ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0093×

16 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects information about the Internet adapter configuration.

T1018
Remote System Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea can enumerate and map ICS-specific systems in victim environments.

T1033
System Owner/User Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects the current username from the victim.

T1046
Network Service Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea can use a network scanning module to identify ICS-related ports.

T1055
Process Injection
MalwareBackdoor.Oldrea

Backdoor.Oldrea injects itself into explorer.exe.

T1057
Process Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects information about running processes.

T1070.004
File Deletion
MalwareBackdoor.Oldrea

Backdoor.Oldrea contains a cleanup module that removes traces of itself from the victim.

T1082
System Information Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects information about the OS and computer name.

T1083
File and Directory Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects information about available drives, default browser, desktop file list, My Documents, Internet history, program files, and root of available drives. It also searches for ICS-related software files.

T1087.003
Email Account
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects address book information from Outlook.

T1105
Ingress Tool Transfer
MalwareBackdoor.Oldrea

Backdoor.Oldrea can download additional modules from C2.

T1132.001
Standard Encoding
MalwareBackdoor.Oldrea

Some Backdoor.Oldrea samples use standard Base64 + bzip2, and some use standard Base64 + reverse XOR + RSA-2048 to decrypt data received from C2 servers.

T1218.011
Rundll32
MalwareBackdoor.Oldrea

Backdoor.Oldrea can use rundll32 for execution on compromised hosts.

T1547.001
Registry Run Keys / Startup Folder
MalwareBackdoor.Oldrea

Backdoor.Oldrea adds Registry Run keys to achieve persistence.

T1555.003
Credentials from Web Browsers
MalwareBackdoor.Oldrea

Some Backdoor.Oldrea samples contain a publicly available Web browser password recovery tool.

T1560
Archive Collected Data
MalwareBackdoor.Oldrea

Backdoor.Oldrea writes collected data to a temporary file in an encrypted form before exfiltration to a C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.