ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0201×

20 examples

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareJPIN

JPIN can list running services.

T1012
Query Registry
MalwareJPIN

JPIN can enumerate Registry keys.

T1016
System Network Configuration Discovery
MalwareJPIN

JPIN can obtain network information, including DNS, IP, and proxies.

T1027
Obfuscated Files or Information
MalwareJPIN

A JPIN uses a encrypted and compressed payload that is disguised as a bitmap within the resource section of the installer.

T1033
System Owner/User Discovery
MalwareJPIN

JPIN can obtain the victim user name.

T1055
Process Injection
MalwareJPIN

JPIN can inject content into lsass.exe to load a module.

T1056.001
Keylogging
MalwareJPIN

JPIN contains a custom keylogger.

T1057
Process Discovery
MalwareJPIN

JPIN can list running processes.

T1059.003
Windows Command Shell
MalwareJPIN

JPIN can use the command-line utility cacls.exe to change file permissions.

T1069.001
Local Groups
MalwareJPIN

JPIN can obtain the permissions of the victim user.

T1070.004
File Deletion
MalwareJPIN

JPIN's installer/uninstaller component deletes itself if it encounters a version of Windows earlier than Windows XP or identifies security-related processes running.

T1071.002
File Transfer Protocols
MalwareJPIN

JPIN can communicate over FTP.

T1071.003
Mail Protocols
MalwareJPIN

JPIN can send email over SMTP.

T1082
System Information Discovery
MalwareJPIN

JPIN can obtain system information such as OS version and disk space.

T1083
File and Directory Discovery
MalwareJPIN

JPIN can enumerate drives and their types. It can also change file permissions using cacls.exe.

T1105
Ingress Tool Transfer
MalwareJPIN

JPIN can download files and upgrade itself.

T1197
BITS Jobs
MalwareJPIN

A JPIN variant downloads the backdoor payload via the BITS service.

T1222.001
Windows Permissions
MalwareJPIN

JPIN can use the command-line utility cacls.exe to change file permissions.

T1518.001
Security Software Discovery
MalwareJPIN

JPIN checks for the presence of certain security-related processes and deletes its installer/uninstaller component if it identifies any of them.

T1685
Disable or Modify Tools
MalwareJPIN

JPIN can lower security settings by changing Registry keys.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.