ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1027.007
Dynamic API Resolution
MalwareHTTPTroy

HTTPTroy has utilized dynamic API resolution by reconstructing API calls during runtime using combinations of arithmetic and logical operations to complicate static analysis.

T1027.007
Dynamic API Resolution
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use `LoadLibrary` and `GetProcAddress` to resolve Windows API function strings at run time.

T1027.007
Dynamic API Resolution
MalwarePteranodon

Pteranodon can use a dynamic Windows hashing algorithm to map API components.

T1027.007
Dynamic API Resolution
MalwareSplatDropper

SplatDropper has leveraged hashed Windows API calls using a seed value of "131313".

T1027.007
Dynamic API Resolution
MalwarePlugX

PlugX has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API.

T1027.007
Dynamic API Resolution
MalwareLatrodectus

Latrodectus can resolve Windows APIs dynamically by hash.

T1027.007
Dynamic API Resolution
MalwareLODEINFO

LODEINFO can use a hashing algorithm to dynamically resolve API function addresses.

T1027.007
Dynamic API Resolution
MalwareLP-Notes

LP-Notes has dynamically resolved API functions during the C runtime startup.

T1027.007
Dynamic API Resolution
MalwareBazar

Bazar can hash then resolve API calls at runtime.

T1027.007
Dynamic API Resolution
MalwareHiddenFace

HiddenFace can dynamically resolve Windows APIs.

T1027.007
Dynamic API Resolution
MalwareSamurai

Samurai can encrypt API name strings with an XOR-based algorithm.

T1027.007
Dynamic API Resolution
MalwareRaccoon Stealer

Raccoon Stealer dynamically links key WinApi functions during execution.

T1027.007
Dynamic API Resolution
ToolBrute Ratel C4

Brute Ratel C4 can call and dynamically resolve hashed APIs.

T1027.008
Stripped Payloads
MalwaremacOS.OSAMiner

macOS.OSAMiner has used run-only Applescripts, a compiled and stripped version of AppleScript, to remove human readable indicators to evade detection.

T1027.008
Stripped Payloads
MalwareCuckoo Stealer

Cuckoo Stealer is a stripped binary payload.

T1027.009
Embedded Payloads
MalwarePikabot

Pikabot further decrypts information embedded via steganography using AES-CBC with the same 32 bit key as initial XOR operations combined with the first 16 bytes of the encrypted data as an initialization vector. Other Pikabot variants include encrypted, chunked sections of the stage 2 payload in the initial loader .text section before decrypting and assembling these during execution.

T1027.009
Embedded Payloads
MalwaremacOS.OSAMiner

macOS.OSAMiner has embedded Stripped Payloads within another run-only Stripped Payloads.

T1027.009
Embedded Payloads
MalwareEmotet

Emotet has dropped an embedded executable at `%Temp%\setup.exe`. Additionally, Emotet may embed entire code into other files.

T1027.009
Embedded Payloads
MalwareDUSTTRAP

DUSTTRAP contains additional embedded DLLs and configuration files that are loaded into memory during execution.

T1027.009
Embedded Payloads
MalwareBADHATCH

BADHATCH has an embedded second stage DLL payload within the first stage of the malware.

T1027.009
Embedded Payloads
MalwareDUSTPAN

DUSTPAN decrypts and executes an embedded payload.

T1027.009
Embedded Payloads
MalwareMoneybird

Moneybird contains a configuration blob embedded in the malware itself.

T1027.009
Embedded Payloads
MalwareIcedID

IcedID has embedded malicious functionality in a legitimate DLL file.

T1027.009
Embedded Payloads
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can extract RC4 encrypted embedded payloads for privilege escalation.

T1027.009
Embedded Payloads
MalwareMultiLayer Wiper

MultiLayer Wiper contains two binaries in its resources section, MultiList and MultiWip. MultiLayer Wiper drops and executes each of these items when run, then deletes them after execution.

T1027.009
Embedded Payloads
MalwareNetwalker

Netwalker's DLL has been embedded within the PowerShell script in hex format.

T1027.009
Embedded Payloads
MalwareSMOKEDHAM

The SMOKEDHAM source code is embedded in the dropper as an encrypted string.

T1027.009
Embedded Payloads
MalwareUroburos

The Uroburos Queue file contains embedded executable files along with key material, communication channels, and modes of operation.

T1027.009
Embedded Payloads
MalwareDEADEYE

The DEADEYE.EMBED variant of DEADEYE has the ability to embed payloads inside of a compiled binary.

T1027.009
Embedded Payloads
MalwareComRAT

ComRAT has embedded a XOR encrypted communications module inside the orchestrator module.

T1027.009
Embedded Payloads
MalwareDEADWOOD

DEADWOOD contains an embedded, AES-encrypted payload labeled METADATA that provides configuration information for follow-on execution.

T1027.009
Embedded Payloads
MalwareDtrack

Dtrack has used a dropper that embeds an encrypted payload as extra data.

T1027.009
Embedded Payloads
ToolInvoke-PSImage

Invoke-PSImage can be used to embed payload data within a new image file.

T1027.009
Embedded Payloads
MalwareCanisterWorm

CanisterWorm has used embedded second stage Base64-encoded payloads.

T1027.010
Command Obfuscation
MalwareIronWind

IronWind has used Base64 encoding and XOR encryption with the key “53” to obfuscate command strings.

T1027.010
Command Obfuscation
MalwareSardonic

Sardonic PowerShell scripts can be encrypted with RC4 and compressed using Gzip.

T1027.010
Command Obfuscation
MalwareUrsnif

Ursnif droppers execute base64 encoded PowerShell commands.

T1027.010
Command Obfuscation
MalwareTsundere Botnet

Tsundere Botnet’s MSI installer has Base64-encoded command execution.

T1027.010
Command Obfuscation
MalwareZeus Panda

Zeus Panda obfuscates the macro commands in its initial payload.

T1027.010
Command Obfuscation
MalwareHavoc

Havoc has utilized XOR encryption with the key “01-01-1900” to obfuscate command strings.

T1027.010
Command Obfuscation
MalwareCARROTBAT

CARROTBAT has the ability to execute obfuscated commands on the infected host.

T1027.010
Command Obfuscation
MalwareEmotet

Emotet has obfuscated macros within malicious documents to hide the URLs hosting the malware, CMD.exe arguments, and PowerShell scripts.

T1027.010
Command Obfuscation
MalwareBADHATCH

BADHATCH malicious PowerShell commands can be encoded with base64.

T1027.010
Command Obfuscation
MalwareMachete

Machete has used pyobfuscate, zlib compression, and base64 encoding for obfuscation. Machete has also used some visual obfuscation techniques by naming variables as combinations of letters to hinder analysis.

T1027.010
Command Obfuscation
MalwareFruitFly

FruitFly executes and stores obfuscated Perl scripts.

T1027.010
Command Obfuscation
MalwareDarkWatchman

DarkWatchman has used Base64 to encode PowerShell commands.

T1027.010
Command Obfuscation
MalwareSHARPSTATS

SHARPSTATS has used base64 encoding and XOR to obfuscate PowerShell scripts.

T1027.010
Command Obfuscation
MalwareNetwalker

Netwalker's PowerShell script has been obfuscated with multiple layers including base64 and hexadecimal encoding and XOR-encryption, as well as obfuscated PowerShell functions and variables.

T1027.010
Command Obfuscation
MalwareQUADAGENT

QUADAGENT was likely obfuscated using `Invoke-Obfuscation`.

T1027.010
Command Obfuscation
MalwareRedLine Stealer

RedLine Stealer has obfuscated scripts within text files used in execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.