ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0083×

16 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareMisdat

Misdat has collected files and data from a compromised host.

T1027.002
Software Packing
MalwareMisdat

Misdat was typically packed using UPX.

T1036.005
Match Legitimate Resource Name or Location
MalwareMisdat

Misdat saves itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary.

T1041
Exfiltration Over C2 Channel
MalwareMisdat

Misdat has uploaded files and data to its C2 servers.

T1059.003
Windows Command Shell
MalwareMisdat

Misdat is capable of providing shell functionality to the attacker to execute commands.

T1070.004
File Deletion
MalwareMisdat

Misdat is capable of deleting the backdoor file.

T1070.006
Timestomp
MalwareMisdat

Many Misdat samples were programmed using Borland Delphi, which will mangle the default PE compile timestamp of a file.

T1070.009
Clear Persistence
MalwareMisdat

Misdat is capable of deleting Registry keys used for persistence.

T1082
System Information Discovery
MalwareMisdat

The initial beacon packet for Misdat contains the operating system version of the victim.

T1083
File and Directory Discovery
MalwareMisdat

Misdat is capable of running commands to obtain a list of files and directories, as well as enumerating logical drives.

T1095
Non-Application Layer Protocol
MalwareMisdat

Misdat network traffic communicates over a raw socket.

T1105
Ingress Tool Transfer
MalwareMisdat

Misdat is capable of downloading files from the C2.

T1106
Native API
MalwareMisdat

Misdat has used Windows APIs, including `ExitWindowsEx` and `GetKeyboardType`.

T1132.001
Standard Encoding
MalwareMisdat

Misdat network traffic is Base64-encoded plaintext.

T1547
Boot or Logon Autostart Execution
MalwareMisdat

Misdat has created registry keys for persistence, including `HKCU\Software\dnimtsoleht\StubPath`, `HKCU\Software\snimtsOleht\StubPath`, `HKCU\Software\Backtsaleht\StubPath`, `HKLM\SOFTWARE\Microsoft\Active Setup\Installed. Components\{3bf41072-b2b1-21c8-b5c1-bd56d32fbda7}`, and `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{3ef41072-a2f1-21c8-c5c1-70c2c3bc7905}`.

T1614.001
System Language Discovery
MalwareMisdat

Misdat has attempted to detect if a compromised host had a Japanese keyboard via the Windows API call `GetKeyboardType`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.