ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0032×

24 examples

TechniqueUsed byProcedure example
T1012
Query Registry
Malwaregh0st RAT

gh0st RAT has checked for the existence of a Service key to determine if it has already been installed on the system.

T1055
Process Injection
Malwaregh0st RAT

gh0st RAT can inject malicious code into process created by the “Command_Create&Inject” function.

T1056.001
Keylogging
Malwaregh0st RAT

gh0st RAT has a keylogger.

T1057
Process Discovery
Malwaregh0st RAT

gh0st RAT has the capability to list processes.

T1059
Command and Scripting Interpreter
Malwaregh0st RAT

gh0st RAT is able to open a remote shell to execute commands.

T1070.004
File Deletion
Malwaregh0st RAT

gh0st RAT has the capability to to delete files.

T1082
System Information Discovery
Malwaregh0st RAT

gh0st RAT has gathered system architecture, processor, OS configuration, and installed hardware information.

T1095
Non-Application Layer Protocol
Malwaregh0st RAT

gh0st RAT has used an encrypted protocol within TCP segments to communicate with the C2.

T1105
Ingress Tool Transfer
Malwaregh0st RAT

gh0st RAT can download files to the victim’s machine.

T1106
Native API
Malwaregh0st RAT

gh0st RAT has used the `InterlockedExchange`, `SeShutdownPrivilege`, and `ExitWindowsEx` Windows API functions.

T1112
Modify Registry
Malwaregh0st RAT

gh0st RAT has altered the InstallTime subkey.

T1113
Screen Capture
Malwaregh0st RAT

gh0st RAT can capture the victim’s screen remotely.

T1129
Shared Modules
Malwaregh0st RAT

gh0st RAT can load DLLs into memory.

T1132.001
Standard Encoding
Malwaregh0st RAT

gh0st RAT has used Zlib to compress C2 communications data before encrypting it.

T1140
Deobfuscate/Decode Files or Information
Malwaregh0st RAT

gh0st RAT has decrypted and loaded the gh0st RAT DLL into memory, once the initial dropper executable is launched.

T1218.011
Rundll32
Malwaregh0st RAT

A gh0st RAT variant has used rundll32 for execution.

T1543.003
Windows Service
Malwaregh0st RAT

gh0st RAT can create a new service to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
Malwaregh0st RAT

gh0st RAT has added a Registry Run key to establish persistence.

T1568.001
Fast Flux DNS
Malwaregh0st RAT

gh0st RAT operators have used dynamic DNS to mask the true location of their C2 behind rapidly changing IP addresses.

T1569.002
Service Execution
Malwaregh0st RAT

gh0st RAT can execute its service if the Service key exists. If the key does not exist, gh0st RAT will create and run the service.

T1573
Encrypted Channel
Malwaregh0st RAT

gh0st RAT has encrypted TCP communications to evade detection.

T1573.001
Symmetric Cryptography
Malwaregh0st RAT

gh0st RAT uses RC4 and XOR to encrypt C2 traffic.

T1574.001
DLL
Malwaregh0st RAT

A gh0st RAT variant has used DLL side-loading.

T1685.005
Clear Windows Event Logs
Malwaregh0st RAT

gh0st RAT is able to wipe event logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.