ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0354×

20 examples

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareDenis

Denis queries the Registry for keys and values.

T1016
System Network Configuration Discovery
MalwareDenis

Denis uses ipconfig to gather the IP address from the system.

T1027
Obfuscated Files or Information
MalwareDenis

Denis obfuscates its code and encrypts the API names.

T1027.010
Command Obfuscation
MalwareDenis

Denis has encoded its PowerShell commands in Base64.

T1033
System Owner/User Discovery
MalwareDenis

Denis enumerates and collects the username from the victim’s machine.

T1055.012
Process Hollowing
MalwareDenis

Denis performed process hollowing through the API calls CreateRemoteThread, ResumeThread, and Wow64SetThreadContext.

T1059.001
PowerShell
MalwareDenis

Denis has a version written in PowerShell.

T1059.003
Windows Command Shell
MalwareDenis

Denis can launch a remote shell to execute arbitrary commands on the victim’s machine.

T1070.004
File Deletion
MalwareDenis

Denis has a command to delete files from the victim’s machine.

T1071.004
DNS
MalwareDenis

Denis has used DNS tunneling for C2 communications.

T1082
System Information Discovery
MalwareDenis

Denis collects OS information and the computer name from the victim’s machine.

T1083
File and Directory Discovery
MalwareDenis

Denis has several commands to search directories for files.

T1105
Ingress Tool Transfer
MalwareDenis

Denis deploys additional backdoors and hacking tools to the system.

T1106
Native API
MalwareDenis

Denis used the IsDebuggerPresent, OutputDebugString, and SetLastError APIs to avoid debugging. Denis used GetProcAddress and LoadLibrary to dynamically resolve APIs. Denis also used the Wow64SetThreadContext API as part of a process hollowing process.

T1132.001
Standard Encoding
MalwareDenis

Denis encodes the data sent to the server in Base64.

T1140
Deobfuscate/Decode Files or Information
MalwareDenis

Denis will decrypt important strings used for C&C communication.

T1497.001
System Checks
MalwareDenis

Denis ran multiple system checks, looking for processor and register characteristics, to evade emulation and analysis.

T1560.002
Archive via Library
MalwareDenis

Denis compressed collected data using zlib.

T1574
Hijack Execution Flow
MalwareDenis

Denis replaces the nonexistent Windows DLL "msfte.dll" with its own malicious version, which is loaded by the SearchIndexer.exe and SearchProtocolHost.exe.

T1574.001
DLL
MalwareDenis

Denis exploits a security vulnerability to load a fake DLL and execute its code.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.