ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0126×

22 examples

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareComRAT

ComRAT can check the default browser by querying HKCR\http\shell\open\command.

T1027
Obfuscated Files or Information
MalwareComRAT

ComRAT has encrypted its virtual file system using AES-256 in XTS mode.

T1027.009
Embedded Payloads
MalwareComRAT

ComRAT has embedded a XOR encrypted communications module inside the orchestrator module.

T1027.010
Command Obfuscation
MalwareComRAT

ComRAT has used encryption and base64 to obfuscate its orchestrator code in the Registry. ComRAT has also used encoded PowerShell scripts.

T1027.011
Fileless Storage
MalwareComRAT

ComRAT has stored encrypted orchestrator code and payloads in the Registry.

T1029
Scheduled Transfer
MalwareComRAT

ComRAT has been programmed to sleep outside local business hours (9 to 5, Monday to Friday).

T1036.004
Masquerade Task or Service
MalwareComRAT

ComRAT has used a task name associated with Windows SQM Consolidator.

T1053.005
Scheduled Task
MalwareComRAT

ComRAT has used a scheduled task to launch its PowerShell loader.

T1055.001
Dynamic-link Library Injection
MalwareComRAT

ComRAT has injected its orchestrator DLL into explorer.exe. ComRAT has also injected its communications module into the victim's default browser to make C2 connections appear less suspicious as all network connections will be initiated by the browser process.

T1059.001
PowerShell
MalwareComRAT

ComRAT has used PowerShell to load itself every time a user logs in to the system. ComRAT can execute PowerShell scripts loaded into memory or from the file system.

T1059.003
Windows Command Shell
MalwareComRAT

ComRAT has used cmd.exe to execute commands.

T1071.001
Web Protocols
MalwareComRAT

ComRAT has used HTTP requests for command and control.

T1071.003
Mail Protocols
MalwareComRAT

ComRAT can use email attachments for command and control.

T1102.002
Bidirectional Communication
MalwareComRAT

ComRAT has the ability to use the Gmail web UI to receive commands and exfiltrate information.

T1106
Native API
MalwareComRAT

ComRAT can load a PE file from memory or the file system and execute it with CreateProcessW.

T1112
Modify Registry
MalwareComRAT

ComRAT has modified Registry values to store encrypted orchestrator code and payloads.

T1124
System Time Discovery
MalwareComRAT

ComRAT has checked the victim system's date and time to perform tasks during business hours (9 to 5, Monday to Friday).

T1140
Deobfuscate/Decode Files or Information
MalwareComRAT

ComRAT has used unique per machine passwords to decrypt the orchestrator payload and a hardcoded XOR key to decrypt its communications module. ComRAT has also used a unique password to decrypt the file used for its hidden file system.

T1518
Software Discovery
MalwareComRAT

ComRAT can check the victim's default browser to determine which process to inject its communications module into.

T1546.015
Component Object Model Hijacking
MalwareComRAT

ComRAT samples have been seen which hijack COM objects for persistence by replacing the path to shell32.dll in registry location HKCU\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32.

T1564.005
Hidden File System
MalwareComRAT

ComRAT has used a portable FAT16 partition image placed in %TEMP% as a hidden file system.

T1573.002
Asymmetric Cryptography
MalwareComRAT

ComRAT can use SSL/TLS encryption for its HTTP-based C2 channel. ComRAT has used public key cryptography with RSA and AES encrypted email attachments for its Gmail C2 channel.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.