ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0342×

17 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
MalwareGreyEnergy

GreyEnergy has a module for Mimikatz to collect Windows credentials from the victim’s machine.

T1007
System Service Discovery
MalwareGreyEnergy

GreyEnergy enumerates all Windows services.

T1027.002
Software Packing
MalwareGreyEnergy

GreyEnergy is packed for obfuscation.

T1027.013
Encrypted/Encoded File
MalwareGreyEnergy

GreyEnergy encrypts its configuration files with AES-256 and also encrypts its strings.

T1055.002
Portable Executable Injection
MalwareGreyEnergy

GreyEnergy has a module to inject a PE binary into a remote process.

T1056.001
Keylogging
MalwareGreyEnergy

GreyEnergy has a module to harvest pressed keystrokes.

T1059.003
Windows Command Shell
MalwareGreyEnergy

GreyEnergy uses cmd.exe to execute itself in-memory.

T1070.004
File Deletion
MalwareGreyEnergy

GreyEnergy can securely delete a file by hooking into the DeleteFileA and DeleteFileW functions in the Windows API.

T1071.001
Web Protocols
MalwareGreyEnergy

GreyEnergy uses HTTP and HTTPS for C2 communications.

T1090.003
Multi-hop Proxy
MalwareGreyEnergy

GreyEnergy has used Tor relays for Command and Control servers.

T1105
Ingress Tool Transfer
MalwareGreyEnergy

GreyEnergy can download additional modules and payloads.

T1112
Modify Registry
MalwareGreyEnergy

GreyEnergy modifies conditions in the Registry and adds keys.

T1218.011
Rundll32
MalwareGreyEnergy

GreyEnergy uses PsExec locally in order to execute rundll32.exe at the highest privileges (NTAUTHORITY\SYSTEM).

T1543.003
Windows Service
MalwareGreyEnergy

GreyEnergy chooses a service, drops a DLL file, and writes it to that serviceDLL Registry key.

T1553.002
Code Signing
MalwareGreyEnergy

GreyEnergy digitally signs the malware with a code-signing certificate.

T1573.001
Symmetric Cryptography
MalwareGreyEnergy

GreyEnergy encrypts communications using AES256.

T1573.002
Asymmetric Cryptography
MalwareGreyEnergy

GreyEnergy encrypts communications using RSA-2048.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.