ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0353×

16 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareNOKKI

NOKKI can gather information on the victim IP address.

T1027
Obfuscated Files or Information
MalwareNOKKI

NOKKI uses Base64 encoding for strings.

T1033
System Owner/User Discovery
MalwareNOKKI

NOKKI can collect the username from the victim’s machine.

T1036.005
Match Legitimate Resource Name or Location
MalwareNOKKI

NOKKI is written to %LOCALAPPDATA%\MicroSoft Updatea\svServiceUpdate.exe prior being executed in a new process in an apparent attempt to masquerade as a legitimate folder and file.

T1056.004
Credential API Hooking
MalwareNOKKI

NOKKI uses the Windows call SetWindowsHookEx and begins injecting it into every GUI process running on the victim's machine.

T1070.004
File Deletion
MalwareNOKKI

NOKKI can delete files to cover tracks.

T1071.001
Web Protocols
MalwareNOKKI

NOKKI has used HTTP for C2 communications.

T1071.002
File Transfer Protocols
MalwareNOKKI

NOKKI has used FTP for C2 communications.

T1074.001
Local Data Staging
MalwareNOKKI

NOKKI can collect data from the victim and stage it in LOCALAPPDATA%\MicroSoft Updatea\uplog.tmp.

T1082
System Information Discovery
MalwareNOKKI

NOKKI can gather information on the operating system on the victim’s machine.

T1105
Ingress Tool Transfer
MalwareNOKKI

NOKKI has downloaded a remote module for execution.

T1124
System Time Discovery
MalwareNOKKI

NOKKI can collect the current timestamp of the victim's machine.

T1140
Deobfuscate/Decode Files or Information
MalwareNOKKI

NOKKI uses a unique, custom de-obfuscation technique.

T1218.011
Rundll32
MalwareNOKKI

NOKKI has used rundll32 for execution.

T1547.001
Registry Run Keys / Startup Folder
MalwareNOKKI

NOKKI has established persistence by writing the payload to the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run.

T1680
Local Storage Discovery
MalwareNOKKI

NOKKI can gather information on drives on the victim’s machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.