Real-world descriptions of how a group, tool or campaign used a technique.
26 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareBandook | Bandook can collect local files from the system . |
| T1016 System Network Configuration Discovery |
MalwareBandook | Bandook has a command to get the public IP address from a system. |
| T1027.003 Steganography |
MalwareBandook | Bandook has used .PNG images within a zip file to build the executable. |
| T1041 Exfiltration Over C2 Channel |
MalwareBandook | Bandook can upload files from a victim's machine over the C2 channel. |
| T1055.012 Process Hollowing |
MalwareBandook | Bandook has been launched by starting iexplore.exe and replacing it with Bandook's payload. |
| T1056.001 Keylogging |
MalwareBandook | Bandook contains keylogging capabilities. |
| T1059 Command and Scripting Interpreter |
MalwareBandook | Bandook can support commands to execute Java-based payloads. |
| T1059.001 PowerShell |
MalwareBandook | Bandook has used PowerShell loaders as part of execution. |
| T1059.003 Windows Command Shell |
MalwareBandook | Bandook is capable of spawning a Windows command shell. |
| T1059.005 Visual Basic |
MalwareBandook | Bandook has used malicious VBA code against the target system. |
| T1059.006 Python |
MalwareBandook | Bandook can support commands to execute Python-based payloads. |
| T1070.004 File Deletion |
MalwareBandook | Bandook has a command to delete a file. |
| T1083 File and Directory Discovery |
MalwareBandook | Bandook has a command to list files on a system. |
| T1095 Non-Application Layer Protocol |
MalwareBandook | Bandook has a command built in to use a raw TCP socket. |
| T1105 Ingress Tool Transfer |
MalwareBandook | Bandook can download files to the system. |
| T1106 Native API |
MalwareBandook | Bandook has used the ShellExecuteW() function call. |
| T1113 Screen Capture |
MalwareBandook | Bandook is capable of taking an image of and uploading the current desktop. |
| T1120 Peripheral Device Discovery |
MalwareBandook | Bandook can detect USB devices. |
| T1123 Audio Capture |
MalwareBandook | Bandook has modules that are capable of capturing audio. |
| T1125 Video Capture |
MalwareBandook | Bandook has modules that are capable of capturing video from a victim's webcam. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBandook | Bandook has decoded its PowerShell script. |
| T1204.002 Malicious File |
MalwareBandook | Bandook has used lure documents to convince the user to enable macros. |
| T1553.002 Code Signing |
MalwareBandook | Bandook was signed with valid Certum certificates. |
| T1566.001 Spearphishing Attachment |
MalwareBandook | Bandook is delivered via a malicious Word document inside a zip file. |
| T1573.001 Symmetric Cryptography |
MalwareBandook | Bandook has used AES encryption for C2 communication. |
| T1680 Local Storage Discovery |
MalwareBandook | Bandook can collect information about the drives available on the system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.