ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0251×

31 examples

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareZebrocy

Zebrocy executes the reg query command to obtain information in the Registry.

T1016
System Network Configuration Discovery
MalwareZebrocy

Zebrocy runs the ipconfig /all command.

T1027.002
Software Packing
MalwareZebrocy

Zebrocy's Delphi variant was packed with UPX.

T1033
System Owner/User Discovery
MalwareZebrocy

Zebrocy gets the username from the system.

T1037.001
Logon Script (Windows)
MalwareZebrocy

Zebrocy performs persistence with a logon script via adding to the Registry key HKCU\Environment\UserInitMprLogonScript.

T1041
Exfiltration Over C2 Channel
MalwareZebrocy

Zebrocy has exfiltrated data to the designated C2 server using HTTP POST requests.

T1047
Windows Management Instrumentation
MalwareZebrocy

One variant of Zebrocy uses WMI queries to gather information.

T1049
System Network Connections Discovery
MalwareZebrocy

Zebrocy uses netstat -aon to gather network connection information.

T1053.005
Scheduled Task
MalwareZebrocy

Zebrocy has a command to create a scheduled task for persistence.

T1056.004
Credential API Hooking
MalwareZebrocy

Zebrocy installs an application-defined Windows hook to get notified when a network drive has been attached, so it can then use the hook to call its RecordToFile file stealing method.

T1057
Process Discovery
MalwareZebrocy

Zebrocy uses the tasklist and wmic process get Capture, ExecutablePath commands to gather the processes running on the system.

T1059.003
Windows Command Shell
MalwareZebrocy

Zebrocy uses cmd.exe to execute commands on the system.

T1070.004
File Deletion
MalwareZebrocy

Zebrocy has a command to delete files and directories.

T1071.001
Web Protocols
MalwareZebrocy

Zebrocy uses HTTP for C2.

T1071.003
Mail Protocols
MalwareZebrocy

Zebrocy uses SMTP and POP3 for C2.

T1074.001
Local Data Staging
MalwareZebrocy

Zebrocy stores all collected information in a single file before exfiltration.

T1082
System Information Discovery
MalwareZebrocy

Zebrocy collects the OS version and computer name. Zebrocy also runs the systeminfo command to gather system information.

T1083
File and Directory Discovery
MalwareZebrocy

Zebrocy searches for files that are 60mb and less and contain the following extensions: .doc, .docx, .xls, .xlsx, .ppt, .pptx, .exe, .zip, and .rar. Zebrocy also runs the echo %APPDATA% command to list the contents of the directory. Zebrocy can obtain the current execution path as well as perform drive enumeration.

T1105
Ingress Tool Transfer
MalwareZebrocy

Zebrocy obtains additional code to execute on the victim's machine, including the downloading of a secondary payload.

T1113
Screen Capture
MalwareZebrocy

A variant of Zebrocy captures screenshots of the victim’s machine in JPEG and BMP format.

T1119
Automated Collection
MalwareZebrocy

Zebrocy scans the system and automatically collects files with the following extensions: .doc, .docx, ,.xls, .xlsx, .pdf, .pptx, .rar, .zip, .jpg, .jpeg, .bmp, .tiff, .kum, .tlg, .sbx, .cr, .hse, .hsf, and .lhz.

T1120
Peripheral Device Discovery
MalwareZebrocy

Zebrocy enumerates information about connected storage devices.

T1124
System Time Discovery
MalwareZebrocy

Zebrocy gathers the current time zone and date information from the system.

T1132.001
Standard Encoding
MalwareZebrocy

Zebrocy has used URL/Percent Encoding on data exfiltrated via HTTP POST requests.

T1135
Network Share Discovery
MalwareZebrocy

Zebrocy identifies network drives when they are added to victim systems.

T1140
Deobfuscate/Decode Files or Information
MalwareZebrocy

Zebrocy decodes its secondary payload and writes it to the victim’s machine. Zebrocy also uses AES and XOR to decrypt strings and payloads.

T1547.001
Registry Run Keys / Startup Folder
MalwareZebrocy

Zebrocy creates an entry in a Registry Run key for the malware to execute on startup.

T1555.003
Credentials from Web Browsers
MalwareZebrocy

Zebrocy has the capability to upload dumper tools that extract credentials from web browsers and store them in database files.

T1560
Archive Collected Data
MalwareZebrocy

Zebrocy has used a method similar to RC4 as well as AES for encryption and hexadecimal for encoding data before exfiltration.

T1573.002
Asymmetric Cryptography
MalwareZebrocy

Zebrocy uses SSL and AES ECB for encrypting C2 communications.

T1680
Local Storage Discovery
MalwareZebrocy

Zebrocy collects the serial number for the storage volume C:\.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.