Real-world descriptions of how a group, tool or campaign used a technique.
27 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwarePOWERSTATS | POWERSTATS can upload files from compromised hosts. |
| T1016 System Network Configuration Discovery |
MalwarePOWERSTATS | POWERSTATS can retrieve IP, network adapter configuration information, and domain from compromised hosts. |
| T1027.010 Command Obfuscation |
MalwarePOWERSTATS | POWERSTATS uses character replacement, PowerShell environment variables, and XOR encoding to obfuscate code. POWERSTATS's backdoor code is a multi-layer obfuscated, encoded, and compressed blob. POWERSTATS has used PowerShell code with custom string obfuscation |
| T1027.016 Junk Code Insertion |
MalwarePOWERSTATS | POWERSTATS has used useless code blocks to counter analysis. |
| T1029 Scheduled Transfer |
MalwarePOWERSTATS | POWERSTATS can sleep for a given number of seconds. |
| T1033 System Owner/User Discovery |
MalwarePOWERSTATS | POWERSTATS has the ability to identify the username on the compromised host. |
| T1036.004 Masquerade Task or Service |
MalwarePOWERSTATS | POWERSTATS has created a scheduled task named "MicrosoftEdge" to establish persistence. |
| T1047 Windows Management Instrumentation |
MalwarePOWERSTATS | POWERSTATS can use WMI queries to retrieve data from compromised hosts. |
| T1053.005 Scheduled Task |
MalwarePOWERSTATS | POWERSTATS has established persistence through a scheduled task using the command |
| T1057 Process Discovery |
MalwarePOWERSTATS | POWERSTATS has used |
| T1059.001 PowerShell |
MalwarePOWERSTATS | POWERSTATS uses PowerShell for obfuscation and execution. |
| T1059.005 Visual Basic |
MalwarePOWERSTATS | POWERSTATS can use VBScript (VBE) code for execution. |
| T1059.007 JavaScript |
MalwarePOWERSTATS | POWERSTATS can use JavaScript code for execution. |
| T1070.004 File Deletion |
MalwarePOWERSTATS | POWERSTATS can delete all files on the C:\, D:\, E:\ and, F:\ drives using PowerShell Remove-Item commands. |
| T1082 System Information Discovery |
MalwarePOWERSTATS | POWERSTATS can retrieve OS name/architecture and computer/domain name information from compromised hosts. |
| T1087.001 Local Account |
MalwarePOWERSTATS | POWERSTATS can retrieve usernames from compromised hosts. |
| T1090.002 External Proxy |
MalwarePOWERSTATS | POWERSTATS has connected to C2 servers through proxies. |
| T1105 Ingress Tool Transfer |
MalwarePOWERSTATS | POWERSTATS can retrieve and execute additional PowerShell payloads from the C2 server. |
| T1113 Screen Capture |
MalwarePOWERSTATS | POWERSTATS can retrieve screenshots from compromised hosts. |
| T1132.001 Standard Encoding |
MalwarePOWERSTATS | POWERSTATS encoded C2 traffic with base64. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePOWERSTATS | POWERSTATS can deobfuscate the main backdoor code. |
| T1218.005 Mshta |
MalwarePOWERSTATS | POWERSTATS can use Mshta.exe to execute additional payloads on compromised hosts. |
| T1518.001 Security Software Discovery |
MalwarePOWERSTATS | POWERSTATS has detected security tools. |
| T1559.001 Component Object Model |
MalwarePOWERSTATS | POWERSTATS can use DCOM (targeting the 127.0.0.1 loopback address) to execute additional payloads on compromised hosts. |
| T1559.002 Dynamic Data Exchange |
MalwarePOWERSTATS | POWERSTATS can use DDE to execute additional payloads on compromised hosts. |
| T1573.002 Asymmetric Cryptography |
MalwarePOWERSTATS | POWERSTATS has encrypted C2 traffic with RSA. |
| T1685 Disable or Modify Tools |
MalwarePOWERSTATS | POWERSTATS can disable Microsoft Office Protected View by changing Registry keys. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.