ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0267×

19 examples

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareFELIXROOT

FELIXROOT queries the Registry for specific keys for potential privilege escalation and proxy information. FELIXROOT has also used WMI to query the Windows Registry.

T1016
System Network Configuration Discovery
MalwareFELIXROOT

FELIXROOT collects information about the network including the IP address and DHCP server.

T1027.013
Encrypted/Encoded File
MalwareFELIXROOT

FELIXROOT encrypts strings in the backdoor using a custom XOR algorithm.

T1033
System Owner/User Discovery
MalwareFELIXROOT

FELIXROOT collects the username from the victim’s machine.

T1047
Windows Management Instrumentation
MalwareFELIXROOT

FELIXROOT uses WMI to query the Windows Registry.

T1057
Process Discovery
MalwareFELIXROOT

FELIXROOT collects a list of running processes.

T1059.003
Windows Command Shell
MalwareFELIXROOT

FELIXROOT executes batch scripts on the victim’s machine, and can launch a reverse shell for command execution.

T1070.004
File Deletion
MalwareFELIXROOT

FELIXROOT deletes the .LNK file from the startup directory as well as the dropper components.

T1071.001
Web Protocols
MalwareFELIXROOT

FELIXROOT uses HTTP and HTTPS to communicate with the C2 server.

T1082
System Information Discovery
MalwareFELIXROOT

FELIXROOT collects the victim’s computer name, processor architecture, OS version, and system type.

T1105
Ingress Tool Transfer
MalwareFELIXROOT

FELIXROOT downloads and uploads files to and from the victim’s machine.

T1112
Modify Registry
MalwareFELIXROOT

FELIXROOT deletes the Registry key HKCU\Software\Classes\Applications\rundll32.exe\shell\open.

T1124
System Time Discovery
MalwareFELIXROOT

FELIXROOT gathers the time zone information from the victim’s machine.

T1218.011
Rundll32
MalwareFELIXROOT

FELIXROOT uses Rundll32 for executing the dropper program.

T1518.001
Security Software Discovery
MalwareFELIXROOT

FELIXROOT checks for installed security software like antivirus and firewall.

T1547.001
Registry Run Keys / Startup Folder
MalwareFELIXROOT

FELIXROOT adds a shortcut file to the startup folder for persistence.

T1547.009
Shortcut Modification
MalwareFELIXROOT

FELIXROOT creates a .LNK file for persistence.

T1560
Archive Collected Data
MalwareFELIXROOT

FELIXROOT encrypts collected data with AES and Base64 and then sends it to the C2 server.

T1680
Local Storage Discovery
MalwareFELIXROOT

FELIXROOT collects the victim’s volume serial number.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.