Real-world descriptions of how a group, tool or campaign used a technique.
20 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
MalwareJHUHUGIT | JHUHUGIT tests if it can reach its C2 server by first attempting a direct connection, and if it fails, obtaining proxy settings and sending the connection through a proxy, and finally injecting code into a running browser if the proxy method fails. |
| T1016 System Network Configuration Discovery |
MalwareJHUHUGIT | A JHUHUGIT variant gathers network interface card information. |
| T1027.013 Encrypted/Encoded File |
MalwareJHUHUGIT | Many strings in JHUHUGIT are obfuscated with a XOR algorithm. |
| T1037.001 Logon Script (Windows) |
MalwareJHUHUGIT | JHUHUGIT has registered a Windows shell script under the Registry key |
| T1053.005 Scheduled Task |
MalwareJHUHUGIT | JHUHUGIT has registered itself as a scheduled task to run each time the current user logs in. |
| T1055 Process Injection |
MalwareJHUHUGIT | JHUHUGIT performs code injection injecting its own functions to browser processes. |
| T1057 Process Discovery |
MalwareJHUHUGIT | JHUHUGIT obtains a list of running processes on the victim. |
| T1059.003 Windows Command Shell |
MalwareJHUHUGIT | JHUHUGIT uses a .bat file to execute a .dll. |
| T1068 Exploitation for Privilege Escalation |
MalwareJHUHUGIT | JHUHUGIT has exploited CVE-2015-1701 and CVE-2015-2387 to escalate privileges. |
| T1070.004 File Deletion |
MalwareJHUHUGIT | The JHUHUGIT dropper can delete itself from the victim. Another JHUHUGIT variant has the capability to delete specified files. |
| T1071.001 Web Protocols |
MalwareJHUHUGIT | JHUHUGIT variants have communicated with C2 servers over HTTP and HTTPS. |
| T1105 Ingress Tool Transfer |
MalwareJHUHUGIT | JHUHUGIT can retrieve an additional payload from its C2 server. JHUHUGIT has a command to download files to the victim’s machine. |
| T1113 Screen Capture |
MalwareJHUHUGIT | A JHUHUGIT variant takes screenshots by simulating the user pressing the "Take Screenshot" key (VK_SCREENSHOT), accessing the screenshot saved in the clipboard, and converting it to a JPG image. |
| T1115 Clipboard Data |
MalwareJHUHUGIT | A JHUHUGIT variant accesses a screenshot saved in the clipboard and converts it to a JPG image. |
| T1132.001 Standard Encoding |
MalwareJHUHUGIT | A JHUHUGIT variant encodes C2 POST data base64. |
| T1218.011 Rundll32 |
MalwareJHUHUGIT | JHUHUGIT is executed using rundll32.exe. |
| T1543.003 Windows Service |
MalwareJHUHUGIT | JHUHUGIT has registered itself as a service to establish persistence. |
| T1546.015 Component Object Model Hijacking |
MalwareJHUHUGIT | JHUHUGIT has used COM hijacking to establish persistence by hijacking a class named MMDeviceEnumerator and also by registering the payload as a Shell Icon Overlay handler COM object ({3543619C-D563-43f7-95EA-4DA7E1CC396A}). |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareJHUHUGIT | JHUHUGIT has used a Registry Run key to establish persistence by executing JavaScript code within the rundll32.exe process. |
| T1680 Local Storage Discovery |
MalwareJHUHUGIT | JHUHUGIT obtains a build identifier as well as victim hard drive information from Windows registry key |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.