ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0335×

18 examples

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareCarbon

Carbon enumerates values in the Registry.

T1016
System Network Configuration Discovery
MalwareCarbon

Carbon can collect the IP address of the victims and other computers on the network using the commands: ipconfig -all nbtstat -n, and nbtstat -s.

T1018
Remote System Discovery
MalwareCarbon

Carbon uses the net view command.

T1027
Obfuscated Files or Information
MalwareCarbon

Carbon encrypts configuration files and tasks for the malware to complete using CAST-128 algorithm.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareCarbon

Carbon uses HTTP to send data to the C2 server.

T1049
System Network Connections Discovery
MalwareCarbon

Carbon uses the netstat -r and netstat -an commands.

T1053.005
Scheduled Task
MalwareCarbon

Carbon creates several tasks for later execution to continue persistence on the victim’s machine.

T1055.001
Dynamic-link Library Injection
MalwareCarbon

Carbon has a command to inject code into a process.

T1057
Process Discovery
MalwareCarbon

Carbon can list the processes on the victim’s machine.

T1069
Permission Groups Discovery
MalwareCarbon

Carbon uses the net group command.

T1071.001
Web Protocols
MalwareCarbon

Carbon can use HTTP in C2 communications.

T1074.001
Local Data Staging
MalwareCarbon

Carbon creates a base directory that contains the files and folders that are collected.

T1095
Non-Application Layer Protocol
MalwareCarbon

Carbon uses TCP and UDP for C2.

T1102
Web Service
MalwareCarbon

Carbon can use Pastebin to receive C2 commands.

T1124
System Time Discovery
MalwareCarbon

Carbon uses the command net time \\127.0.0.1 to get information the system’s time.

T1140
Deobfuscate/Decode Files or Information
MalwareCarbon

Carbon decrypts task and configuration files for execution.

T1543.003
Windows Service
MalwareCarbon

Carbon establishes persistence by creating a service and naming it based off the operating system version running on the current machine.

T1573.002
Asymmetric Cryptography
MalwareCarbon

Carbon has used RSA encryption for C2 communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.