ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0081×

19 examples

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareElise

Elise executes net start after initial communication is made to the remote server.

T1016
System Network Configuration Discovery
MalwareElise

Elise executes ipconfig /all after initial communication is made to the remote server.

T1027.013
Encrypted/Encoded File
MalwareElise

Elise encrypts several of its files, including configuration files.

T1036.005
Match Legitimate Resource Name or Location
MalwareElise

If installing itself as a service fails, Elise instead writes itself as a file named svchost.exe saved in %APPDATA%\Microsoft\Network.

T1055.001
Dynamic-link Library Injection
MalwareElise

Elise injects DLL files into iexplore.exe.

T1057
Process Discovery
MalwareElise

Elise enumerates processes via the tasklist command.

T1070.004
File Deletion
MalwareElise

Elise is capable of launching a remote shell on the host to delete itself.

T1070.006
Timestomp
MalwareElise

Elise performs timestomping of a CAB file it creates.

T1071.001
Web Protocols
MalwareElise

Elise communicates over HTTP or HTTPS for C2.

T1074.001
Local Data Staging
MalwareElise

Elise creates a file in AppData\Local\Microsoft\Windows\Explorer and stores all harvested data in that file.

T1082
System Information Discovery
MalwareElise

Elise executes systeminfo after initial communication is made to the remote server.

T1083
File and Directory Discovery
MalwareElise

A variant of Elise executes dir C:\progra~1 when initially run.

T1087.001
Local Account
MalwareElise

Elise executes net user after initial communication is made to the remote server.

T1105
Ingress Tool Transfer
MalwareElise

Elise can download additional files from the C2 server for execution.

T1132.001
Standard Encoding
MalwareElise

Elise exfiltrates data using cookie values that are Base64-encoded.

T1218.011
Rundll32
MalwareElise

After copying itself to a DLL file, a variant of Elise calls the DLL file using rundll32.exe.

T1543.003
Windows Service
MalwareElise

Elise configures itself as a service.

T1547.001
Registry Run Keys / Startup Folder
MalwareElise

If establishing persistence by installation as a new service fails, one variant of Elise establishes persistence for the created .exe file by setting the following Registry key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\svchost : %APPDATA%\Microsoft\Network\svchost.exe. Other variants have set the following Registry keys for persistence: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\imejp : [self] and HKCU\Software\Microsoft\Windows\CurrentVersion\Run\IAStorD.

T1573.001
Symmetric Cryptography
MalwareElise

Elise encrypts exfiltrated data with RC4.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.