Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareVolgmer | Volgmer queries the system to identify existing services. |
| T1012 Query Registry |
MalwareVolgmer | Volgmer checks the system for certain Registry keys. |
| T1016 System Network Configuration Discovery |
MalwareVolgmer | Volgmer can gather the IP address from the victim's machine. |
| T1027.011 Fileless Storage |
MalwareVolgmer | Volgmer stores an encoded configuration file in |
| T1027.013 Encrypted/Encoded File |
MalwareVolgmer | A Volgmer variant is encoded using a simple XOR cipher. |
| T1036.004 Masquerade Task or Service |
MalwareVolgmer | Some Volgmer variants add new services with display names generated by a list of hard-coded strings such as Application, Background, Security, and Windows, presumably as a way to masquerade as a legitimate service. |
| T1049 System Network Connections Discovery |
MalwareVolgmer | Volgmer can gather information about TCP connection state. |
| T1057 Process Discovery |
MalwareVolgmer | Volgmer can gather a list of processes. |
| T1059.003 Windows Command Shell |
MalwareVolgmer | Volgmer can execute commands on the victim's machine. |
| T1070.004 File Deletion |
MalwareVolgmer | Volgmer can delete files and itself after infection to avoid analysis. |
| T1082 System Information Discovery |
MalwareVolgmer | Volgmer can gather system information, the computer name, OS version, drive and serial information from the victim's machine. |
| T1083 File and Directory Discovery |
MalwareVolgmer | Volgmer can list directories on a victim. |
| T1105 Ingress Tool Transfer |
MalwareVolgmer | Volgmer can download remote files and additional payloads to the victim's machine. |
| T1106 Native API |
MalwareVolgmer | Volgmer executes payloads using the Windows API call CreateProcessW(). |
| T1112 Modify Registry |
MalwareVolgmer | Volgmer modifies the Registry to store an encoded configuration file in |
| T1140 Deobfuscate/Decode Files or Information |
MalwareVolgmer | Volgmer deobfuscates its strings and APIs once its executed. |
| T1543.003 Windows Service |
MalwareVolgmer | Volgmer installs a copy of itself in a randomly selected service, then overwrites the ServiceDLL entry in the service's Registry entry. Some Volgmer variants also install .dll files as services with names generated by a list of hard-coded strings. |
| T1573.001 Symmetric Cryptography |
MalwareVolgmer | Volgmer uses a simple XOR cipher to encrypt traffic and files. |
| T1573.002 Asymmetric Cryptography |
MalwareVolgmer | Some Volgmer variants use SSL to encrypt C2 communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.