Real-world descriptions of how a group, tool or campaign used a technique.
30 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
MalwareRemsec | Remsec can dump the SAM database. |
| T1016 System Network Configuration Discovery |
MalwareRemsec | Remsec can obtain information about network configuration, including the routing table, ARP cache, and DNS cache. |
| T1018 Remote System Discovery |
MalwareRemsec | Remsec can ping or traceroute a remote host. |
| T1025 Data from Removable Media |
MalwareRemsec | Remsec has a package that collects documents from any inserted USB sticks. |
| T1027.013 Encrypted/Encoded File |
MalwareRemsec | Some data in Remsec is encrypted using RC5 in CBC mode, AES-CBC with a hardcoded key, RC4, or Salsa20. Some data is also base64-encoded. |
| T1033 System Owner/User Discovery |
MalwareRemsec | Remsec can obtain information about the current user. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRemsec | The Remsec loader implements itself with the name Security Support Provider, a legitimate Windows function. Various Remsec .exe files mimic legitimate file names used by Microsoft, Symantec, Kaspersky, Hewlett-Packard, and VMWare. Remsec also disguised malicious modules using similar filenames as custom network encryption software on victims. |
| T1046 Network Service Discovery |
MalwareRemsec | Remsec has a plugin that can perform ARP scanning as well as port scanning. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareRemsec | Remsec can exfiltrate data via a DNS tunnel or email, separately from its C2 channel. |
| T1049 System Network Connections Discovery |
MalwareRemsec | Remsec can obtain a list of active connections and open ports. |
| T1052.001 Exfiltration over USB |
MalwareRemsec | Remsec contains a module to move data from airgapped networks to Internet-connected systems by using a removable USB device. |
| T1053.005 Scheduled Task |
MalwareRemsec | Remsec schedules the execution one of its modules by creating a new scheduler task. |
| T1055.001 Dynamic-link Library Injection |
MalwareRemsec | Remsec can perform DLL injection. |
| T1056.001 Keylogging |
MalwareRemsec | Remsec contains a keylogger component. |
| T1057 Process Discovery |
MalwareRemsec | Remsec can obtain a process list from the victim. |
| T1059.011 Lua |
MalwareRemsec | Remsec can use modules written in Lua for execution. |
| T1068 Exploitation for Privilege Escalation |
MalwareRemsec | Remsec has a plugin to drop and execute vulnerable Outpost Sandbox or avast! Virtualization drivers in order to gain kernel mode privileges. |
| T1070.004 File Deletion |
MalwareRemsec | Remsec is capable of deleting files on the victim. It also securely removes itself after collecting and exfiltrating data. |
| T1071.001 Web Protocols |
MalwareRemsec | Remsec is capable of using HTTP and HTTPS for C2. |
| T1071.003 Mail Protocols |
MalwareRemsec | Remsec is capable of using SMTP for C2. |
| T1071.004 DNS |
MalwareRemsec | Remsec is capable of using DNS for C2. |
| T1082 System Information Discovery |
MalwareRemsec | Remsec can obtain the OS version information, computer name, processor architecture, machine role, and OS edition. |
| T1083 File and Directory Discovery |
MalwareRemsec | Remsec is capable of listing contents of folders on the victim. Remsec also searches for custom network encryption software on victims. |
| T1087.001 Local Account |
MalwareRemsec | Remsec can obtain a list of users. |
| T1095 Non-Application Layer Protocol |
MalwareRemsec | Remsec is capable of using ICMP, TCP, and UDP for C2. |
| T1105 Ingress Tool Transfer |
MalwareRemsec | Remsec contains a network loader to receive executable modules from remote attackers and run them on the local victim. It can also upload and download files over HTTP and HTTPS. |
| T1518.001 Security Software Discovery |
MalwareRemsec | Remsec has a plugin detect security products via active drivers. |
| T1556.002 Password Filter DLL |
MalwareRemsec | Remsec harvests plain-text credentials as a password filter registered on domain controllers. |
| T1652 Device Driver Discovery |
MalwareRemsec | Remsec has a plugin to detect active drivers of some security products. |
| T1686.003 Windows Host Firewall |
MalwareRemsec | Remsec can add or remove applications or ports on the Windows firewall or disable it entirely. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.