Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.007 Dynamic API Resolution |
MalwarePteranodon | Pteranodon can use a dynamic Windows hashing algorithm to map API components. |
| T1041 Exfiltration Over C2 Channel |
MalwarePteranodon | Pteranodon exfiltrates screenshot files to its C2 server. |
| T1053.005 Scheduled Task |
MalwarePteranodon | Pteranodon schedules tasks to invoke its components in order to establish persistence. |
| T1059.003 Windows Command Shell |
MalwarePteranodon | Pteranodon can use `cmd.exe` for execution on victim systems. |
| T1059.005 Visual Basic |
MalwarePteranodon | Pteranodon can use a malicious VBS file for execution. |
| T1070.004 File Deletion |
MalwarePteranodon | Pteranodon can delete files that may interfere with it executing. It also can delete temporary files and itself after the initial script executes. |
| T1071.001 Web Protocols |
MalwarePteranodon | Pteranodon can use HTTP for C2. |
| T1074.001 Local Data Staging |
MalwarePteranodon | Pteranodon creates various subdirectories under |
| T1083 File and Directory Discovery |
MalwarePteranodon | Pteranodon identifies files matching certain file extension and copies them to subdirectories it created. |
| T1105 Ingress Tool Transfer |
MalwarePteranodon | Pteranodon can download and execute additional files. |
| T1106 Native API |
MalwarePteranodon | Pteranodon has used various API calls. |
| T1113 Screen Capture |
MalwarePteranodon | Pteranodon can capture screenshots at a configurable interval. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePteranodon | Pteranodon can decrypt encrypted data strings prior to using them. |
| T1218.005 Mshta |
MalwarePteranodon | Pteranodon can use mshta.exe to execute an HTA file hosted on a remote server. |
| T1218.011 Rundll32 |
MalwarePteranodon | Pteranodon executes functions using rundll32.exe. |
| T1497 Virtualization/Sandbox Evasion |
MalwarePteranodon | Pteranodon has the ability to use anti-detection functions to identify sandbox environments. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePteranodon | Pteranodon copies itself to the Startup folder to establish persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.