Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareMis-Type | Mis-Type has collected files and data from a compromised host. |
| T1008 Fallback Channels |
MalwareMis-Type | Mis-Type first attempts to use a Base64-encoded network protocol over a raw TCP socket for C2, and if that method fails, falls back to a secondary HTTP-based protocol to communicate to an alternate C2 server. |
| T1016 System Network Configuration Discovery |
MalwareMis-Type | Mis-Type may create a file containing the results of the command |
| T1033 System Owner/User Discovery |
MalwareMis-Type | Mis-Type runs tests to determine the privilege level of the compromised user. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMis-Type | Mis-Type saves itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary. |
| T1041 Exfiltration Over C2 Channel |
MalwareMis-Type | Mis-Type has transmitted collected files and data to its C2 server. |
| T1055 Process Injection |
MalwareMis-Type | Mis-Type has been injected directly into a running process, including `explorer.exe`. |
| T1059.003 Windows Command Shell |
MalwareMis-Type | Mis-Type has used `cmd.exe` to run commands on a compromised host. |
| T1071.001 Web Protocols |
MalwareMis-Type | Mis-Type network traffic can communicate over HTTP. |
| T1074.001 Local Data Staging |
MalwareMis-Type | Mis-Type has temporarily stored collected information to the files `“%AppData%\{Unique Identifier}\HOSTRURKLSR”` and `“%AppData%\{Unique Identifier}\NEWERSSEMP”`. |
| T1082 System Information Discovery |
MalwareMis-Type | The initial beacon packet for Mis-Type contains the operating system version and file system of the victim. |
| T1087.001 Local Account |
MalwareMis-Type | Mis-Type may create a file containing the results of the command |
| T1095 Non-Application Layer Protocol |
MalwareMis-Type | Mis-Type network traffic can communicate over a raw socket. |
| T1105 Ingress Tool Transfer |
MalwareMis-Type | Mis-Type has downloaded additional malware and files onto a compromised host. |
| T1106 Native API |
MalwareMis-Type | Mis-Type has used Windows API calls, including `NetUserAdd` and `NetUserDel`. |
| T1132.001 Standard Encoding |
MalwareMis-Type | Mis-Type uses Base64 encoding for C2 traffic. |
| T1136.001 Local Account |
MalwareMis-Type | Mis-Type may create a temporary user on the system named `Lost_{Unique Identifier}`. |
| T1547 Boot or Logon Autostart Execution |
MalwareMis-Type | Mis-Type has created registry keys for persistence, including `HKCU\Software\bkfouerioyou`, `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{6afa8072-b2b1-31a8-b5c1-{Unique Identifier}`, and `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{3BF41072-B2B1-31A8-B5C1-{Unique Identifier}`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.