ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0170×

21 examples

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareHelminth

The Helminth config file is encrypted with RC4.

T1030
Data Transfer Size Limits
MalwareHelminth

Helminth splits data into chunks up to 23 bytes and sends the data in DNS queries to its C2 server.

T1053.005
Scheduled Task
MalwareHelminth

Helminth has used a scheduled task for persistence.

T1056.001
Keylogging
MalwareHelminth

The executable version of Helminth has a module to log keystrokes.

T1057
Process Discovery
MalwareHelminth

Helminth has used Tasklist to get information on processes.

T1059.001
PowerShell
MalwareHelminth

One version of Helminth uses a PowerShell script.

T1059.003
Windows Command Shell
MalwareHelminth

Helminth can provide a remote shell. One version of Helminth uses batch scripting.

T1059.005
Visual Basic
MalwareHelminth

One version of Helminth consists of VBScript scripts.

T1069.001
Local Groups
MalwareHelminth

Helminth has checked the local administrators group.

T1069.002
Domain Groups
MalwareHelminth

Helminth has checked for the domain admin group and Exchange Trusted Subsystem groups using the commands net group Exchange Trusted Subsystem /domain and net group domain admins /domain.

T1071.001
Web Protocols
MalwareHelminth

Helminth can use HTTP for C2.

T1071.004
DNS
MalwareHelminth

Helminth can use DNS for C2.

T1074.001
Local Data Staging
MalwareHelminth

Helminth creates folders to store output from batch scripts prior to sending the information to its C2 server.

T1105
Ingress Tool Transfer
MalwareHelminth

Helminth can download additional files.

T1115
Clipboard Data
MalwareHelminth

The executable version of Helminth has a module to log clipboard contents.

T1119
Automated Collection
MalwareHelminth

A Helminth VBScript receives a batch script to execute a set of commands in a command prompt.

T1132.001
Standard Encoding
MalwareHelminth

For C2 over HTTP, Helminth encodes data with base64 and sends it via the "Cookie" field of HTTP requests. For C2 over DNS, Helminth converts ASCII characters into their hexadecimal values and sends the data in cleartext.

T1547.001
Registry Run Keys / Startup Folder
MalwareHelminth

Helminth establishes persistence by creating a shortcut in the Start Menu folder.

T1547.009
Shortcut Modification
MalwareHelminth

Helminth establishes persistence by creating a shortcut.

T1553.002
Code Signing
MalwareHelminth

Helminth samples have been signed with legitimate, compromised code signing certificates owned by software company AI Squared.

T1573.001
Symmetric Cryptography
MalwareHelminth

Helminth encrypts data sent to its C2 server over HTTP with RC4.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.