ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0044×

20 examples

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareJHUHUGIT

JHUHUGIT tests if it can reach its C2 server by first attempting a direct connection, and if it fails, obtaining proxy settings and sending the connection through a proxy, and finally injecting code into a running browser if the proxy method fails.

T1016
System Network Configuration Discovery
MalwareJHUHUGIT

A JHUHUGIT variant gathers network interface card information.

T1027.013
Encrypted/Encoded File
MalwareJHUHUGIT

Many strings in JHUHUGIT are obfuscated with a XOR algorithm.

T1037.001
Logon Script (Windows)
MalwareJHUHUGIT

JHUHUGIT has registered a Windows shell script under the Registry key HKCU\Environment\UserInitMprLogonScript to establish persistence.

T1053.005
Scheduled Task
MalwareJHUHUGIT

JHUHUGIT has registered itself as a scheduled task to run each time the current user logs in.

T1055
Process Injection
MalwareJHUHUGIT

JHUHUGIT performs code injection injecting its own functions to browser processes.

T1057
Process Discovery
MalwareJHUHUGIT

JHUHUGIT obtains a list of running processes on the victim.

T1059.003
Windows Command Shell
MalwareJHUHUGIT

JHUHUGIT uses a .bat file to execute a .dll.

T1068
Exploitation for Privilege Escalation
MalwareJHUHUGIT

JHUHUGIT has exploited CVE-2015-1701 and CVE-2015-2387 to escalate privileges.

T1070.004
File Deletion
MalwareJHUHUGIT

The JHUHUGIT dropper can delete itself from the victim. Another JHUHUGIT variant has the capability to delete specified files.

T1071.001
Web Protocols
MalwareJHUHUGIT

JHUHUGIT variants have communicated with C2 servers over HTTP and HTTPS.

T1105
Ingress Tool Transfer
MalwareJHUHUGIT

JHUHUGIT can retrieve an additional payload from its C2 server. JHUHUGIT has a command to download files to the victim’s machine.

T1113
Screen Capture
MalwareJHUHUGIT

A JHUHUGIT variant takes screenshots by simulating the user pressing the "Take Screenshot" key (VK_SCREENSHOT), accessing the screenshot saved in the clipboard, and converting it to a JPG image.

T1115
Clipboard Data
MalwareJHUHUGIT

A JHUHUGIT variant accesses a screenshot saved in the clipboard and converts it to a JPG image.

T1132.001
Standard Encoding
MalwareJHUHUGIT

A JHUHUGIT variant encodes C2 POST data base64.

T1218.011
Rundll32
MalwareJHUHUGIT

JHUHUGIT is executed using rundll32.exe.

T1543.003
Windows Service
MalwareJHUHUGIT

JHUHUGIT has registered itself as a service to establish persistence.

T1546.015
Component Object Model Hijacking
MalwareJHUHUGIT

JHUHUGIT has used COM hijacking to establish persistence by hijacking a class named MMDeviceEnumerator and also by registering the payload as a Shell Icon Overlay handler COM object ({3543619C-D563-43f7-95EA-4DA7E1CC396A}).

T1547.001
Registry Run Keys / Startup Folder
MalwareJHUHUGIT

JHUHUGIT has used a Registry Run key to establish persistence by executing JavaScript code within the rundll32.exe process.

T1680
Local Storage Discovery
MalwareJHUHUGIT

JHUHUGIT obtains a build identifier as well as victim hard drive information from Windows registry key HKLM\SYSTEM\CurrentControlSet\Services\Disk\Enum. Another JHUHUGIT variant gathers the victim storage volume serial number and the storage device name.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.