ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0356×

40 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareKONNI

KONNI has stored collected information and discovered processes in a tmp file.

T1016
System Network Configuration Discovery
MalwareKONNI

KONNI can collect the IP address from the victim’s machine.

T1027.002
Software Packing
MalwareKONNI

KONNI has been packed for obfuscation.

T1027.013
Encrypted/Encoded File
MalwareKONNI

KONNI is heavily obfuscated and includes encrypted configuration files.

T1033
System Owner/User Discovery
MalwareKONNI

KONNI can collect the username from the victim’s machine.

T1036.004
Masquerade Task or Service
MalwareKONNI

KONNI has pretended to be the xmlProv Network Provisioning service.

T1036.005
Match Legitimate Resource Name or Location
MalwareKONNI

KONNI has created a shortcut called "Anti virus service.lnk" in an apparent attempt to masquerade as a legitimate file.

T1041
Exfiltration Over C2 Channel
MalwareKONNI

KONNI has sent data and files to its C2 server.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareKONNI

KONNI has used FTP to exfiltrate reconnaissance data out.

T1049
System Network Connections Discovery
MalwareKONNI

KONNI has used net session on the victim's machine.

T1056.001
Keylogging
MalwareKONNI

KONNI has the capability to perform keylogging.

T1057
Process Discovery
MalwareKONNI

KONNI has used the command cmd /c tasklist to get a snapshot of the current processes on the target machine.

T1059.001
PowerShell
MalwareKONNI

KONNI used PowerShell to download and execute a specific 64-bit version of the malware.

T1059.003
Windows Command Shell
MalwareKONNI

KONNI has used cmd.exe to execute arbitrary commands on the infected host across different stages of the infection chain.

T1059.007
JavaScript
MalwareKONNI

KONNI has executed malicious JavaScript code.

T1070.004
File Deletion
MalwareKONNI

KONNI can delete files.

T1071.001
Web Protocols
MalwareKONNI

KONNI has used HTTP POST for C2.

T1082
System Information Discovery
MalwareKONNI

KONNI can gather the OS version, architecture information, hostname, and RAM size information from the victim’s machine and has used cmd /c systeminfo command to get a snapshot of the current system state of the target machine.

T1083
File and Directory Discovery
MalwareKONNI

A version of KONNI searches for filenames created with a previous version of the malware, suggesting different versions targeted the same victims and the versions may work together.

T1105
Ingress Tool Transfer
MalwareKONNI

KONNI can download files and execute them on the victim’s machine.

T1106
Native API
MalwareKONNI

KONNI has hardcoded API calls within its functions to use on the victim's machine.

T1112
Modify Registry
MalwareKONNI

KONNI has modified registry keys of ComSysApp, Svchost, and xmlProv on the machine to gain persistence.

T1113
Screen Capture
MalwareKONNI

KONNI can take screenshots of the victim’s machine.

T1115
Clipboard Data
MalwareKONNI

KONNI had a feature to steal data from the clipboard.

T1132.001
Standard Encoding
MalwareKONNI

KONNI has used a custom base64 key to encode stolen data before exfiltration.

T1134.002
Create Process with Token
MalwareKONNI

KONNI has duplicated the token of a high integrity process to spawn an instance of cmd.exe under an impersonated user.

T1134.004
Parent PID Spoofing
MalwareKONNI

KONNI has used parent PID spoofing to spawn a new `cmd` process using `CreateProcessW` and a handle to `Taskmgr.exe`.

T1140
Deobfuscate/Decode Files or Information
MalwareKONNI

KONNI has used certutil to download and decode base64 encoded strings and has also devoted a custom section to performing all the components of the deobfuscation process.

T1204.002
Malicious File
MalwareKONNI

KONNI has relied on a victim to enable malicious macros within an attachment delivered via email.

T1218.011
Rundll32
MalwareKONNI

KONNI has used Rundll32 to execute its loader for privilege escalation purposes.

T1543.003
Windows Service
MalwareKONNI

KONNI has registered itself as a service using its export function.

T1546.015
Component Object Model Hijacking
MalwareKONNI

KONNI has modified ComSysApp service to load the malicious DLL payload.

T1547.001
Registry Run Keys / Startup Folder
MalwareKONNI

A version of KONNI has dropped a Windows shortcut into the Startup folder to establish persistence.

T1547.009
Shortcut Modification
MalwareKONNI

A version of KONNI drops a Windows shortcut on the victim’s machine to establish persistence.

T1548.002
Bypass User Account Control
MalwareKONNI

KONNI has bypassed UAC by performing token impersonation as well as an RPC-based method, this included bypassing UAC set to “AlwaysNotify".

T1555.003
Credentials from Web Browsers
MalwareKONNI

KONNI can steal profiles (containing credential information) from Firefox, Chrome, and Opera.

T1560
Archive Collected Data
MalwareKONNI

KONNI has encrypted data and files prior to exfiltration.

T1566.001
Spearphishing Attachment
MalwareKONNI

KONNI has been delivered via spearphishing campaigns through a malicious Word document.

T1573.001
Symmetric Cryptography
MalwareKONNI

KONNI has used AES to encrypt C2 traffic.

T1680
Local Storage Discovery
MalwareKONNI

KONNI can gather information on connected drives and disk space from the victim’s machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.