ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0330×

23 examples

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareZeus Panda

Zeus Panda checks for the existence of a Registry key and if it contains certain values.

T1027.010
Command Obfuscation
MalwareZeus Panda

Zeus Panda obfuscates the macro commands in its initial payload.

T1027.013
Encrypted/Encoded File
MalwareZeus Panda

Zeus Panda encrypts strings with XOR. Zeus Panda also encrypts all configuration and settings in AES and RC4.

T1055.002
Portable Executable Injection
MalwareZeus Panda

Zeus Panda checks processes on the system and if they meet the necessary requirements, it injects into that process.

T1056.001
Keylogging
MalwareZeus Panda

Zeus Panda can perform keylogging on the victim’s machine by hooking the functions TranslateMessage and WM_KEYDOWN.

T1056.004
Credential API Hooking
MalwareZeus Panda

Zeus Panda hooks processes by leveraging its own IAT hooked functions.

T1057
Process Discovery
MalwareZeus Panda

Zeus Panda checks for running processes on the victim’s machine.

T1059
Command and Scripting Interpreter
MalwareZeus Panda

Zeus Panda can launch remote scripts on the victim’s machine.

T1059.001
PowerShell
MalwareZeus Panda

Zeus Panda uses PowerShell to download and execute the payload.

T1059.003
Windows Command Shell
MalwareZeus Panda

Zeus Panda can launch an interface where it can execute several commands on the victim’s PC.

T1070.004
File Deletion
MalwareZeus Panda

Zeus Panda has a command to delete a file. It also can uninstall scripts and delete files to cover its track.

T1071.001
Web Protocols
MalwareZeus Panda

Zeus Panda uses HTTP for C2 communications.

T1082
System Information Discovery
MalwareZeus Panda

Zeus Panda collects the OS version, system architecture, computer name, product ID, install date, and information on the keyboard mapping to determine the language used on the system.

T1083
File and Directory Discovery
MalwareZeus Panda

Zeus Panda searches for specific directories on the victim’s machine.

T1105
Ingress Tool Transfer
MalwareZeus Panda

Zeus Panda can download additional malware plug-in modules and execute them on the victim’s machine.

T1112
Modify Registry
MalwareZeus Panda

Zeus Panda modifies several Registry keys under HKCU\Software\Microsoft\Internet Explorer\ PhishingFilter\ to disable phishing filters.

T1113
Screen Capture
MalwareZeus Panda

Zeus Panda can take screenshots of the victim’s machine.

T1115
Clipboard Data
MalwareZeus Panda

Zeus Panda can hook GetClipboardData function to watch for clipboard pastes to collect.

T1124
System Time Discovery
MalwareZeus Panda

Zeus Panda collects the current system time (UTC) and sends it back to the C2 server.

T1140
Deobfuscate/Decode Files or Information
MalwareZeus Panda

Zeus Panda decrypts strings in the code during the execution process.

T1518.001
Security Software Discovery
MalwareZeus Panda

Zeus Panda checks to see if anti-virus, anti-spyware, or firewall products are installed in the victim’s environment.

T1547.001
Registry Run Keys / Startup Folder
MalwareZeus Panda

Zeus Panda adds persistence by creating Registry Run keys.

T1614.001
System Language Discovery
MalwareZeus Panda

Zeus Panda queries the system's keyboard mapping to determine the language used on the system. It will terminate execution if it detects LANG_RUSSIAN, LANG_BELARUSIAN, LANG_KAZAK, or LANG_UKRAINIAN.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.