ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0084×

18 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareMis-Type

Mis-Type has collected files and data from a compromised host.

T1008
Fallback Channels
MalwareMis-Type

Mis-Type first attempts to use a Base64-encoded network protocol over a raw TCP socket for C2, and if that method fails, falls back to a secondary HTTP-based protocol to communicate to an alternate C2 server.

T1016
System Network Configuration Discovery
MalwareMis-Type

Mis-Type may create a file containing the results of the command cmd.exe /c ipconfig /all.

T1033
System Owner/User Discovery
MalwareMis-Type

Mis-Type runs tests to determine the privilege level of the compromised user.

T1036.005
Match Legitimate Resource Name or Location
MalwareMis-Type

Mis-Type saves itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary.

T1041
Exfiltration Over C2 Channel
MalwareMis-Type

Mis-Type has transmitted collected files and data to its C2 server.

T1055
Process Injection
MalwareMis-Type

Mis-Type has been injected directly into a running process, including `explorer.exe`.

T1059.003
Windows Command Shell
MalwareMis-Type

Mis-Type has used `cmd.exe` to run commands on a compromised host.

T1071.001
Web Protocols
MalwareMis-Type

Mis-Type network traffic can communicate over HTTP.

T1074.001
Local Data Staging
MalwareMis-Type

Mis-Type has temporarily stored collected information to the files `“%AppData%\{Unique Identifier}\HOSTRURKLSR”` and `“%AppData%\{Unique Identifier}\NEWERSSEMP”`.

T1082
System Information Discovery
MalwareMis-Type

The initial beacon packet for Mis-Type contains the operating system version and file system of the victim.

T1087.001
Local Account
MalwareMis-Type

Mis-Type may create a file containing the results of the command cmd.exe /c net user {Username}.

T1095
Non-Application Layer Protocol
MalwareMis-Type

Mis-Type network traffic can communicate over a raw socket.

T1105
Ingress Tool Transfer
MalwareMis-Type

Mis-Type has downloaded additional malware and files onto a compromised host.

T1106
Native API
MalwareMis-Type

Mis-Type has used Windows API calls, including `NetUserAdd` and `NetUserDel`.

T1132.001
Standard Encoding
MalwareMis-Type

Mis-Type uses Base64 encoding for C2 traffic.

T1136.001
Local Account
MalwareMis-Type

Mis-Type may create a temporary user on the system named `Lost_{Unique Identifier}`.

T1547
Boot or Logon Autostart Execution
MalwareMis-Type

Mis-Type has created registry keys for persistence, including `HKCU\Software\bkfouerioyou`, `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{6afa8072-b2b1-31a8-b5c1-{Unique Identifier}`, and `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{3BF41072-B2B1-31A8-B5C1-{Unique Identifier}`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.