Real-world descriptions of how a group, tool or campaign used a technique.
16 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects information about the Internet adapter configuration. |
| T1018 Remote System Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea can enumerate and map ICS-specific systems in victim environments. |
| T1033 System Owner/User Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects the current username from the victim. |
| T1046 Network Service Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea can use a network scanning module to identify ICS-related ports. |
| T1055 Process Injection |
MalwareBackdoor.Oldrea | Backdoor.Oldrea injects itself into explorer.exe. |
| T1057 Process Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects information about running processes. |
| T1070.004 File Deletion |
MalwareBackdoor.Oldrea | Backdoor.Oldrea contains a cleanup module that removes traces of itself from the victim. |
| T1082 System Information Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects information about the OS and computer name. |
| T1083 File and Directory Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects information about available drives, default browser, desktop file list, My Documents, Internet history, program files, and root of available drives. It also searches for ICS-related software files. |
| T1087.003 Email Account |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects address book information from Outlook. |
| T1105 Ingress Tool Transfer |
MalwareBackdoor.Oldrea | Backdoor.Oldrea can download additional modules from C2. |
| T1132.001 Standard Encoding |
MalwareBackdoor.Oldrea | Some Backdoor.Oldrea samples use standard Base64 + bzip2, and some use standard Base64 + reverse XOR + RSA-2048 to decrypt data received from C2 servers. |
| T1218.011 Rundll32 |
MalwareBackdoor.Oldrea | Backdoor.Oldrea can use rundll32 for execution on compromised hosts. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBackdoor.Oldrea | Backdoor.Oldrea adds Registry Run keys to achieve persistence. |
| T1555.003 Credentials from Web Browsers |
MalwareBackdoor.Oldrea | Some Backdoor.Oldrea samples contain a publicly available Web browser password recovery tool. |
| T1560 Archive Collected Data |
MalwareBackdoor.Oldrea | Backdoor.Oldrea writes collected data to a temporary file in an encrypted form before exfiltration to a C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.