ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0237×

19 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareGravityRAT

GravityRAT steals files with the following extensions: .docx, .doc, .pptx, .ppt, .xlsx, .xls, .rtf, and .pdf.

T1007
System Service Discovery
MalwareGravityRAT

GravityRAT has a feature to list the available services on the system.

T1016
System Network Configuration Discovery
MalwareGravityRAT

GravityRAT collects the victim IP address, MAC address, as well as the victim account domain name.

T1025
Data from Removable Media
MalwareGravityRAT

GravityRAT steals files based on an extension list if a USB drive is connected to the system.

T1027.005
Indicator Removal from Tools
MalwareGravityRAT

The author of GravityRAT submitted samples to VirusTotal for testing, showing that the author modified the code to try to hide the DDE object in a different part of the document.

T1027.013
Encrypted/Encoded File
MalwareGravityRAT

GravityRAT supports file encryption (AES with the key "lolomycin2017").

T1033
System Owner/User Discovery
MalwareGravityRAT

GravityRAT collects the victim username along with other account information (account type, description, full name, SID and status).

T1047
Windows Management Instrumentation
MalwareGravityRAT

GravityRAT collects various information via WMI requests, including CPU information in the Win32_Processor entry (Processor ID, Name, Manufacturer and the clock speed).

T1049
System Network Connections Discovery
MalwareGravityRAT

GravityRAT uses the netstat command to find open ports on the victim’s machine.

T1053.005
Scheduled Task
MalwareGravityRAT

GravityRAT creates a scheduled task to ensure it is re-executed everyday.

T1057
Process Discovery
MalwareGravityRAT

GravityRAT lists the running processes on the system.

T1059.003
Windows Command Shell
MalwareGravityRAT

GravityRAT executes commands remotely on the infected host.

T1071.001
Web Protocols
MalwareGravityRAT

GravityRAT uses HTTP for C2.

T1082
System Information Discovery
MalwareGravityRAT

GravityRAT collects the MAC address, computer name, and CPU information.

T1083
File and Directory Discovery
MalwareGravityRAT

GravityRAT collects the volumes mapped on the system, and also steals files with the following extensions: .docx, .doc, .pptx, .ppt, .xlsx, .xls, .rtf, and .pdf.

T1124
System Time Discovery
MalwareGravityRAT

GravityRAT can obtain the date and time of a system.

T1497.001
System Checks
MalwareGravityRAT

GravityRAT uses WMI to check the BIOS and manufacturer information for strings like "VMWare", "Virtual", and "XEN" and another WMI request to get the current temperature of the hardware to determine if it's a virtual machine environment.

T1559.002
Dynamic Data Exchange
MalwareGravityRAT

GravityRAT has been delivered via Word documents using DDE for execution.

T1571
Non-Standard Port
MalwareGravityRAT

GravityRAT has used HTTP over a non-standard port, such as TCP port 46769.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.