ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0196×

17 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwarePUNCHBUGGY

PUNCHBUGGY has hashed most its code's functions and encrypted payloads with base64 and XOR.

T1036.005
Match Legitimate Resource Name or Location
MalwarePUNCHBUGGY

PUNCHBUGGY mimics filenames from %SYSTEM%\System32 to hide DLLs in %WINDIR% and/or %TEMP%.

T1059.001
PowerShell
MalwarePUNCHBUGGY

PUNCHBUGGY has used PowerShell scripts.

T1059.006
Python
MalwarePUNCHBUGGY

PUNCHBUGGY has used python scripts.

T1070.004
File Deletion
MalwarePUNCHBUGGY

PUNCHBUGGY can delete files written to disk.

T1071.001
Web Protocols
MalwarePUNCHBUGGY

PUNCHBUGGY enables remote interaction and can obtain additional code over HTTPS GET and POST requests.

T1074.001
Local Data Staging
MalwarePUNCHBUGGY

PUNCHBUGGY has saved information to a random temp file before exfil.

T1082
System Information Discovery
MalwarePUNCHBUGGY

PUNCHBUGGY can gather system information such as computer names.

T1087.001
Local Account
MalwarePUNCHBUGGY

PUNCHBUGGY can gather user names.

T1105
Ingress Tool Transfer
MalwarePUNCHBUGGY

PUNCHBUGGY can download additional files and payloads to compromised hosts.

T1129
Shared Modules
MalwarePUNCHBUGGY

PUNCHBUGGY can load a DLL using the LoadLibrary API.

T1140
Deobfuscate/Decode Files or Information
MalwarePUNCHBUGGY

PUNCHBUGGY has used PowerShell to decode base64-encoded assembly.

T1218.011
Rundll32
MalwarePUNCHBUGGY

PUNCHBUGGY can load a DLL using Rundll32.

T1518.001
Security Software Discovery
MalwarePUNCHBUGGY

PUNCHBUGGY can gather AVs registered in the system.

T1546.009
AppCert DLLs
MalwarePUNCHBUGGY

PUNCHBUGGY can establish using a AppCertDLLs Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwarePUNCHBUGGY

PUNCHBUGGY has been observed using a Registry Run key.

T1560.001
Archive via Utility
MalwarePUNCHBUGGY

PUNCHBUGGY has Gzipped information and saved it to a random temp file before exfil.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.