ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0140×

24 examples

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareShamoon

Shamoon queries several Registry keys to identify hard disk partitions to overwrite.

T1016
System Network Configuration Discovery
MalwareShamoon

Shamoon obtains the target's IP address and local network segment.

T1018
Remote System Discovery
MalwareShamoon

Shamoon scans the C-class subnet of the IPs on the victim's interfaces.

T1021.002
SMB/Windows Admin Shares
MalwareShamoon

Shamoon accesses network share(s), enables share access to the target device, copies an executable payload to the target system, and uses a Scheduled Task/Job to execute the malware.

T1027
Obfuscated Files or Information
MalwareShamoon

Shamoon contains base64-encoded strings.

T1036.004
Masquerade Task or Service
MalwareShamoon

Shamoon creates a new service named “ntssrv” that attempts to appear legitimate; the service's display name is “Microsoft Network Realtime Inspection Service” and its description is “Helps guard against time change attempts targeting known and newly discovered vulnerabilities in network time protocols.” Newer versions create the "MaintenaceSrv" service, which misspells the word "maintenance."

T1053.005
Scheduled Task
MalwareShamoon

Shamoon copies an executable payload to the target system by using SMB/Windows Admin Shares and then scheduling an unnamed task to execute the malware.

T1070.006
Timestomp
MalwareShamoon

Shamoon can change the modified time for files to evade forensic detection.

T1071.001
Web Protocols
MalwareShamoon

Shamoon has used HTTP for C2.

T1078.002
Domain Accounts
MalwareShamoon

If Shamoon cannot access shares using current privileges, it attempts access using hard coded, domain-specific credentials gathered earlier in the intrusion.

T1082
System Information Discovery
MalwareShamoon

Shamoon obtains the victim's operating system version and keyboard layout and sends the information to the C2 server.

T1105
Ingress Tool Transfer
MalwareShamoon

Shamoon can download an executable to run on the victim.

T1112
Modify Registry
MalwareShamoon

Once Shamoon has access to a network share, it enables the RemoteRegistry service on the target system. It will then connect to the system with RegConnectRegistryW and modify the Registry to disable UAC remote restrictions by setting SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy to 1.

T1124
System Time Discovery
MalwareShamoon

Shamoon obtains the system time and will only activate if it is greater than a preset date.

T1134.001
Token Impersonation/Theft
MalwareShamoon

Shamoon can impersonate tokens using LogonUser, ImpersonateLoggedOnUser, and ImpersonateNamedPipeClient.

T1140
Deobfuscate/Decode Files or Information
MalwareShamoon

Shamoon decrypts ciphertext using an XOR cipher and a base64-encoded string.

T1485
Data Destruction
MalwareShamoon

Shamoon attempts to overwrite operating system files and disk structures with image files. In a later variant, randomly generated data was used for data overwrites.

T1486
Data Encrypted for Impact
MalwareShamoon

Shamoon has an operational mode for encrypting data instead of overwriting it.

T1529
System Shutdown/Reboot
MalwareShamoon

Shamoon will reboot the infected system once the wiping functionality has been completed.

T1543.003
Windows Service
MalwareShamoon

Shamoon creates a new service named “ntssrv” to execute the payload. Newer versions create the "MaintenaceSrv" and "hdv_725x" services.

T1548.002
Bypass User Account Control
MalwareShamoon

Shamoon attempts to disable UAC remote restrictions by modifying the Registry.

T1561.002
Disk Structure Wipe
MalwareShamoon

Shamoon has been seen overwriting features of disk structure such as the MBR.

T1569.002
Service Execution
MalwareShamoon

Shamoon creates a new service named “ntssrv” to execute the payload. Shamoon can also spread via PsExec.

T1570
Lateral Tool Transfer
MalwareShamoon

Shamoon attempts to copy itself to remote machines on the network.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.