ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0366×

16 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareWannaCry

WannaCry will attempt to determine the local network segment it is a part of.

T1018
Remote System Discovery
MalwareWannaCry

WannaCry scans its local network segment for remote systems to try to exploit and copy itself to.

T1047
Windows Management Instrumentation
MalwareWannaCry

WannaCry utilizes wmic to delete shadow copies.

T1083
File and Directory Discovery
MalwareWannaCry

WannaCry searches for variety of user files by file extension before encrypting them using RSA and AES, including Office, PDF, image, audio, video, source code, archive/compression format, and key and certificate files.

T1090.003
Multi-hop Proxy
MalwareWannaCry

WannaCry uses Tor for command and control traffic.

T1120
Peripheral Device Discovery
MalwareWannaCry

WannaCry contains a thread that will attempt to scan for new attached drives every few seconds. If one is identified, it will encrypt the files on the attached device.

T1210
Exploitation of Remote Services
MalwareWannaCry

WannaCry uses an exploit in SMBv1 to spread itself to other remote systems on a network.

T1222.001
Windows Permissions
MalwareWannaCry

WannaCry uses attrib +h and icacls . /grant Everyone:F /T /C /Q to make some of its files hidden and grant all users full access controls.

T1486
Data Encrypted for Impact
MalwareWannaCry

WannaCry encrypts user files and demands that a ransom be paid in Bitcoin to decrypt those files.

T1489
Service Stop
MalwareWannaCry

WannaCry attempts to kill processes associated with Exchange, Microsoft SQL Server, and MySQL to make it possible to encrypt their data stores.

T1490
Inhibit System Recovery
MalwareWannaCry

WannaCry uses vssadmin, wbadmin, bcdedit, and wmic to delete and disable operating system recovery features.

T1543.003
Windows Service
MalwareWannaCry

WannaCry creates the service "mssecsvc2.0" with the display name "Microsoft Security Center (2.0) Service."

T1563.002
RDP Hijacking
MalwareWannaCry

WannaCry enumerates current remote desktop sessions and tries to execute the malware on each session.

T1564.001
Hidden Files and Directories
MalwareWannaCry

WannaCry uses attrib +h to make some of its files hidden.

T1570
Lateral Tool Transfer
MalwareWannaCry

WannaCry attempts to copy itself to remote computers after gaining access via an SMB exploit.

T1573.002
Asymmetric Cryptography
MalwareWannaCry

WannaCry uses Tor for command and control traffic and routes a custom cryptographic protocol over the Tor circuit.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.