ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0203×

19 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can read data from files.

T1007
System Service Discovery
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can monitor services.

T1012
Query Registry
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can retrieve system information, such as CPU speed, from Registry keys.

T1016
System Network Configuration Discovery
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can retrieve IP addresses of compromised machines.

T1027
Obfuscated Files or Information
MalwareHydraq

Hydraq uses basic obfuscation in the form of spaghetti code.

T1048
Exfiltration Over Alternative Protocol
MalwareHydraq

Hydraq connects to a predefined domain on port 443 to exfil gathered information.

T1057
Process Discovery
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can monitor processes.

T1070.004
File Deletion
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can delete files.

T1082
System Information Discovery
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can retrieve information such as computer name, OS version, processor speed, memory size, and CPU speed.

T1083
File and Directory Discovery
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can check for the existence of files, including its own components, as well as retrieve a list of logical drives.

T1105
Ingress Tool Transfer
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can download files and additional malware components.

T1112
Modify Registry
MalwareHydraq

Hydraq creates a Registry subkey to register its created service, and can also uninstall itself later by deleting this value. Hydraq's backdoor also enables remote attackers to modify and delete subkeys.

T1113
Screen Capture
MalwareHydraq

Hydraq includes a component based on the code of VNC that can stream a live feed of the desktop of an infected host.

T1129
Shared Modules
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can load and call DLL functions.

T1134
Access Token Manipulation
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can adjust token privileges.

T1543.003
Windows Service
MalwareHydraq

Hydraq creates new services to establish persistence.

T1569.002
Service Execution
MalwareHydraq

Hydraq uses svchost.exe to execute a malicious DLL included in a new service group.

T1573.001
Symmetric Cryptography
MalwareHydraq

Hydraq C2 traffic is encrypted using bitwise NOT and XOR operations.

T1685.005
Clear Windows Event Logs
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can clear all system event logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.