Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareElise | Elise executes |
| T1016 System Network Configuration Discovery |
MalwareElise | Elise executes |
| T1027.013 Encrypted/Encoded File |
MalwareElise | Elise encrypts several of its files, including configuration files. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareElise | If installing itself as a service fails, Elise instead writes itself as a file named svchost.exe saved in %APPDATA%\Microsoft\Network. |
| T1055.001 Dynamic-link Library Injection |
MalwareElise | Elise injects DLL files into iexplore.exe. |
| T1057 Process Discovery |
MalwareElise | Elise enumerates processes via the |
| T1070.004 File Deletion |
MalwareElise | Elise is capable of launching a remote shell on the host to delete itself. |
| T1070.006 Timestomp |
MalwareElise | Elise performs timestomping of a CAB file it creates. |
| T1071.001 Web Protocols |
MalwareElise | Elise communicates over HTTP or HTTPS for C2. |
| T1074.001 Local Data Staging |
MalwareElise | Elise creates a file in |
| T1082 System Information Discovery |
MalwareElise | Elise executes |
| T1083 File and Directory Discovery |
MalwareElise | A variant of Elise executes |
| T1087.001 Local Account |
MalwareElise | Elise executes |
| T1105 Ingress Tool Transfer |
MalwareElise | Elise can download additional files from the C2 server for execution. |
| T1132.001 Standard Encoding |
MalwareElise | Elise exfiltrates data using cookie values that are Base64-encoded. |
| T1218.011 Rundll32 |
MalwareElise | After copying itself to a DLL file, a variant of Elise calls the DLL file using rundll32.exe. |
| T1543.003 Windows Service |
MalwareElise | Elise configures itself as a service. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareElise | If establishing persistence by installation as a new service fails, one variant of Elise establishes persistence for the created .exe file by setting the following Registry key: |
| T1573.001 Symmetric Cryptography |
MalwareElise | Elise encrypts exfiltrated data with RC4. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.