ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0269×

17 examples

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareQUADAGENT

QUADAGENT uses multiple protocols (HTTPS, HTTP, DNS) for its C2 server as fallback channels if communication with one is unsuccessful.

T1012
Query Registry
MalwareQUADAGENT

QUADAGENT checks if a value exists within a Registry key in the HKCU hive whose name is the same as the scheduled task it has created.

T1016
System Network Configuration Discovery
MalwareQUADAGENT

QUADAGENT gathers the current domain the victim system belongs to.

T1027.010
Command Obfuscation
MalwareQUADAGENT

QUADAGENT was likely obfuscated using `Invoke-Obfuscation`.

T1027.011
Fileless Storage
MalwareQUADAGENT

QUADAGENT stores a session identifier unique to the compromised system as well as a pre-shared key used for encrypting and decrypting C2 communications within a Registry key (such as `HKCU\Office365DCOMCheck`) in the `HKCU` hive.

T1033
System Owner/User Discovery
MalwareQUADAGENT

QUADAGENT gathers the victim username.

T1036.005
Match Legitimate Resource Name or Location
MalwareQUADAGENT

QUADAGENT used the PowerShell filenames Office365DCOMCheck.ps1 and SystemDiskClean.ps1.

T1053.005
Scheduled Task
MalwareQUADAGENT

QUADAGENT creates a scheduled task to maintain persistence on the victim’s machine.

T1059.001
PowerShell
MalwareQUADAGENT

QUADAGENT uses PowerShell scripts for execution.

T1059.003
Windows Command Shell
MalwareQUADAGENT

QUADAGENT uses cmd.exe to execute scripts and commands on the victim’s machine.

T1059.005
Visual Basic
MalwareQUADAGENT

QUADAGENT uses VBScripts.

T1070.004
File Deletion
MalwareQUADAGENT

QUADAGENT has a command to delete its Registry key and scheduled task.

T1071.001
Web Protocols
MalwareQUADAGENT

QUADAGENT uses HTTPS and HTTP for C2 communications.

T1071.004
DNS
MalwareQUADAGENT

QUADAGENT uses DNS for C2 communications.

T1112
Modify Registry
MalwareQUADAGENT

QUADAGENT modifies an HKCU Registry key to store a session identifier unique to the compromised system as well as a pre-shared key used for encrypting and decrypting C2 communications.

T1132.001
Standard Encoding
MalwareQUADAGENT

QUADAGENT encodes C2 communications with base64.

T1140
Deobfuscate/Decode Files or Information
MalwareQUADAGENT

QUADAGENT uses AES and a preshared key to decrypt the custom Base64 routine used to encode strings and scripts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.