ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0264×

19 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareOopsIE

OopsIE uses the Confuser protector to obfuscate an embedded .Net Framework assembly used for C2. OopsIE also encodes collected data in hexadecimal format before writing to files on disk and obfuscates strings.

T1027.002
Software Packing
MalwareOopsIE

OopsIE uses the SmartAssembly obfuscator to pack an embedded .Net Framework assembly used for C2.

T1030
Data Transfer Size Limits
MalwareOopsIE

OopsIE exfiltrates command output and collected files to its C2 server in 1500-byte blocks.

T1041
Exfiltration Over C2 Channel
MalwareOopsIE

OopsIE can upload files from the victim's machine to its C2 server.

T1047
Windows Management Instrumentation
MalwareOopsIE

OopsIE uses WMI to perform discovery techniques.

T1053.005
Scheduled Task
MalwareOopsIE

OopsIE creates a scheduled task to run itself every three minutes.

T1059.003
Windows Command Shell
MalwareOopsIE

OopsIE uses the command prompt to execute commands on the victim's machine.

T1059.005
Visual Basic
MalwareOopsIE

OopsIE creates and uses a VBScript as part of its persistent execution.

T1070.004
File Deletion
MalwareOopsIE

OopsIE has the capability to delete files and scripts from the victim's machine.

T1071.001
Web Protocols
MalwareOopsIE

OopsIE uses HTTP for C2 communications.

T1074.001
Local Data Staging
MalwareOopsIE

OopsIE stages the output from command execution and collected files in specific folders before exfiltration.

T1082
System Information Discovery
MalwareOopsIE

OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks.

T1105
Ingress Tool Transfer
MalwareOopsIE

OopsIE can download files from its C2 server to the victim's machine.

T1124
System Time Discovery
MalwareOopsIE

OopsIE checks to see if the system is configured with "Daylight" time and checks for a specific region to be set for the timezone.

T1132.001
Standard Encoding
MalwareOopsIE

OopsIE encodes data in hexadecimal format over the C2 channel.

T1140
Deobfuscate/Decode Files or Information
MalwareOopsIE

OopsIE concatenates then decompresses multiple resources to load an embedded .Net Framework assembly.

T1497.001
System Checks
MalwareOopsIE

OopsIE performs several anti-VM and sandbox checks on the victim's machine. One technique the group has used was to perform a WMI query SELECT * FROM MSAcpi_ThermalZoneTemperature to check the temperature to see if it’s running in a virtual environment.

T1560.001
Archive via Utility
MalwareOopsIE

OopsIE compresses collected files with GZipStream before sending them to its C2 server.

T1560.003
Archive via Custom Method
MalwareOopsIE

OopsIE compresses collected files with a simple character replacement scheme before sending them to its C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.