Service |
GroupAPT28 | In 2016, APT28 conducted a distributed denial of service (DDoS) attack against the World Anti-Doping Agency. |
| T1498 Network Denial of Service |
MalwareLucifer | Lucifer can execute TCP, UDP, and HTTP denial of service (DoS) attacks. |
| T1498 Network Denial of Service |
MalwareNKAbuse | NKAbuse enables multiple types of network denial of service capabilities across several protocols post-installation. |
| T1499 Endpoint Denial of Service |
GroupSandworm Team | Sandworm Team temporarily disrupted service to Georgian government, non-government, and private sector websites after compromising a Georgian web hosting provider in 2019. |
| T1499 Endpoint Denial of Service |
MalwareOnionDuke | OnionDuke has the capability to use a Denial of Service module. |
| T1499 Endpoint Denial of Service |
MalwareZxShell | ZxShell has a feature to perform SYN flood attack on a host. |
| T1499.004 Application or System Exploitation |
MalwareIndustroyer | Industroyer uses a custom DoS tool that leverages CVE-2015-5374 and targets hardcoded IP addresses of Siemens SIPROTEC devices. |
| T1505.001 SQL Stored Procedures |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used various MS-SQL stored procedures. |
| T1505.001 SQL Stored Procedures |
MalwareStuxnet | Stuxnet used xp_cmdshell to store and execute SQL code. |
| T1505.002 Transport Agent |
MalwareLightNeuron | LightNeuron has used a malicious Microsoft Exchange transport agent for persistence. |
| T1505.003 Web Shell |
CampaignFrostyGoop Incident | FrostyGoop Incident deployed a ReGeorg variant web shell to impacted systems following initial access for persistence. |
| T1505.003 Web Shell |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors followed exploitation of SharePoint servers with installation of a malicious .aspx web shell (spinstall0.aspx) that was written to the `_layouts/15/` directory, granting persistent HTTP-based access. |
| T1505.003 Web Shell |
CampaignCutting Edge | During Cutting Edge, threat actors used multiple web shells to maintain presence on compromised Connect Secure appliances such as WIREFIRE, GLASSTOKEN, BUSHWALK, LIGHTWIRE, and FRAMESTING. |
| T1505.003 Web Shell |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors deployed a PHP-based webshell to maintain persistent access. |
| T1505.003 Web Shell |
CampaignHomeLand Justice | For HomeLand Justice, threat actors used .aspx webshells named pickers.aspx, error4.aspx, and ClientBin.aspx, to maintain persistence. |
| T1505.003 Web Shell |
CampaignC0032 | During the C0032 campaign, TEMP.Veles planted Web shells on Outlook Exchange servers. |
| T1505.003 Web Shell |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors generated a web shell within a vulnerable Enterprise Resource Planning Web Application Server as a persistence mechanism. |
| T1505.003 Web Shell |
CampaignAPT41 DUST | APT41 DUST involved use of web shells such as ANTSWORD and BLUEBEAM for persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.