ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0125×

30 examples

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
MalwareRemsec

Remsec can dump the SAM database.

T1016
System Network Configuration Discovery
MalwareRemsec

Remsec can obtain information about network configuration, including the routing table, ARP cache, and DNS cache.

T1018
Remote System Discovery
MalwareRemsec

Remsec can ping or traceroute a remote host.

T1025
Data from Removable Media
MalwareRemsec

Remsec has a package that collects documents from any inserted USB sticks.

T1027.013
Encrypted/Encoded File
MalwareRemsec

Some data in Remsec is encrypted using RC5 in CBC mode, AES-CBC with a hardcoded key, RC4, or Salsa20. Some data is also base64-encoded.

T1033
System Owner/User Discovery
MalwareRemsec

Remsec can obtain information about the current user.

T1036.005
Match Legitimate Resource Name or Location
MalwareRemsec

The Remsec loader implements itself with the name Security Support Provider, a legitimate Windows function. Various Remsec .exe files mimic legitimate file names used by Microsoft, Symantec, Kaspersky, Hewlett-Packard, and VMWare. Remsec also disguised malicious modules using similar filenames as custom network encryption software on victims.

T1046
Network Service Discovery
MalwareRemsec

Remsec has a plugin that can perform ARP scanning as well as port scanning.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareRemsec

Remsec can exfiltrate data via a DNS tunnel or email, separately from its C2 channel.

T1049
System Network Connections Discovery
MalwareRemsec

Remsec can obtain a list of active connections and open ports.

T1052.001
Exfiltration over USB
MalwareRemsec

Remsec contains a module to move data from airgapped networks to Internet-connected systems by using a removable USB device.

T1053.005
Scheduled Task
MalwareRemsec

Remsec schedules the execution one of its modules by creating a new scheduler task.

T1055.001
Dynamic-link Library Injection
MalwareRemsec

Remsec can perform DLL injection.

T1056.001
Keylogging
MalwareRemsec

Remsec contains a keylogger component.

T1057
Process Discovery
MalwareRemsec

Remsec can obtain a process list from the victim.

T1059.011
Lua
MalwareRemsec

Remsec can use modules written in Lua for execution.

T1068
Exploitation for Privilege Escalation
MalwareRemsec

Remsec has a plugin to drop and execute vulnerable Outpost Sandbox or avast! Virtualization drivers in order to gain kernel mode privileges.

T1070.004
File Deletion
MalwareRemsec

Remsec is capable of deleting files on the victim. It also securely removes itself after collecting and exfiltrating data.

T1071.001
Web Protocols
MalwareRemsec

Remsec is capable of using HTTP and HTTPS for C2.

T1071.003
Mail Protocols
MalwareRemsec

Remsec is capable of using SMTP for C2.

T1071.004
DNS
MalwareRemsec

Remsec is capable of using DNS for C2.

T1082
System Information Discovery
MalwareRemsec

Remsec can obtain the OS version information, computer name, processor architecture, machine role, and OS edition.

T1083
File and Directory Discovery
MalwareRemsec

Remsec is capable of listing contents of folders on the victim. Remsec also searches for custom network encryption software on victims.

T1087.001
Local Account
MalwareRemsec

Remsec can obtain a list of users.

T1095
Non-Application Layer Protocol
MalwareRemsec

Remsec is capable of using ICMP, TCP, and UDP for C2.

T1105
Ingress Tool Transfer
MalwareRemsec

Remsec contains a network loader to receive executable modules from remote attackers and run them on the local victim. It can also upload and download files over HTTP and HTTPS.

T1518.001
Security Software Discovery
MalwareRemsec

Remsec has a plugin detect security products via active drivers.

T1556.002
Password Filter DLL
MalwareRemsec

Remsec harvests plain-text credentials as a password filter registered on domain controllers.

T1652
Device Driver Discovery
MalwareRemsec

Remsec has a plugin to detect active drivers of some security products.

T1686.003
Windows Host Firewall
MalwareRemsec

Remsec can add or remove applications or ports on the Windows firewall or disable it entirely.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.