ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0180×

19 examples

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareVolgmer

Volgmer queries the system to identify existing services.

T1012
Query Registry
MalwareVolgmer

Volgmer checks the system for certain Registry keys.

T1016
System Network Configuration Discovery
MalwareVolgmer

Volgmer can gather the IP address from the victim's machine.

T1027.011
Fileless Storage
MalwareVolgmer

Volgmer stores an encoded configuration file in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security.

T1027.013
Encrypted/Encoded File
MalwareVolgmer

A Volgmer variant is encoded using a simple XOR cipher.

T1036.004
Masquerade Task or Service
MalwareVolgmer

Some Volgmer variants add new services with display names generated by a list of hard-coded strings such as Application, Background, Security, and Windows, presumably as a way to masquerade as a legitimate service.

T1049
System Network Connections Discovery
MalwareVolgmer

Volgmer can gather information about TCP connection state.

T1057
Process Discovery
MalwareVolgmer

Volgmer can gather a list of processes.

T1059.003
Windows Command Shell
MalwareVolgmer

Volgmer can execute commands on the victim's machine.

T1070.004
File Deletion
MalwareVolgmer

Volgmer can delete files and itself after infection to avoid analysis.

T1082
System Information Discovery
MalwareVolgmer

Volgmer can gather system information, the computer name, OS version, drive and serial information from the victim's machine.

T1083
File and Directory Discovery
MalwareVolgmer

Volgmer can list directories on a victim.

T1105
Ingress Tool Transfer
MalwareVolgmer

Volgmer can download remote files and additional payloads to the victim's machine.

T1106
Native API
MalwareVolgmer

Volgmer executes payloads using the Windows API call CreateProcessW().

T1112
Modify Registry
MalwareVolgmer

Volgmer modifies the Registry to store an encoded configuration file in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security.

T1140
Deobfuscate/Decode Files or Information
MalwareVolgmer

Volgmer deobfuscates its strings and APIs once its executed.

T1543.003
Windows Service
MalwareVolgmer

Volgmer installs a copy of itself in a randomly selected service, then overwrites the ServiceDLL entry in the service's Registry entry. Some Volgmer variants also install .dll files as services with names generated by a list of hard-coded strings.

T1573.001
Symmetric Cryptography
MalwareVolgmer

Volgmer uses a simple XOR cipher to encrypt traffic and files.

T1573.002
Asymmetric Cryptography
MalwareVolgmer

Some Volgmer variants use SSL to encrypt C2 communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.