ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0091×

22 examples

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareEpic

Epic uses the tasklist /svc command to list the services on the system.

T1012
Query Registry
MalwareEpic

Epic uses the rem reg query command to obtain values from Registry keys.

T1016
System Network Configuration Discovery
MalwareEpic

Epic uses the nbtstat -n and nbtstat -s commands on the victim’s machine.

T1018
Remote System Discovery
MalwareEpic

Epic uses the net view command on the victim’s machine.

T1027
Obfuscated Files or Information
MalwareEpic

Epic heavily obfuscates its code to make analysis more difficult.

T1033
System Owner/User Discovery
MalwareEpic

Epic collects the user name from the victim’s machine.

T1049
System Network Connections Discovery
MalwareEpic

Epic uses the net use, net session, and netstat commands to gather information on network connections.

T1055.011
Extra Window Memory Injection
MalwareEpic

Epic has overwritten the function pointer in the extra window memory of Explorer's Shell_TrayWnd in order to execute malicious code in the context of the explorer.exe process.

T1057
Process Discovery
MalwareEpic

Epic uses the tasklist /v command to obtain a list of processes.

T1069.001
Local Groups
MalwareEpic

Epic gathers information on local group names.

T1070.004
File Deletion
MalwareEpic

Epic has a command to delete a file from the machine.

T1071.001
Web Protocols
MalwareEpic

Epic uses HTTP and HTTPS for C2 communications.

T1082
System Information Discovery
MalwareEpic

Epic collects the OS version, hardware information, computer name, available system memory status, and system and user language settings.

T1083
File and Directory Discovery
MalwareEpic

Epic recursively searches for all .doc files on the system and collects a directory listing of the Desktop, %TEMP%, and %WINDOWS%\Temp directories.

T1087.001
Local Account
MalwareEpic

Epic gathers a list of all user accounts, privilege classes, and time of last logon.

T1124
System Time Discovery
MalwareEpic

Epic uses the net time command to get the system time from the machine and collect the current date and time zone information.

T1518.001
Security Software Discovery
MalwareEpic

Epic searches for anti-malware services running on the victim’s machine and terminates itself if it finds them.

T1553.002
Code Signing
MalwareEpic

Turla has used valid digital certificates from Sysprint AG to sign its Epic dropper.

T1560
Archive Collected Data
MalwareEpic

Epic encrypts collected data using a public key framework before sending it over the C2 channel. Some variants encrypt the collected data with AES and encode it with base64 before transmitting it to the C2 server.

T1560.002
Archive via Library
MalwareEpic

Epic compresses the collected data with bzip2 before sending it to the C2 server.

T1573.001
Symmetric Cryptography
MalwareEpic

Epic encrypts commands from the C2 server using a hardcoded key.

T1680
Local Storage Discovery
MalwareEpic

Epic collects disk space information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.