Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareGravityRAT | GravityRAT steals files with the following extensions: .docx, .doc, .pptx, .ppt, .xlsx, .xls, .rtf, and .pdf. |
| T1007 System Service Discovery |
MalwareGravityRAT | GravityRAT has a feature to list the available services on the system. |
| T1016 System Network Configuration Discovery |
MalwareGravityRAT | GravityRAT collects the victim IP address, MAC address, as well as the victim account domain name. |
| T1025 Data from Removable Media |
MalwareGravityRAT | GravityRAT steals files based on an extension list if a USB drive is connected to the system. |
| T1027.005 Indicator Removal from Tools |
MalwareGravityRAT | The author of GravityRAT submitted samples to VirusTotal for testing, showing that the author modified the code to try to hide the DDE object in a different part of the document. |
| T1027.013 Encrypted/Encoded File |
MalwareGravityRAT | GravityRAT supports file encryption (AES with the key "lolomycin2017"). |
| T1033 System Owner/User Discovery |
MalwareGravityRAT | GravityRAT collects the victim username along with other account information (account type, description, full name, SID and status). |
| T1047 Windows Management Instrumentation |
MalwareGravityRAT | GravityRAT collects various information via WMI requests, including CPU information in the Win32_Processor entry (Processor ID, Name, Manufacturer and the clock speed). |
| T1049 System Network Connections Discovery |
MalwareGravityRAT | GravityRAT uses the |
| T1053.005 Scheduled Task |
MalwareGravityRAT | GravityRAT creates a scheduled task to ensure it is re-executed everyday. |
| T1057 Process Discovery |
MalwareGravityRAT | GravityRAT lists the running processes on the system. |
| T1059.003 Windows Command Shell |
MalwareGravityRAT | GravityRAT executes commands remotely on the infected host. |
| T1071.001 Web Protocols |
MalwareGravityRAT | GravityRAT uses HTTP for C2. |
| T1082 System Information Discovery |
MalwareGravityRAT | GravityRAT collects the MAC address, computer name, and CPU information. |
| T1083 File and Directory Discovery |
MalwareGravityRAT | GravityRAT collects the volumes mapped on the system, and also steals files with the following extensions: .docx, .doc, .pptx, .ppt, .xlsx, .xls, .rtf, and .pdf. |
| T1124 System Time Discovery |
MalwareGravityRAT | GravityRAT can obtain the date and time of a system. |
| T1497.001 System Checks |
MalwareGravityRAT | GravityRAT uses WMI to check the BIOS and manufacturer information for strings like "VMWare", "Virtual", and "XEN" and another WMI request to get the current temperature of the hardware to determine if it's a virtual machine environment. |
| T1559.002 Dynamic Data Exchange |
MalwareGravityRAT | GravityRAT has been delivered via Word documents using DDE for execution. |
| T1571 Non-Standard Port |
MalwareGravityRAT | GravityRAT has used HTTP over a non-standard port, such as TCP port 46769. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.