ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0038×

21 examples

TechniqueUsed byProcedure example
T1001.002
Steganography
MalwareDuqu

When the Duqu command and control is operating over HTTP or HTTPS, Duqu uploads data to its controller by appending it to a blank JPG file.

T1010
Application Window Discovery
MalwareDuqu

The discovery modules used with Duqu can collect information on open windows.

T1016
System Network Configuration Discovery
MalwareDuqu

The reconnaissance modules used with Duqu can collect information on network configuration.

T1021.002
SMB/Windows Admin Shares
MalwareDuqu

Adversaries can instruct Duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials (via keylogging or other means). The remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware.

T1049
System Network Connections Discovery
MalwareDuqu

The discovery modules used with Duqu can collect information on network connections.

T1053.005
Scheduled Task
MalwareDuqu

Adversaries can instruct Duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials (via keylogging or other means). The remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware.

T1055.001
Dynamic-link Library Injection
MalwareDuqu

Duqu will inject itself into different processes to evade detection. The selection of the target process is influenced by the security software that is installed on the system (Duqu will inject into different processes depending on which security suite is installed on the infected host).

T1055.012
Process Hollowing
MalwareDuqu

Duqu is capable of loading executable code via process hollowing.

T1056.001
Keylogging
MalwareDuqu

Duqu can track key presses with a keylogger module.

T1057
Process Discovery
MalwareDuqu

The discovery modules used with Duqu can collect information on process details.

T1071
Application Layer Protocol
MalwareDuqu

Duqu uses a custom command and control protocol that communicates over commonly used ports, and is frequently encapsulated by application layer protocols.

T1074.001
Local Data Staging
MalwareDuqu

Modules can be pushed to and executed by Duqu that copy data to a staging area, compress it, and XOR encrypt it.

T1078
Valid Accounts
MalwareDuqu

Adversaries can instruct Duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials (via keylogging or other means). The remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware.

T1087.001
Local Account
MalwareDuqu

The discovery modules used with Duqu can collect information on accounts and permissions.

T1090.001
Internal Proxy
MalwareDuqu

Duqu can be configured to have commands relayed over a peer-to-peer network of infected hosts if some of the hosts do not have Internet access.

T1134
Access Token Manipulation
MalwareDuqu

Duqu examines running system processes for tokens that have specific system privileges. If it finds one, it will copy the token and store it for later use. Eventually it will start new processes with the stored token attached. It can also steal tokens to acquire administrative privileges.

T1218.007
Msiexec
MalwareDuqu

Duqu has used msiexec to execute malicious Windows Installer packages. Additionally, a PROPERTY=VALUE pair containing a 56-bit encryption key has been used to decrypt the main payload from the installer packages.

T1543.003
Windows Service
MalwareDuqu

Duqu creates a new service that loads a malicious driver when the system starts. When Duqu is active, the operating system believes that the driver is legitimate, as it has been signed with a valid private key.

T1560.003
Archive via Custom Method
MalwareDuqu

Modules can be pushed to and executed by Duqu that copy data to a staging area, compress it, and XOR encrypt it.

T1572
Protocol Tunneling
MalwareDuqu

Duqu uses a custom command and control protocol that communicates over commonly used ports, and is frequently encapsulated by application layer protocols.

T1573.001
Symmetric Cryptography
MalwareDuqu

The Duqu command and control protocol's data stream can be encrypted with AES-CBC.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.