ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0257×

17 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareVERMIN

VERMIN gathers the local IP address.

T1027.002
Software Packing
MalwareVERMIN

VERMIN is initially packed.

T1027.013
Encrypted/Encoded File
MalwareVERMIN

VERMIN is obfuscated using the obfuscation tool called ConfuserEx.

T1033
System Owner/User Discovery
MalwareVERMIN

VERMIN gathers the username from the victim’s machine.

T1056.001
Keylogging
MalwareVERMIN

VERMIN collects keystrokes from the victim machine.

T1057
Process Discovery
MalwareVERMIN

VERMIN can get a list of the processes and running tasks on the system.

T1070.004
File Deletion
MalwareVERMIN

VERMIN can delete files on the victim’s machine.

T1071.001
Web Protocols
MalwareVERMIN

VERMIN uses HTTP for C2 communications.

T1082
System Information Discovery
MalwareVERMIN

VERMIN collects the OS name, machine name, and architecture information.

T1105
Ingress Tool Transfer
MalwareVERMIN

VERMIN can download and upload files to the victim's machine.

T1113
Screen Capture
MalwareVERMIN

VERMIN can perform screen captures of the victim’s machine.

T1115
Clipboard Data
MalwareVERMIN

VERMIN collects data stored in the clipboard.

T1119
Automated Collection
MalwareVERMIN

VERMIN saves each collected file with the automatically generated format {0:dd-MM-yyyy}.txt .

T1123
Audio Capture
MalwareVERMIN

VERMIN can perform audio capture.

T1140
Deobfuscate/Decode Files or Information
MalwareVERMIN

VERMIN decrypts code, strings, and commands to use once it's on the victim's machine.

T1518.001
Security Software Discovery
MalwareVERMIN

VERMIN uses WMI to check for anti-virus software installed on the system.

T1560
Archive Collected Data
MalwareVERMIN

VERMIN encrypts the collected files using 3-DES.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.