ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0187×

16 examples

TechniqueUsed byProcedure example
T1001.002
Steganography
MalwareDaserf

Daserf can use steganography to hide malicious code downloaded to the victim.

T1003.001
LSASS Memory
MalwareDaserf

Daserf leverages Mimikatz and Windows Credential Editor to steal credentials.

T1027
Obfuscated Files or Information
MalwareDaserf

Daserf uses encrypted Windows APIs and also encrypts data using the alternative base64+RC4 or the Caesar cipher.

T1027.002
Software Packing
MalwareDaserf

A version of Daserf uses the MPRESS packer.

T1027.005
Indicator Removal from Tools
MalwareDaserf

Analysis of Daserf has shown that it regularly undergoes technical improvements to evade anti-virus detection.

T1036.005
Match Legitimate Resource Name or Location
MalwareDaserf

Daserf uses file and folder names related to legitimate programs in order to blend in, such as HP, Intel, Adobe, and perflogs.

T1056.001
Keylogging
MalwareDaserf

Daserf can log keystrokes.

T1059.003
Windows Command Shell
MalwareDaserf

Daserf can execute shell commands.

T1071.001
Web Protocols
MalwareDaserf

Daserf uses HTTP for C2.

T1105
Ingress Tool Transfer
MalwareDaserf

Daserf can download remote files.

T1113
Screen Capture
MalwareDaserf

Daserf can take screenshots.

T1132.001
Standard Encoding
MalwareDaserf

Daserf uses custom base64 encoding to obfuscate HTTP traffic.

T1553.002
Code Signing
MalwareDaserf

Some Daserf samples were signed with a stolen digital certificate.

T1560
Archive Collected Data
MalwareDaserf

Daserf hides collected data in password-protected .rar archives.

T1560.001
Archive via Utility
MalwareDaserf

Daserf hides collected data in password-protected .rar archives.

T1573.001
Symmetric Cryptography
MalwareDaserf

Daserf uses RC4 encryption to obfuscate HTTP traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.