ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0147×

17 examples

TechniqueUsed byProcedure example
T1027.007
Dynamic API Resolution
MalwarePteranodon

Pteranodon can use a dynamic Windows hashing algorithm to map API components.

T1041
Exfiltration Over C2 Channel
MalwarePteranodon

Pteranodon exfiltrates screenshot files to its C2 server.

T1053.005
Scheduled Task
MalwarePteranodon

Pteranodon schedules tasks to invoke its components in order to establish persistence.

T1059.003
Windows Command Shell
MalwarePteranodon

Pteranodon can use `cmd.exe` for execution on victim systems.

T1059.005
Visual Basic
MalwarePteranodon

Pteranodon can use a malicious VBS file for execution.

T1070.004
File Deletion
MalwarePteranodon

Pteranodon can delete files that may interfere with it executing. It also can delete temporary files and itself after the initial script executes.

T1071.001
Web Protocols
MalwarePteranodon

Pteranodon can use HTTP for C2.

T1074.001
Local Data Staging
MalwarePteranodon

Pteranodon creates various subdirectories under %Temp%\reports\% and copies files to those subdirectories. It also creates a folder at C:\Users\<Username>\AppData\Roaming\Microsoft\store to store screenshot JPEG files.

T1083
File and Directory Discovery
MalwarePteranodon

Pteranodon identifies files matching certain file extension and copies them to subdirectories it created.

T1105
Ingress Tool Transfer
MalwarePteranodon

Pteranodon can download and execute additional files.

T1106
Native API
MalwarePteranodon

Pteranodon has used various API calls.

T1113
Screen Capture
MalwarePteranodon

Pteranodon can capture screenshots at a configurable interval.

T1140
Deobfuscate/Decode Files or Information
MalwarePteranodon

Pteranodon can decrypt encrypted data strings prior to using them.

T1218.005
Mshta
MalwarePteranodon

Pteranodon can use mshta.exe to execute an HTA file hosted on a remote server.

T1218.011
Rundll32
MalwarePteranodon

Pteranodon executes functions using rundll32.exe.

T1497
Virtualization/Sandbox Evasion
MalwarePteranodon

Pteranodon has the ability to use anti-detection functions to identify sandbox environments.

T1547.001
Registry Run Keys / Startup Folder
MalwarePteranodon

Pteranodon copies itself to the Startup folder to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.