ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0022×

36 examples

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwareUroburos

Uroburos can add extra characters in encoded strings to help mimic DNS legitimate requests.

T1001.003
Protocol or Service Impersonation
MalwareUroburos

Uroburos can use custom communication methodologies that ride over common protocols including TCP, UDP, HTTP, SMTP, and DNS in order to blend with normal network traffic.

T1005
Data from Local System
MalwareUroburos

Uroburos can use its `Get` command to exfiltrate specified files from the compromised system.

T1008
Fallback Channels
MalwareUroburos

Uroburos can use up to 10 channels to communicate between implants.

T1012
Query Registry
MalwareUroburos

Uroburos can query the Registry, typically `HKLM:\SOFTWARE\Classes\.wav\OpenWithProgIds`, to find the key and path to decrypt and load its kernel driver and kernel driver loader.

T1014
Rootkit
MalwareUroburos

Uroburos can use its kernel module to prevent its host components from being listed by the targeted system's OS and to mediate requests between user mode and concealed components.

T1027.002
Software Packing
MalwareUroburos

Uroburos uses a custom packer.

T1027.009
Embedded Payloads
MalwareUroburos

The Uroburos Queue file contains embedded executable files along with key material, communication channels, and modes of operation.

T1027.011
Fileless Storage
MalwareUroburos

Uroburos can store configuration information for the kernel driver and kernel driver loader components in an encrypted blob typically found at `HKLM:\SOFTWARE\Classes\.wav\OpenWithProgIds.`

T1027.013
Encrypted/Encoded File
MalwareUroburos

Uroburos can use AES and CAST-128 encryption to obfuscate resources.

T1036.004
Masquerade Task or Service
MalwareUroburos

Uroburos has registered a service named `WerFaultSvc`, likely to spoof the legitimate Windows error reporting service.

T1055.001
Dynamic-link Library Injection
MalwareUroburos

Uroburos can use DLL injection to load embedded files and modules.

T1057
Process Discovery
MalwareUroburos

Uroburos can use its `Process List` command to enumerate processes on compromised hosts.

T1059.003
Windows Command Shell
MalwareUroburos

Uroburos has the ability to use the command line for execution on the targeted system.

T1070.004
File Deletion
MalwareUroburos

Uroburos can run a `Clear Agents Track` command on an infected machine to delete Uroburos-related logs.

T1071.001
Web Protocols
MalwareUroburos

Uroburos can use a custom HTTP-based protocol for large data communications that can blend with normal network traffic by riding on top of standard HTTP.

T1071.003
Mail Protocols
MalwareUroburos

Uroburos can use custom communications protocols that ride over SMTP.

T1071.004
DNS
MalwareUroburos

Uroburos has encoded outbound C2 communications in DNS requests consisting of character strings made to resemble standard domain names. The actual information transmitted by Uroburos is contained in the part of the character string prior to the first ‘.’ character.

T1082
System Information Discovery
MalwareUroburos

Uroburos has the ability to gather basic system information and run the POSIX API `gethostbyname`.

T1083
File and Directory Discovery
MalwareUroburos

Uroburos can search for specific files on a compromised system.

T1090.003
Multi-hop Proxy
MalwareUroburos

Uroburos can use implants on multiple compromised machines to proxy communications through its worldwide P2P network.

T1095
Non-Application Layer Protocol
MalwareUroburos

Uroburos can communicate through custom methodologies for UDP, ICMP, and TCP that use distinct sessions to ride over the legitimate protocols.

T1104
Multi-Stage Channels
MalwareUroburos

Individual Uroburos implants can use multiple communication channels based on one of four available modes of operation.

T1105
Ingress Tool Transfer
MalwareUroburos

Uroburos can use a `Put` command to write files to an infected machine.

T1106
Native API
MalwareUroburos

Uroburos can use native Windows APIs including `GetHostByName`.

T1112
Modify Registry
MalwareUroburos

Uroburos can store configuration information in the Registry including the initialization vector and AES key needed to find and decrypt other Uroburos components.

T1132.002
Non-Standard Encoding
MalwareUroburos

Uroburos can use a custom base62 and a de-facto base32 encoding that uses digits 0-9 and lowercase letters a-z in C2 communications.

T1140
Deobfuscate/Decode Files or Information
MalwareUroburos

Uroburos can decrypt command parameters sent through C2 and use unpacking code to extract its packed executable.

T1205
Traffic Signaling
MalwareUroburos

Uroburos can intercept the first client to server packet in the 3-way TCP handshake to determine if the packet contains the correct unique value for a specific Uroburos implant. If the value does not match, the packet and the rest of the TCP session are passed to the legitimate listening application.

T1543.003
Windows Service
MalwareUroburos

Uroburos has registered a service, typically named `WerFaultSvc`, to decrypt and find a kernel driver and kernel driver loader to maintain persistence.

T1559
Inter-Process Communication
MalwareUroburos

Uroburos has the ability to move data between its kernel and user mode components, generally using named pipes.

T1564.005
Hidden File System
MalwareUroburos

Uroburos can use concealed storage mechanisms including an NTFS or FAT-16 filesystem encrypted with CAST-128 in CBC mode.

T1572
Protocol Tunneling
MalwareUroburos

Uroburos has the ability to communicate over custom communications methodologies that ride over common network protocols including raw TCP and UDP sockets, HTTP, SMTP, and DNS.

T1573.001
Symmetric Cryptography
MalwareUroburos

Uroburos can encrypt the data beneath its http2 or tcp encryption at the session layer with CAST-128, using a different key for incoming and outgoing data.

T1573.002
Asymmetric Cryptography
MalwareUroburos

Uroburos has used a combination of a Diffie-Hellman key exchange mixed with a pre-shared key (PSK) to encrypt its top layer of C2 communications.

T1620
Reflective Code Loading
MalwareUroburos

Uroburos has the ability to load new modules directly into memory using its `Load Modules Mem` command.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.