ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0198×

45 examples

TechniqueUsed byProcedure example
T1010
Application Window Discovery
MalwareNETWIRE

NETWIRE can discover and close windows on controlled systems.

T1016
System Network Configuration Discovery
MalwareNETWIRE

NETWIRE can collect the IP address of a compromised host.

T1027
Obfuscated Files or Information
MalwareNETWIRE

NETWIRE has used a custom obfuscation algorithm to hide strings including Registry keys, APIs, and DLL names.

T1027.002
Software Packing
MalwareNETWIRE

NETWIRE has used .NET packer tools to evade detection.

T1027.011
Fileless Storage
MalwareNETWIRE

NETWIRE can store its configuration information in the Registry under `HKCU:\Software\Netwire`.

T1036.001
Invalid Code Signature
MalwareNETWIRE

The NETWIRE client has been signed by fake and invalid digital certificates.

T1036.005
Match Legitimate Resource Name or Location
MalwareNETWIRE

NETWIRE has masqueraded as legitimate software including TeamViewer and macOS Finder.

T1049
System Network Connections Discovery
MalwareNETWIRE

NETWIRE can capture session logon details from a compromised host.

T1053.003
Cron
MalwareNETWIRE

NETWIRE can use crontabs to establish persistence.

T1053.005
Scheduled Task
MalwareNETWIRE

NETWIRE can create a scheduled task to establish persistence.

T1055
Process Injection
MalwareNETWIRE

NETWIRE can inject code into system processes including notepad.exe, svchost.exe, and vbc.exe.

T1055.012
Process Hollowing
MalwareNETWIRE

The NETWIRE payload has been injected into benign Microsoft executables via process hollowing.

T1056.001
Keylogging
MalwareNETWIRE

NETWIRE can perform keylogging.

T1057
Process Discovery
MalwareNETWIRE

NETWIRE can discover processes on compromised hosts.

T1059.001
PowerShell
MalwareNETWIRE

The NETWIRE binary has been executed via PowerShell script.

T1059.003
Windows Command Shell
MalwareNETWIRE

NETWIRE can issue commands using cmd.exe.

T1059.004
Unix Shell
MalwareNETWIRE

NETWIRE has the ability to use /bin/bash and /bin/sh to execute commands.

T1059.005
Visual Basic
MalwareNETWIRE

NETWIRE has been executed through use of VBScripts.

T1071.001
Web Protocols
MalwareNETWIRE

NETWIRE has the ability to communicate over HTTP.

T1074.001
Local Data Staging
MalwareNETWIRE

NETWIRE has the ability to write collected data to a file created in the ./LOGS directory.

T1082
System Information Discovery
MalwareNETWIRE

NETWIRE can discover and collect victim system information.

T1083
File and Directory Discovery
MalwareNETWIRE

NETWIRE has the ability to search for files on the compromised host.

T1090
Proxy
MalwareNETWIRE

NETWIRE can implement use of proxies to pivot traffic.

T1095
Non-Application Layer Protocol
MalwareNETWIRE

NETWIRE can use TCP in C2 communications.

T1102
Web Service
MalwareNETWIRE

NETWIRE has used web services including Paste.ee to host payloads.

T1105
Ingress Tool Transfer
MalwareNETWIRE

NETWIRE can downloaded payloads from C2 to the compromised host.

T1106
Native API
MalwareNETWIRE

NETWIRE can use Native API including CreateProcess GetProcessById, and WriteProcessMemory.

T1112
Modify Registry
MalwareNETWIRE

NETWIRE can modify the Registry to store its configuration information.

T1113
Screen Capture
MalwareNETWIRE

NETWIRE can capture the victim's screen.

T1119
Automated Collection
MalwareNETWIRE

NETWIRE can automatically archive collected data.

T1204.001
Malicious Link
MalwareNETWIRE

NETWIRE has been executed through convincing victims into clicking malicious links.

T1204.002
Malicious File
MalwareNETWIRE

NETWIRE has been executed through luring victims into opening malicious documents.

T1543.001
Launch Agent
MalwareNETWIRE

NETWIRE can use launch agents for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareNETWIRE

NETWIRE creates a Registry start-up entry to establish persistence.

T1547.013
XDG Autostart Entries
MalwareNETWIRE

NETWIRE can use XDG Autostart Entries to establish persistence on Linux systems.

T1547.015
Login Items
MalwareNETWIRE

NETWIRE can persist via startup options for Login items.

T1555
Credentials from Password Stores
MalwareNETWIRE

NETWIRE can retrieve passwords from messaging and mail client applications.

T1555.003
Credentials from Web Browsers
MalwareNETWIRE

NETWIRE has the ability to steal credentials from web browsers including Internet Explorer, Opera, Yandex, and Chrome.

T1560
Archive Collected Data
MalwareNETWIRE

NETWIRE has the ability to compress archived screenshots.

T1560.003
Archive via Custom Method
MalwareNETWIRE

NETWIRE has used a custom encryption algorithm to encrypt collected data.

T1564.001
Hidden Files and Directories
MalwareNETWIRE

NETWIRE can copy itself to and launch itself from hidden folders.

T1566.001
Spearphishing Attachment
MalwareNETWIRE

NETWIRE has been spread via e-mail campaigns utilizing malicious attachments.

T1566.002
Spearphishing Link
MalwareNETWIRE

NETWIRE has been spread via e-mail campaigns utilizing malicious links.

T1573
Encrypted Channel
MalwareNETWIRE

NETWIRE can encrypt C2 communications.

T1573.001
Symmetric Cryptography
MalwareNETWIRE

NETWIRE can use AES encryption for C2 data transferred.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.