ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0262×

25 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
ToolQuasarRAT

QuasarRAT can retrieve files from compromised client machines.

T1010
Application Window Discovery
ToolQuasarRAT

APT-C-36 used a customized version of QuasarRAT to monitor browser windows for strings relating to specific Colombian financial institutions.

T1016
System Network Configuration Discovery
ToolQuasarRAT

QuasarRAT has the ability to enumerate the Wide Area Network (WAN) IP through requests to ip-api[.]com, freegeoip[.]net, or api[.]ipify[.]org observed with user-agent string `Mozilla/5.0 (Windows NT 6.3; rv:48.0) Gecko/20100101 Firefox/48.0`.

T1021.001
Remote Desktop Protocol
ToolQuasarRAT

QuasarRAT has a module for performing remote desktop access.

T1033
System Owner/User Discovery
ToolQuasarRAT

QuasarRAT can enumerate the username and account type.

T1053.005
Scheduled Task
ToolQuasarRAT

QuasarRAT contains a .NET wrapper DLL for creating and managing scheduled tasks for maintaining persistence upon reboot.

T1056.001
Keylogging
ToolQuasarRAT

QuasarRAT has a built-in keylogger.

T1059.003
Windows Command Shell
ToolQuasarRAT

QuasarRAT can launch a remote shell to execute commands on the victim’s machine.

T1082
System Information Discovery
ToolQuasarRAT

QuasarRAT can gather system information from the victim’s machine including the OS type.

T1090
Proxy
ToolQuasarRAT

QuasarRAT can communicate over a reverse proxy using SOCKS5.

T1095
Non-Application Layer Protocol
ToolQuasarRAT

QuasarRAT can use TCP for C2 communication.

T1105
Ingress Tool Transfer
ToolQuasarRAT

QuasarRAT can download files to the victim’s machine and execute them.

T1112
Modify Registry
ToolQuasarRAT

QuasarRAT has a command to edit the Registry on the victim’s machine.

T1125
Video Capture
ToolQuasarRAT

QuasarRAT can perform webcam viewing.

T1547.001
Registry Run Keys / Startup Folder
ToolQuasarRAT

If the QuasarRAT client process does not have administrator privileges it will add a registry key to `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` for persistence.

T1548.002
Bypass User Account Control
ToolQuasarRAT

QuasarRAT can generate a UAC pop-up Window to prompt the target user to run a command as the administrator.

T1552.001
Credentials In Files
ToolQuasarRAT

QuasarRAT can obtain passwords from FTP clients.

T1553.002
Code Signing
ToolQuasarRAT

A QuasarRAT .dll file is digitally signed by a certificate from AirVPN.

T1555
Credentials from Password Stores
ToolQuasarRAT

QuasarRAT can obtain passwords from common FTP clients.

T1555.003
Credentials from Web Browsers
ToolQuasarRAT

QuasarRAT can obtain passwords from common web browsers.

T1564.001
Hidden Files and Directories
ToolQuasarRAT

QuasarRAT has the ability to set file attributes to "hidden" to hide files from the compromised user's view in Windows File Explorer.

T1564.003
Hidden Window
ToolQuasarRAT

QuasarRAT can hide process windows and make web requests invisible to the compromised user. Requests marked as invisible have been sent with user-agent string `Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit/537.75.14 (KHTML, like Gecko) Version/7.0.3 Safari/7046A194A` though QuasarRAT can only be run on Windows systems.

T1571
Non-Standard Port
ToolQuasarRAT

QuasarRAT can use port 4782 on the compromised host for TCP callbacks.

T1573.001
Symmetric Cryptography
ToolQuasarRAT

QuasarRAT uses AES with a hardcoded pre-shared key to encrypt network communication.

T1614
System Location Discovery
ToolQuasarRAT

QuasarRAT can determine the country a victim host is located in.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.