ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0021×

18 examples

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareDerusbi

Derusbi uses a backup communication method with an HTTP beacon.

T1012
Query Registry
MalwareDerusbi

Derusbi is capable of enumerating Registry keys and values.

T1033
System Owner/User Discovery
MalwareDerusbi

A Linux version of Derusbi checks if the victim user ID is anything other than zero (normally used for root), and the malware will not execute if it does not have root privileges. Derusbi also gathers the username of the victim.

T1055.001
Dynamic-link Library Injection
MalwareDerusbi

Derusbi injects itself into the secure shell (SSH) process.

T1056.001
Keylogging
MalwareDerusbi

Derusbi is capable of logging keystrokes.

T1057
Process Discovery
MalwareDerusbi

Derusbi collects current and parent process IDs.

T1059.004
Unix Shell
MalwareDerusbi

Derusbi is capable of creating a remote Bash shell and executing commands.

T1070.004
File Deletion
MalwareDerusbi

Derusbi is capable of deleting files. It has been observed loading a Linux Kernel Module (LKM) and then deleting it from the hard disk as well as overwriting the data with null bytes.

T1070.006
Timestomp
MalwareDerusbi

The Derusbi malware supports timestomping.

T1082
System Information Discovery
MalwareDerusbi

Derusbi gathers the name of the local host, version of GNU Compiler Collection (GCC), and the system information about the CPU, machine, and operating system.

T1083
File and Directory Discovery
MalwareDerusbi

Derusbi is capable of obtaining directory, file, and drive listings.

T1095
Non-Application Layer Protocol
MalwareDerusbi

Derusbi binds to a raw socket on a random source port between 31800 and 31900 for C2.

T1113
Screen Capture
MalwareDerusbi

Derusbi is capable of performing screen captures.

T1123
Audio Capture
MalwareDerusbi

Derusbi is capable of performing audio captures.

T1125
Video Capture
MalwareDerusbi

Derusbi is capable of capturing video.

T1218.010
Regsvr32
MalwareDerusbi

Derusbi variants have been seen that use Registry persistence to proxy execution through regsvr32.exe.

T1571
Non-Standard Port
MalwareDerusbi

Derusbi has used unencrypted HTTP on port 443 for C2.

T1573.001
Symmetric Cryptography
MalwareDerusbi

Derusbi obfuscates C2 traffic with variable 4-byte XOR keys.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.