ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0244×

19 examples

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareComnie

Comnie runs the command: net start >> %TEMP%\info.dat on a victim.

T1016
System Network Configuration Discovery
MalwareComnie

Comnie uses ipconfig /all and route PRINT to identify network adapter and interface information.

T1018
Remote System Discovery
MalwareComnie

Comnie runs the net view command

T1027
Obfuscated Files or Information
MalwareComnie

Comnie uses RC4 and Base64 to obfuscate strings.

T1027.001
Binary Padding
MalwareComnie

Comnie appends a total of 64MB of garbage data to a file to deter any security products in place that may be scanning files on disk.

T1049
System Network Connections Discovery
MalwareComnie

Comnie executes the netstat -ano command.

T1057
Process Discovery
MalwareComnie

Comnie uses the tasklist to view running processes on the victim’s machine.

T1059.003
Windows Command Shell
MalwareComnie

Comnie executes BAT scripts.

T1059.005
Visual Basic
MalwareComnie

Comnie executes VBS scripts.

T1071.001
Web Protocols
MalwareComnie

Comnie uses HTTP for C2 communication.

T1082
System Information Discovery
MalwareComnie

Comnie collects the hostname of the victim machine.

T1087.001
Local Account
MalwareComnie

Comnie uses the net user command.

T1102.002
Bidirectional Communication
MalwareComnie

Comnie uses blogs and third-party sites (GitHub, tumbler, and BlogSpot) to avoid DNS-based blocking of their communication to the command and control server.

T1119
Automated Collection
MalwareComnie

Comnie executes a batch script to store discovery information in %TEMP%\info.dat and then uploads the temporarily file to the remote C2 server.

T1218.011
Rundll32
MalwareComnie

Comnie uses Rundll32 to load a malicious DLL.

T1518.001
Security Software Discovery
MalwareComnie

Comnie attempts to detect several anti-virus products.

T1547.001
Registry Run Keys / Startup Folder
MalwareComnie

Comnie achieves persistence by adding a shortcut of itself to the startup path in the Registry.

T1547.009
Shortcut Modification
MalwareComnie

Comnie establishes persistence via a .lnk file in the victim’s startup path.

T1573.001
Symmetric Cryptography
MalwareComnie

Comnie encrypts command and control communications with RC4.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.