ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0089×

25 examples

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareBlackEnergy

BlackEnergy has the capability to communicate over a backup channel via plus.google.com.

T1016
System Network Configuration Discovery
MalwareBlackEnergy

BlackEnergy has gathered information about network IP configurations using ipconfig.exe and about routing tables using route.exe.

T1021.002
SMB/Windows Admin Shares
MalwareBlackEnergy

BlackEnergy has run a plug-in on a victim to spread through the local network by using PsExec and accessing admin shares.

T1046
Network Service Discovery
MalwareBlackEnergy

BlackEnergy has conducted port scans on a host.

T1047
Windows Management Instrumentation
MalwareBlackEnergy

A BlackEnergy 2 plug-in uses WMI to gather victim host details.

T1049
System Network Connections Discovery
MalwareBlackEnergy

BlackEnergy has gathered information about local network connections using netstat.

T1055.001
Dynamic-link Library Injection
MalwareBlackEnergy

BlackEnergy injects its DLL component into svchost.exe.

T1056.001
Keylogging
MalwareBlackEnergy

BlackEnergy has run a keylogger plug-in on a victim.

T1057
Process Discovery
MalwareBlackEnergy

BlackEnergy has gathered a process list by using Tasklist.exe.

T1070
Indicator Removal
MalwareBlackEnergy

BlackEnergy has removed the watermark associated with enabling the TESTSIGNING boot configuration option by removing the relevant strings in the user32.dll.mui of the system.

T1071.001
Web Protocols
MalwareBlackEnergy

BlackEnergy communicates with its C2 server over HTTP.

T1082
System Information Discovery
MalwareBlackEnergy

BlackEnergy has used Systeminfo to gather the OS version, as well as information on the system configuration, BIOS, the motherboard, and the processor.

T1083
File and Directory Discovery
MalwareBlackEnergy

BlackEnergy gathers a list of installed apps from the uninstall program Registry. It also gathers registered mail, browser, and instant messaging clients from the Registry. BlackEnergy has searched for given file types.

T1113
Screen Capture
MalwareBlackEnergy

BlackEnergy is capable of taking screenshots.

T1120
Peripheral Device Discovery
MalwareBlackEnergy

BlackEnergy can gather very specific information about attached USB devices, to include device instance ID and drive geometry.

T1485
Data Destruction
MalwareBlackEnergy

BlackEnergy 2 contains a "Destroy" plug-in that destroys data stored on victim hard drives by overwriting file contents.

T1543.003
Windows Service
MalwareBlackEnergy

One variant of BlackEnergy creates a new service using either a hard-coded or randomly generated name.

T1547.001
Registry Run Keys / Startup Folder
MalwareBlackEnergy

The BlackEnergy 3 variant drops its main DLL component and then creates a .lnk shortcut to that file in the startup folder.

T1547.009
Shortcut Modification
MalwareBlackEnergy

The BlackEnergy 3 variant drops its main DLL component and then creates a .lnk shortcut to that file in the startup folder.

T1548.002
Bypass User Account Control
MalwareBlackEnergy

BlackEnergy attempts to bypass default User Access Control (UAC) settings by exploiting a backward-compatibility setting found in Windows 7 and later.

T1552.001
Credentials In Files
MalwareBlackEnergy

BlackEnergy has used a plug-in to gather credentials stored in files on the host by various software programs, including The Bat! email client, Outlook, and Windows Credential Store.

T1553.006
Code Signing Policy Modification
MalwareBlackEnergy

BlackEnergy has enabled the TESTSIGNING boot configuration option to facilitate loading of a driver component.

T1555.003
Credentials from Web Browsers
MalwareBlackEnergy

BlackEnergy has used a plug-in to gather credentials from web browsers including FireFox, Google Chrome, and Internet Explorer.

T1574.010
Services File Permissions Weakness
MalwareBlackEnergy

One variant of BlackEnergy locates existing driver services that have been disabled and drops its driver component into one of those service's paths, replacing the legitimate executable. The malware then sets the hijacked service to start automatically to establish persistence.

T1685.005
Clear Windows Event Logs
MalwareBlackEnergy

The BlackEnergy component KillDisk is capable of deleting Windows Event Logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.