ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0223×

27 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwarePOWERSTATS

POWERSTATS can upload files from compromised hosts.

T1016
System Network Configuration Discovery
MalwarePOWERSTATS

POWERSTATS can retrieve IP, network adapter configuration information, and domain from compromised hosts.

T1027.010
Command Obfuscation
MalwarePOWERSTATS

POWERSTATS uses character replacement, PowerShell environment variables, and XOR encoding to obfuscate code. POWERSTATS's backdoor code is a multi-layer obfuscated, encoded, and compressed blob. POWERSTATS has used PowerShell code with custom string obfuscation

T1027.016
Junk Code Insertion
MalwarePOWERSTATS

POWERSTATS has used useless code blocks to counter analysis.

T1029
Scheduled Transfer
MalwarePOWERSTATS

POWERSTATS can sleep for a given number of seconds.

T1033
System Owner/User Discovery
MalwarePOWERSTATS

POWERSTATS has the ability to identify the username on the compromised host.

T1036.004
Masquerade Task or Service
MalwarePOWERSTATS

POWERSTATS has created a scheduled task named "MicrosoftEdge" to establish persistence.

T1047
Windows Management Instrumentation
MalwarePOWERSTATS

POWERSTATS can use WMI queries to retrieve data from compromised hosts.

T1053.005
Scheduled Task
MalwarePOWERSTATS

POWERSTATS has established persistence through a scheduled task using the command ”C:\Windows\system32\schtasks.exe” /Create /F /SC DAILY /ST 12:00 /TN MicrosoftEdge /TR “c:\Windows\system32\wscript.exe C:\Windows\temp\Windows.vbe”.

T1057
Process Discovery
MalwarePOWERSTATS

POWERSTATS has used get_tasklist to discover processes on the compromised host.

T1059.001
PowerShell
MalwarePOWERSTATS

POWERSTATS uses PowerShell for obfuscation and execution.

T1059.005
Visual Basic
MalwarePOWERSTATS

POWERSTATS can use VBScript (VBE) code for execution.

T1059.007
JavaScript
MalwarePOWERSTATS

POWERSTATS can use JavaScript code for execution.

T1070.004
File Deletion
MalwarePOWERSTATS

POWERSTATS can delete all files on the C:\, D:\, E:\ and, F:\ drives using PowerShell Remove-Item commands.

T1082
System Information Discovery
MalwarePOWERSTATS

POWERSTATS can retrieve OS name/architecture and computer/domain name information from compromised hosts.

T1087.001
Local Account
MalwarePOWERSTATS

POWERSTATS can retrieve usernames from compromised hosts.

T1090.002
External Proxy
MalwarePOWERSTATS

POWERSTATS has connected to C2 servers through proxies.

T1105
Ingress Tool Transfer
MalwarePOWERSTATS

POWERSTATS can retrieve and execute additional PowerShell payloads from the C2 server.

T1113
Screen Capture
MalwarePOWERSTATS

POWERSTATS can retrieve screenshots from compromised hosts.

T1132.001
Standard Encoding
MalwarePOWERSTATS

POWERSTATS encoded C2 traffic with base64.

T1140
Deobfuscate/Decode Files or Information
MalwarePOWERSTATS

POWERSTATS can deobfuscate the main backdoor code.

T1218.005
Mshta
MalwarePOWERSTATS

POWERSTATS can use Mshta.exe to execute additional payloads on compromised hosts.

T1518.001
Security Software Discovery
MalwarePOWERSTATS

POWERSTATS has detected security tools.

T1559.001
Component Object Model
MalwarePOWERSTATS

POWERSTATS can use DCOM (targeting the 127.0.0.1 loopback address) to execute additional payloads on compromised hosts.

T1559.002
Dynamic Data Exchange
MalwarePOWERSTATS

POWERSTATS can use DDE to execute additional payloads on compromised hosts.

T1573.002
Asymmetric Cryptography
MalwarePOWERSTATS

POWERSTATS has encrypted C2 traffic with RSA.

T1685
Disable or Modify Tools
MalwarePOWERSTATS

POWERSTATS can disable Microsoft Office Protected View by changing Registry keys.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.