ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0153×

17 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareRedLeaves

RedLeaves can obtain information about network parameters.

T1027.013
Encrypted/Encoded File
MalwareRedLeaves

A RedLeaves configuration file is encrypted with a simple XOR key, 0x53.

T1033
System Owner/User Discovery
MalwareRedLeaves

RedLeaves can obtain information about the logged on user both locally and for Remote Desktop sessions.

T1049
System Network Connections Discovery
MalwareRedLeaves

RedLeaves can enumerate drives and Remote Desktop sessions.

T1059.003
Windows Command Shell
MalwareRedLeaves

RedLeaves can receive and execute commands with cmd.exe. It can also provide a reverse shell.

T1070.004
File Deletion
MalwareRedLeaves

RedLeaves can delete specified files.

T1071.001
Web Protocols
MalwareRedLeaves

RedLeaves can communicate to its C2 over HTTP and HTTPS if directed.

T1082
System Information Discovery
MalwareRedLeaves

RedLeaves can gather extended system information including the hostname, OS version number, platform, memory information, time elapsed since system startup, and CPU information.

T1083
File and Directory Discovery
MalwareRedLeaves

RedLeaves can enumerate and search for files and directories.

T1105
Ingress Tool Transfer
MalwareRedLeaves

RedLeaves is capable of downloading a file from a specified URL.

T1113
Screen Capture
MalwareRedLeaves

RedLeaves can capture screenshots.

T1547.001
Registry Run Keys / Startup Folder
MalwareRedLeaves

RedLeaves attempts to add a shortcut file in the Startup folder to achieve persistence. If this fails, it attempts to add Registry Run keys.

T1547.009
Shortcut Modification
MalwareRedLeaves

RedLeaves attempts to add a shortcut file in the Startup folder to achieve persistence.

T1555.003
Credentials from Web Browsers
MalwareRedLeaves

RedLeaves can gather browser usernames and passwords.

T1571
Non-Standard Port
MalwareRedLeaves

RedLeaves can use HTTP over non-standard ports, such as 995, for C2.

T1573.001
Symmetric Cryptography
MalwareRedLeaves

RedLeaves has encrypted C2 traffic with RC4, previously using keys of 88888888 and babybear.

T1574.001
DLL
MalwareRedLeaves

RedLeaves is launched through use of DLL search order hijacking to load a malicious dll.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.