Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwarePUNCHBUGGY | PUNCHBUGGY has hashed most its code's functions and encrypted payloads with base64 and XOR. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePUNCHBUGGY | PUNCHBUGGY mimics filenames from %SYSTEM%\System32 to hide DLLs in %WINDIR% and/or %TEMP%. |
| T1059.001 PowerShell |
MalwarePUNCHBUGGY | PUNCHBUGGY has used PowerShell scripts. |
| T1059.006 Python |
MalwarePUNCHBUGGY | PUNCHBUGGY has used python scripts. |
| T1070.004 File Deletion |
MalwarePUNCHBUGGY | PUNCHBUGGY can delete files written to disk. |
| T1071.001 Web Protocols |
MalwarePUNCHBUGGY | PUNCHBUGGY enables remote interaction and can obtain additional code over HTTPS GET and POST requests. |
| T1074.001 Local Data Staging |
MalwarePUNCHBUGGY | PUNCHBUGGY has saved information to a random temp file before exfil. |
| T1082 System Information Discovery |
MalwarePUNCHBUGGY | PUNCHBUGGY can gather system information such as computer names. |
| T1087.001 Local Account |
MalwarePUNCHBUGGY | PUNCHBUGGY can gather user names. |
| T1105 Ingress Tool Transfer |
MalwarePUNCHBUGGY | PUNCHBUGGY can download additional files and payloads to compromised hosts. |
| T1129 Shared Modules |
MalwarePUNCHBUGGY | PUNCHBUGGY can load a DLL using the LoadLibrary API. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePUNCHBUGGY | PUNCHBUGGY has used PowerShell to decode base64-encoded assembly. |
| T1218.011 Rundll32 |
MalwarePUNCHBUGGY | PUNCHBUGGY can load a DLL using Rundll32. |
| T1518.001 Security Software Discovery |
MalwarePUNCHBUGGY | PUNCHBUGGY can gather AVs registered in the system. |
| T1546.009 AppCert DLLs |
MalwarePUNCHBUGGY | PUNCHBUGGY can establish using a AppCertDLLs Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePUNCHBUGGY | PUNCHBUGGY has been observed using a Registry Run key. |
| T1560.001 Archive via Utility |
MalwarePUNCHBUGGY | PUNCHBUGGY has Gzipped information and saved it to a random temp file before exfil. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.