ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0113×

20 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwarePrikormka

A module in Prikormka collects information from the victim about its IP addresses and MAC addresses.

T1025
Data from Removable Media
MalwarePrikormka

Prikormka contains a module that collects documents with certain extensions from removable media or fixed drives connected via USB.

T1027.013
Encrypted/Encoded File
MalwarePrikormka

Some resources in Prikormka are encrypted with a simple XOR operation or encoded with Base64.

T1033
System Owner/User Discovery
MalwarePrikormka

A module in Prikormka collects information from the victim about the current user name.

T1056.001
Keylogging
MalwarePrikormka

Prikormka contains a keylogger module that collects keystrokes and the titles of foreground windows.

T1070.004
File Deletion
MalwarePrikormka

After encrypting its own log files, the log encryption module in Prikormka deletes the original, unencrypted files from the host.

T1074.001
Local Data Staging
MalwarePrikormka

Prikormka creates a directory, %USERPROFILE%\AppData\Local\SKC\, which is used to store collected log files.

T1082
System Information Discovery
MalwarePrikormka

A module in Prikormka collects information from the victim about Windows OS version, computer name, battery info, and physical memory.

T1083
File and Directory Discovery
MalwarePrikormka

A module in Prikormka collects information about the paths, size, and creation time of files with specific file extensions, but not the actual content of the file.

T1113
Screen Capture
MalwarePrikormka

Prikormka contains a module that captures screenshots of the victim's desktop.

T1120
Peripheral Device Discovery
MalwarePrikormka

A module in Prikormka collects information on available printers and disk drives.

T1132.001
Standard Encoding
MalwarePrikormka

Prikormka encodes C2 traffic with Base64.

T1218.011
Rundll32
MalwarePrikormka

Prikormka uses rundll32.exe to load its DLL.

T1518.001
Security Software Discovery
MalwarePrikormka

A module in Prikormka collects information from the victim about installed anti-virus software.

T1547.001
Registry Run Keys / Startup Folder
MalwarePrikormka

Prikormka adds itself to a Registry Run key with the name guidVGA or guidVSA.

T1555
Credentials from Password Stores
MalwarePrikormka

A module in Prikormka collects passwords stored in applications installed on the victim.

T1555.003
Credentials from Web Browsers
MalwarePrikormka

A module in Prikormka gathers logins and passwords stored in applications on the victims, including Google Chrome, Mozilla Firefox, and several other browsers.

T1560
Archive Collected Data
MalwarePrikormka

After collecting documents from removable media, Prikormka compresses the collected files, and encrypts it with Blowfish.

T1573.001
Symmetric Cryptography
MalwarePrikormka

Prikormka encrypts some C2 traffic with the Blowfish cipher.

T1574.001
DLL
MalwarePrikormka

Prikormka uses DLL search order hijacking for persistence by saving itself as ntshrui.dll to the Windows directory so it will load before the legitimate ntshrui.dll saved in the System32 subdirectory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.