ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0085×

20 examples

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareS-Type

S-Type runs the command net start on a victim.

T1008
Fallback Channels
MalwareS-Type

S-Type primarily uses port 80 for C2, but falls back to ports 443 or 8080 if initial communication fails.

T1016
System Network Configuration Discovery
MalwareS-Type

S-Type has used `ipconfig /all` on a compromised host.

T1027.002
Software Packing
MalwareS-Type

Some S-Type samples have been packed with UPX.

T1033
System Owner/User Discovery
MalwareS-Type

S-Type has run tests to determine the privilege level of the compromised user.

T1036.005
Match Legitimate Resource Name or Location
MalwareS-Type

S-Type may save itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary.

T1041
Exfiltration Over C2 Channel
MalwareS-Type

S-Type has uploaded data and files from a compromised host to its C2 servers.

T1059.003
Windows Command Shell
MalwareS-Type

S-Type has provided the ability to execute shell commands on a compromised host.

T1070.004
File Deletion
MalwareS-Type

S-Type has deleted files it has created on a compromised host.

T1070.009
Clear Persistence
MalwareS-Type

S-Type has deleted accounts it has created.

T1071.001
Web Protocols
MalwareS-Type

S-Type uses HTTP for C2.

T1082
System Information Discovery
MalwareS-Type

The initial beacon packet for S-Type contains the operating system version and file system of the victim.

T1087.001
Local Account
MalwareS-Type

S-Type has run the command `net user` on a victim.

T1105
Ingress Tool Transfer
MalwareS-Type

S-Type can download additional files onto a compromised host.

T1106
Native API
MalwareS-Type

S-Type has used Windows APIs, including `GetKeyboardType`, `NetUserAdd`, and `NetUserDel`.

T1132.001
Standard Encoding
MalwareS-Type

S-Type uses Base64 encoding for C2 traffic.

T1136.001
Local Account
MalwareS-Type

S-Type may create a temporary user on the system named `Lost_{Unique Identifier}` with the password `pond~!@6”{Unique Identifier}`.

T1547.001
Registry Run Keys / Startup Folder
MalwareS-Type

S-Type may create a .lnk file to itself that is saved in the Start menu folder. It may also create the Registry key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ IMJPMIJ8.1{3 characters of Unique Identifier}.

T1547.009
Shortcut Modification
MalwareS-Type

S-Type may create the file %HOMEPATH%\Start Menu\Programs\Startup\Realtek {Unique Identifier}.lnk, which points to the malicious `msdtc.exe` file already created in the `%CommonFiles%` directory.

T1614.001
System Language Discovery
MalwareS-Type

S-Type has attempted to determine if a compromised system was using a Japanese keyboard via the `GetKeyboardType` API call.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.