ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0148×

38 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareRTM

RTM strings, network data, configuration, and modules are encrypted with a modified RC4 algorithm.

T1027.015
Compression
MalwareRTM

RTM has been delivered to targets as various archive files including ZIP, 7-ZIP, and RAR.

T1033
System Owner/User Discovery
MalwareRTM

RTM can obtain the victim username and permissions.

T1036
Masquerading
MalwareRTM

RTM has been delivered as archived Windows executable files masquerading as PDF documents.

T1036.004
Masquerade Task or Service
MalwareRTM

RTM has named the scheduled task it creates "Windows Update".

T1053.005
Scheduled Task
MalwareRTM

RTM tries to add a scheduled task to establish persistence.

T1056.001
Keylogging
MalwareRTM

RTM can record keystrokes from both the keyboard and virtual keyboard.

T1057
Process Discovery
MalwareRTM

RTM can obtain information about process integrity levels.

T1059.003
Windows Command Shell
MalwareRTM

RTM uses the command line and rundll32.exe to execute.

T1070.004
File Deletion
MalwareRTM

RTM can delete all files created during its execution.

T1070.009
Clear Persistence
MalwareRTM

RTM has the ability to remove Registry entries that it created for persistence.

T1071.001
Web Protocols
MalwareRTM

RTM has initiated connections to external domains using HTTPS.

T1082
System Information Discovery
MalwareRTM

RTM can obtain the computer name, OS version, and default language identifier.

T1083
File and Directory Discovery
MalwareRTM

RTM can check for specific files and directories associated with virtualization and malware analysis.

T1102.001
Dead Drop Resolver
MalwareRTM

RTM has used an RSS feed on Livejournal to update a list of encrypted C2 server names. RTM has also hidden Pony C2 server IP addresses within transactions on the Bitcoin and Namecoin blockchain.

T1105
Ingress Tool Transfer
MalwareRTM

RTM can download additional files.

T1106
Native API
MalwareRTM

RTM can use the FindNextUrlCacheEntryA and FindFirstUrlCacheEntryA functions to search for specific strings within browser history.

T1112
Modify Registry
MalwareRTM

RTM can delete all Registry entries created during its execution.

T1113
Screen Capture
MalwareRTM

RTM can capture screenshots.

T1115
Clipboard Data
MalwareRTM

RTM collects data from the clipboard.

T1119
Automated Collection
MalwareRTM

RTM monitors browsing activity and automatically captures screenshots if a victim browses to a URL matching one of a list of strings.

T1120
Peripheral Device Discovery
MalwareRTM

RTM can obtain a list of smart card readers attached to the victim.

T1124
System Time Discovery
MalwareRTM

RTM can obtain the victim time zone.

T1204.002
Malicious File
MalwareRTM

RTM has relied on users opening malicious email attachments, decompressing the attached archive, and double-clicking the executable within.

T1218.011
Rundll32
MalwareRTM

RTM runs its core DLL file using rundll32.exe.

T1219
Remote Access Tools
MalwareRTM

RTM has the capability to download a VNC module from command and control (C2).

T1497
Virtualization/Sandbox Evasion
MalwareRTM

RTM can detect if it is running within a sandbox or other virtualized analysis environment.

T1518
Software Discovery
MalwareRTM

RTM can scan victim drives to look for specific banking software on the machine to determine next actions.

T1518.001
Security Software Discovery
MalwareRTM

RTM can obtain information about security software on the victim.

T1547.001
Registry Run Keys / Startup Folder
MalwareRTM

RTM tries to add a Registry Run key under the name "Windows Update" to establish persistence.

T1548.002
Bypass User Account Control
MalwareRTM

RTM can attempt to run the program as admin, then show a fake error message and a legitimate UAC bypass prompt to the user in an attempt to socially engineer the user into escalating privileges.

T1553.002
Code Signing
MalwareRTM

RTM samples have been signed with a code-signing certificates.

T1553.004
Install Root Certificate
MalwareRTM

RTM can add a certificate to the Windows store.

T1559.002
Dynamic Data Exchange
MalwareRTM

RTM can search for specific strings within browser tabs using a Dynamic Data Exchange mechanism.

T1566.001
Spearphishing Attachment
MalwareRTM

RTM has been delivered via spearphishing attachments disguised as PDF documents.

T1568
Dynamic Resolution
MalwareRTM

RTM has resolved Pony C2 server IP addresses by either converting Bitcoin blockchain transaction data to specific octets, or accessing IP addresses directly within the Namecoin blockchain.

T1571
Non-Standard Port
MalwareRTM

RTM used Port 44443 for its VNC module.

T1573.001
Symmetric Cryptography
MalwareRTM

RTM encrypts C2 traffic with a custom RC4 variant.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.