ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0270×

18 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareRogueRobin

RogueRobin gathers the IP address and domain from the victim’s machine.

T1027.010
Command Obfuscation
MalwareRogueRobin

The PowerShell script with the RogueRobin payload was obfuscated using the COMPRESS technique in `Invoke-Obfuscation`.

T1033
System Owner/User Discovery
MalwareRogueRobin

RogueRobin collects the victim’s username and whether that user is an admin.

T1047
Windows Management Instrumentation
MalwareRogueRobin

RogueRobin uses various WMI queries to check if the sample is running in a sandbox.

T1057
Process Discovery
MalwareRogueRobin

RogueRobin checks the running processes for evidence it may be running in a sandbox environment. It specifically enumerates processes for Wireshark and Sysinternals.

T1059.001
PowerShell
MalwareRogueRobin

RogueRobin uses a command prompt to run a PowerShell script from Excel. To assist in establishing persistence, RogueRobin creates %APPDATA%\OneDrive.bat and saves the following string to it:powershell.exe -WindowStyle Hidden -exec bypass -File “%APPDATA%\OneDrive.ps1”.

T1059.003
Windows Command Shell
MalwareRogueRobin

RogueRobin uses Windows Script Components.

T1082
System Information Discovery
MalwareRogueRobin

RogueRobin gathers BIOS versions and manufacturers, the number of CPU cores, the total physical memory, and the computer name.

T1102.002
Bidirectional Communication
MalwareRogueRobin

RogueRobin has used Google Drive as a Command and Control channel.

T1105
Ingress Tool Transfer
MalwareRogueRobin

RogueRobin can save a new file to the system from the C2 server.

T1113
Screen Capture
MalwareRogueRobin

RogueRobin has a command named $screenshot that may be responsible for taking screenshots of the victim machine.

T1132.001
Standard Encoding
MalwareRogueRobin

RogueRobin base64 encodes strings that are sent to the C2 over its DNS tunnel.

T1140
Deobfuscate/Decode Files or Information
MalwareRogueRobin

RogueRobin decodes an embedded executable using base64 and decompresses it.

T1218.010
Regsvr32
MalwareRogueRobin

RogueRobin uses regsvr32.exe to run a .sct file for execution.

T1497.001
System Checks
MalwareRogueRobin

RogueRobin uses WMI to check BIOS version for VBOX, bochs, qemu, virtualbox, and vm to check for evidence that the script might be executing within an analysis environment.

T1518.001
Security Software Discovery
MalwareRogueRobin

RogueRobin enumerates running processes to search for Wireshark and Windows Sysinternals suite.

T1547.001
Registry Run Keys / Startup Folder
MalwareRogueRobin

RogueRobin created a shortcut in the Windows startup folder to launch a PowerShell script each time the user logs in to establish persistence.

T1547.009
Shortcut Modification
MalwareRogueRobin

RogueRobin establishes persistence by creating a shortcut (.LNK file) in the Windows startup folder to run a script each time the user logs in.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.