Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareCarbon | Carbon enumerates values in the Registry. |
| T1016 System Network Configuration Discovery |
MalwareCarbon | Carbon can collect the IP address of the victims and other computers on the network using the commands: |
| T1018 Remote System Discovery |
MalwareCarbon | Carbon uses the |
| T1027 Obfuscated Files or Information |
MalwareCarbon | Carbon encrypts configuration files and tasks for the malware to complete using CAST-128 algorithm. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCarbon | Carbon uses HTTP to send data to the C2 server. |
| T1049 System Network Connections Discovery |
MalwareCarbon | Carbon uses the |
| T1053.005 Scheduled Task |
MalwareCarbon | Carbon creates several tasks for later execution to continue persistence on the victim’s machine. |
| T1055.001 Dynamic-link Library Injection |
MalwareCarbon | Carbon has a command to inject code into a process. |
| T1057 Process Discovery |
MalwareCarbon | Carbon can list the processes on the victim’s machine. |
| T1069 Permission Groups Discovery |
MalwareCarbon | Carbon uses the |
| T1071.001 Web Protocols |
MalwareCarbon | Carbon can use HTTP in C2 communications. |
| T1074.001 Local Data Staging |
MalwareCarbon | Carbon creates a base directory that contains the files and folders that are collected. |
| T1095 Non-Application Layer Protocol |
MalwareCarbon | Carbon uses TCP and UDP for C2. |
| T1102 Web Service |
MalwareCarbon | Carbon can use Pastebin to receive C2 commands. |
| T1124 System Time Discovery |
MalwareCarbon | Carbon uses the command |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCarbon | Carbon decrypts task and configuration files for execution. |
| T1543.003 Windows Service |
MalwareCarbon | Carbon establishes persistence by creating a service and naming it based off the operating system version running on the current machine. |
| T1573.002 Asymmetric Cryptography |
MalwareCarbon | Carbon has used RSA encryption for C2 communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.