ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0062×

19 examples

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareDustySky

DustySky has two hard-coded domains for C2 servers; if the first does not respond, it will try the second.

T1027
Obfuscated Files or Information
MalwareDustySky

The DustySky dropper uses a function to obfuscate the name of functions and other parts of the malware.

T1041
Exfiltration Over C2 Channel
MalwareDustySky

DustySky has exfiltrated data to the C2 server.

T1047
Windows Management Instrumentation
MalwareDustySky

The DustySky dropper uses Windows Management Instrumentation to extract information about the operating system and whether an anti-virus is active.

T1056.001
Keylogging
MalwareDustySky

DustySky contains a keylogger.

T1057
Process Discovery
MalwareDustySky

DustySky collects information about running processes from victims.

T1070.004
File Deletion
MalwareDustySky

DustySky can delete files it creates from the infected system.

T1071.001
Web Protocols
MalwareDustySky

DustySky has used both HTTP and HTTPS for C2.

T1074.001
Local Data Staging
MalwareDustySky

DustySky created folders in temp directories to host collected files before exfiltration.

T1082
System Information Discovery
MalwareDustySky

DustySky extracts basic information about the operating system.

T1083
File and Directory Discovery
MalwareDustySky

DustySky scans the victim for files that contain certain keywords and document types including PDF, DOC, DOCX, XLS, and XLSX, from a list that is obtained from the C2 as a text file. It can also identify logical drives for the infected machine.

T1091
Replication Through Removable Media
MalwareDustySky

DustySky searches for removable media and duplicates itself onto it.

T1113
Screen Capture
MalwareDustySky

DustySky captures PNG screenshots of the main screen.

T1120
Peripheral Device Discovery
MalwareDustySky

DustySky can detect connected USB devices.

T1518
Software Discovery
MalwareDustySky

DustySky lists all installed software for the infected machine.

T1518.001
Security Software Discovery
MalwareDustySky

DustySky checks for the existence of anti-virus.

T1547.001
Registry Run Keys / Startup Folder
MalwareDustySky

DustySky achieves persistence by creating a Registry entry in HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.

T1560.001
Archive via Utility
MalwareDustySky

DustySky can compress files via RAR while staging data to be exfiltrated.

T1570
Lateral Tool Transfer
MalwareDustySky

DustySky searches for network drives and removable media and duplicates itself onto them.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.