ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1059.005
Visual Basic
MalwareXbash

Xbash can execute malicious VBScript payloads on the victim’s machine.

T1059.005
Visual Basic
MalwareDarkGate

DarkGate initial infection mechanisms include masquerading as pirated media that launches malicious VBScript on the victim.

T1059.005
Visual Basic
MalwareNanHaiShu

NanHaiShu executes additional VBScript code on the victim's machine.

T1059.005
Visual Basic
MalwareSVCReady

SVCReady has used VBA macros to execute shellcode.

T1059.005
Visual Basic
MalwareFerocious

Ferocious has the ability to use Visual Basic scripts for execution.

T1059.005
Visual Basic
MalwareSaint Bot

Saint Bot has used `.vbs` scripts for execution.

T1059.005
Visual Basic
MalwareChaes

Chaes has used VBscript to execute malicious code.

T1059.005
Visual Basic
MalwareTYPEFRAME

TYPEFRAME has used a malicious Word document for delivery with VBA macros for execution.

T1059.005
Visual Basic
MalwareQUADAGENT

QUADAGENT uses VBScripts.

T1059.005
Visual Basic
MalwareMetamorfo

Metamorfo has used VBS code on victims’ systems.

T1059.005
Visual Basic
MalwareBandook

Bandook has used malicious VBA code against the target system.

T1059.005
Visual Basic
MalwareKerrdown

Kerrdown can use a VBS base64 decoder function published by Motobit.

T1059.005
Visual Basic
MalwareVBShower

VBShower has the ability to execute VBScript files.

T1059.005
Visual Basic
MalwareStoneDrill

StoneDrill has several VBS scripts used throughout the malware's lifecycle.

T1059.005
Visual Basic
MalwareOopsIE

OopsIE creates and uses a VBScript as part of its persistent execution.

T1059.005
Visual Basic
MalwareGrandoreiro

Grandoreiro can use VBScript to execute malicious code.

T1059.005
Visual Basic
MalwareSibot

Sibot executes commands using VBScript.

T1059.005
Visual Basic
MalwareLunarMail

LunarMail has been installed using a VBA macro.

T1059.005
Visual Basic
MalwareCobalt Strike

Cobalt Strike can use VBA to perform execution.

T1059.005
Visual Basic
MalwareSUNBURST

SUNBURST used VBScripts to initiate the execution of payloads.

T1059.005
Visual Basic
MalwareJCry

JCry has used VBS scripts.

T1059.005
Visual Basic
MalwareREvil

REvil has used obfuscated VBA macros for execution.

T1059.005
Visual Basic
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D uses Word macros for execution.

T1059.005
Visual Basic
MalwareNanoCore

NanoCore uses VBS files.

T1059.005
Visual Basic
MalwareIPsec Helper

IPsec Helper can run arbitrary Visual Basic scripts and commands passed to it.

T1059.005
Visual Basic
MalwareDanBot

DanBot can use a VBA macro embedded in an Excel file to drop the payload.

T1059.005
Visual Basic
MalwareRamsay

Ramsay has included embedded Visual Basic scripts in malicious documents.

T1059.005
Visual Basic
MalwareBackConfig

BackConfig has used VBS to install its downloader component and malicious documents with VBA macro code.

T1059.005
Visual Basic
MalwareLookBack

LookBack has used VBA macros in Microsoft Word attachments to drop additional files to the host.

T1059.005
Visual Basic
MalwareLokibot

Lokibot has used VBS scripts and XLS macros for execution.

T1059.005
Visual Basic
MalwarePoetRAT

PoetRAT has used Word documents with VBScripts to execute malicious activities.

T1059.005
Visual Basic
MalwareBabyShark

BabyShark can execute additional VisualBasic content.

T1059.005
Visual Basic
MalwareMelcoz

Melcoz can use VBS scripts to execute malicious DLLs.

T1059.005
Visual Basic
MalwareKOCTOPUS

KOCTOPUS has used VBScript to call wscript to execute a PowerShell command.

T1059.005
Visual Basic
MalwareSTARWHALE

STARWHALE can use the VBScript function `GetRef` as part of its persistence mechanism.

T1059.005
Visual Basic
MalwarePOWERSTATS

POWERSTATS can use VBScript (VBE) code for execution.

T1059.005
Visual Basic
MalwareGoopy

Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2.

T1059.005
Visual Basic
MalwareRemexi

Remexi uses AutoIt and VBS scripts throughout its execution process.

T1059.005
Visual Basic
MalwareAstaroth

Astaroth has used malicious VBS e-mail attachments for execution.

T1059.005
Visual Basic
MalwareQakBot

QakBot can use VBS to download and execute malicious files.

T1059.005
Visual Basic
MalwarejRAT

jRAT has been distributed as HTA files with VBScript.

T1059.005
Visual Basic
MalwareHelminth

One version of Helminth consists of VBScript scripts.

T1059.005
Visual Basic
MalwareComnie

Comnie executes VBS scripts.

T1059.005
Visual Basic
MalwareJSS Loader

JSS Loader can download and execute VBScript files.

T1059.005
Visual Basic
ToolRemcos

Remcos can execute VBS remotely.

T1059.005
Visual Basic
ToolDonut

Donut can generate shellcode outputs that execute via VBScript.

T1059.005
Visual Basic
ToolKoadic

Koadic performs most of its operations using Windows Script Host (VBScript) and runs arbitrary shellcode .

T1059.006
Python
MalwarereGeorg

reGeorg is a Python-based web shell.

T1059.006
Python
MalwareInvisibleFerret

InvisibleFerret is written in Python and has used Python scripts for execution.

T1059.006
Python
MalwareUPSTYLE

UPSTYLE is a Python-based application.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.