ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0013×

49 examples

TechniqueUsed byProcedure example
T1012
Query Registry
MalwarePlugX

PlugX can enumerate and query for information contained within the Windows Registry.

T1016
System Network Configuration Discovery
MalwarePlugX

PlugX has captured victim IP address details of the targeted machine.

T1027
Obfuscated Files or Information
MalwarePlugX

PlugX can use API hashing and modify the names of strings to evade detection.

T1027.001
Binary Padding
MalwarePlugX

PlugX has utilized junk code and opaque predicates in payloads to hinder analysis.

T1027.007
Dynamic API Resolution
MalwarePlugX

PlugX has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API.

T1027.013
Encrypted/Encoded File
MalwarePlugX

PlugX has leveraged XOR encryption with the key of 123456789.

T1033
System Owner/User Discovery
MalwarePlugX

PlugX has the ability to gather the username from the victim’s machine.

T1036.004
Masquerade Task or Service
MalwarePlugX

In one instance, menuPass added PlugX as a service with a display name of "Corel Writing Tools Utility."

T1036.005
Match Legitimate Resource Name or Location
MalwarePlugX

PlugX has been disguised as legitimate Adobe and PotPlayer files. PlugX has also imitated legitimate software directories and file names through the creation and storage of a legitimate EXE and the malicious DLLs.

T1041
Exfiltration Over C2 Channel
MalwarePlugX

PlugX has exfiltrated stolen data and files to its C2 server.

T1049
System Network Connections Discovery
MalwarePlugX

PlugX has a module for enumerating TCP and UDP network connections and associated processes using the netstat command.

T1053.005
Scheduled Task
MalwarePlugX

PlugX has created a scheduled task to execute additional malicious software, as well as maintain persistence.

T1056.001
Keylogging
MalwarePlugX

PlugX has a module for capturing keystrokes per process including window titles.

T1057
Process Discovery
MalwarePlugX

PlugX has a module to list the processes running on a machine.

T1059.003
Windows Command Shell
MalwarePlugX

PlugX allows actors to spawn a reverse shell on a victim.

T1070.004
File Deletion
MalwarePlugX

PlugX has the remove itself and other artifacts.

T1070.009
Clear Persistence
MalwarePlugX

PlugX has deleted registry keys that store data and maintained persistence.

T1071.001
Web Protocols
MalwarePlugX

PlugX can be configured to use HTTP for command and control. PlugX has also used HTTPS for C2.

T1071.004
DNS
MalwarePlugX

PlugX can be configured to use DNS for command and control.

T1074.001
Local Data Staging
MalwarePlugX

PlugX has collected and staged the victim’s computer files for exfiltration.

T1082
System Information Discovery
MalwarePlugX

PlugX has collected system information including OS version, processor information, RAM size, location, host name, IP, and screen size of the infected host.

T1083
File and Directory Discovery
MalwarePlugX

PlugX has a module to enumerate drives and find files recursively. PlugX has also checked the path from which it is running for specific parameters prior to execution.

T1091
Replication Through Removable Media
MalwarePlugX

PlugX has copied itself to infected removable drives for propagation to other victim devices.

T1095
Non-Application Layer Protocol
MalwarePlugX

PlugX can be configured to use raw TCP or UDP for command and control.

T1102.001
Dead Drop Resolver
MalwarePlugX

PlugX uses Pastebin to store C2 addresses.

T1105
Ingress Tool Transfer
MalwarePlugX

PlugX has a module to download and execute files on the compromised machine.

T1106
Native API
MalwarePlugX

PlugX can use the Windows API functions `GetProcAddress`, `LoadLibrary`, and `CreateProcess` to execute another process.

T1112
Modify Registry
MalwarePlugX

PlugX has a module to create, delete, or modify Registry keys.

T1113
Screen Capture
MalwarePlugX

PlugX allows the operator to capture screenshots.

T1120
Peripheral Device Discovery
MalwarePlugX

PlugX can identify removable media attached to compromised hosts.

T1124
System Time Discovery
MalwarePlugX

PlugX has identified system time through its GetSystemInfo command.

T1127.001
MSBuild
MalwarePlugX

A version of PlugX loads as shellcode within a .NET Framework project using msbuild.exe, presumably to bypass application control techniques.

T1135
Network Share Discovery
MalwarePlugX

PlugX has a module to enumerate network shares.

T1140
Deobfuscate/Decode Files or Information
MalwarePlugX

PlugX decompresses and decrypts itself using the Microsoft API call RtlDecompressBuffer. PlugX has also decrypted its payloads in memory.

T1204.002
Malicious File
MalwarePlugX

PlugX has leveraged an initial executable disguised as a legitimate document to trick the target into opening it.

T1480.002
Mutual Exclusion
MalwarePlugX

PlugX has leveraged a mutex in its infection process.

T1497.001
System Checks
MalwarePlugX

PlugX checks if VMware tools is running in the background by searching for any process named "vmtoolsd".

T1543.003
Windows Service
MalwarePlugX

PlugX can be added as a service to establish persistence. PlugX also has a module to change service configurations as well as start, control, and delete services.

T1547.001
Registry Run Keys / Startup Folder
MalwarePlugX

PlugX adds Run key entries in the Registry to establish persistence. PlugX has established persistence via the registry keys `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run`.

T1564.001
Hidden Files and Directories
MalwarePlugX

PlugX can modify the characteristics of folders to hide them from the compromised user. PlugX has also modified file attributes to hidden and system.

T1564.003
Hidden Window
MalwarePlugX

PlugX has the ability to execute a command on a hidden desktop.

T1571
Non-Standard Port
MalwarePlugX

PlugX has used random, high-number, non-standard ports to listen for subsequent actions and C2 activities.

T1573.001
Symmetric Cryptography
MalwarePlugX

PlugX can use RC4 encryption in C2 communications.

T1574.001
DLL
MalwarePlugX

PlugX has the ability to use DLL search order hijacking for installation on targeted systems. PlugX has also used DLL side-loading to evade anti-virus. PlugX has also used a legitimately signed executable to side-load a malicious payload within a DLL file.

T1614
System Location Discovery
MalwarePlugX

PlugX has obtained the location of the victim device by leveraging `GetSystemDefaultLCID`.

T1620
Reflective Code Loading
MalwarePlugX

PlugX has loaded its payload into memory.

T1622
Debugger Evasion
MalwarePlugX

PlugX has made calls to Windows API `CheckRemoteDebuggerPresent` and exits if it detects a debugger.

T1680
Local Storage Discovery
MalwarePlugX

PlugX has collected a list of all mapped drives on the infected host.

T1686
Disable or Modify System Firewall
MalwarePlugX

PlugX has modified local firewall rules on victim machines to enable a random, high-number listening port for subsequent access and C2 activity.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.