Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareFELIXROOT | FELIXROOT queries the Registry for specific keys for potential privilege escalation and proxy information. FELIXROOT has also used WMI to query the Windows Registry. |
| T1016 System Network Configuration Discovery |
MalwareFELIXROOT | FELIXROOT collects information about the network including the IP address and DHCP server. |
| T1027.013 Encrypted/Encoded File |
MalwareFELIXROOT | FELIXROOT encrypts strings in the backdoor using a custom XOR algorithm. |
| T1033 System Owner/User Discovery |
MalwareFELIXROOT | FELIXROOT collects the username from the victim’s machine. |
| T1047 Windows Management Instrumentation |
MalwareFELIXROOT | FELIXROOT uses WMI to query the Windows Registry. |
| T1057 Process Discovery |
MalwareFELIXROOT | FELIXROOT collects a list of running processes. |
| T1059.003 Windows Command Shell |
MalwareFELIXROOT | FELIXROOT executes batch scripts on the victim’s machine, and can launch a reverse shell for command execution. |
| T1070.004 File Deletion |
MalwareFELIXROOT | FELIXROOT deletes the .LNK file from the startup directory as well as the dropper components. |
| T1071.001 Web Protocols |
MalwareFELIXROOT | FELIXROOT uses HTTP and HTTPS to communicate with the C2 server. |
| T1082 System Information Discovery |
MalwareFELIXROOT | FELIXROOT collects the victim’s computer name, processor architecture, OS version, and system type. |
| T1105 Ingress Tool Transfer |
MalwareFELIXROOT | FELIXROOT downloads and uploads files to and from the victim’s machine. |
| T1112 Modify Registry |
MalwareFELIXROOT | FELIXROOT deletes the Registry key |
| T1124 System Time Discovery |
MalwareFELIXROOT | FELIXROOT gathers the time zone information from the victim’s machine. |
| T1218.011 Rundll32 |
MalwareFELIXROOT | FELIXROOT uses Rundll32 for executing the dropper program. |
| T1518.001 Security Software Discovery |
MalwareFELIXROOT | FELIXROOT checks for installed security software like antivirus and firewall. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFELIXROOT | FELIXROOT adds a shortcut file to the startup folder for persistence. |
| T1547.009 Shortcut Modification |
MalwareFELIXROOT | FELIXROOT creates a .LNK file for persistence. |
| T1560 Archive Collected Data |
MalwareFELIXROOT | FELIXROOT encrypts collected data with AES and Base64 and then sends it to the C2 server. |
| T1680 Local Storage Discovery |
MalwareFELIXROOT | FELIXROOT collects the victim’s volume serial number. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.