ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0367×

47 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
MalwareEmotet

Emotet has been observed dropping and executing password grabber modules including Mimikatz.

T1016.002
Wi-Fi Discovery
MalwareEmotet

Emotet can extract names of all locally reachable Wi-Fi networks and then perform a brute-force attack to spread to new networks.

T1021.002
SMB/Windows Admin Shares
MalwareEmotet

Emotet has leveraged the Admin$, C$, and IPC$ shares for lateral movement.

T1027.001
Binary Padding
MalwareEmotet

Emotet inflates malicious files and malware as an evasion technique.

T1027.002
Software Packing
MalwareEmotet

Emotet has used custom packers to protect its payloads.

T1027.009
Embedded Payloads
MalwareEmotet

Emotet has dropped an embedded executable at `%Temp%\setup.exe`. Additionally, Emotet may embed entire code into other files.

T1027.010
Command Obfuscation
MalwareEmotet

Emotet has obfuscated macros within malicious documents to hide the URLs hosting the malware, CMD.exe arguments, and PowerShell scripts.

T1027.013
Encrypted/Encoded File
MalwareEmotet

Emotet uses obfuscated URLs to download a ZIP file.

T1033
System Owner/User Discovery
MalwareEmotet

Emotet has enumerated all users connected to network shares.

T1036.004
Masquerade Task or Service
MalwareEmotet

Emotet has installed itself as a new service with the service name `Windows Defender System Service` and display name `WinDefService`.

T1040
Network Sniffing
MalwareEmotet

Emotet has been observed to hook network APIs to monitor network traffic.

T1041
Exfiltration Over C2 Channel
MalwareEmotet

Emotet has exfiltrated data over its C2 channel.

T1047
Windows Management Instrumentation
MalwareEmotet

Emotet has used WMI to execute powershell.exe.

T1053.005
Scheduled Task
MalwareEmotet

Emotet has maintained persistence through a scheduled task, e.g. though a .dll file in the Registry.

T1055.001
Dynamic-link Library Injection
MalwareEmotet

Emotet has been observed injecting in to Explorer.exe and other processes.

T1055.012
Process Hollowing
MalwareEmotet

Emotet uses a copy of `certutil.exe` stored in a temporary directory for process hollowing, starting the program in a suspended state before loading malicious code.

T1057
Process Discovery
MalwareEmotet

Emotet has been observed enumerating local processes.

T1059.001
PowerShell
MalwareEmotet

Emotet has used Powershell to retrieve the malicious payload and download additional resources like Mimikatz.

T1059.003
Windows Command Shell
MalwareEmotet

Emotet has used cmd.exe to run a PowerShell script.

T1059.005
Visual Basic
MalwareEmotet

Emotet has sent Microsoft Word documents with embedded macros that will invoke scripts to download additional payloads.

T1071.001
Web Protocols
MalwareEmotet

Emotet has used HTTP for command and control.

T1078.003
Local Accounts
MalwareEmotet

Emotet can brute force a local admin password, then use it to facilitate lateral movement.

T1087.003
Email Account
MalwareEmotet

Emotet has been observed leveraging a module that can scrape email addresses from Outlook.

T1105
Ingress Tool Transfer
MalwareEmotet

Emotet can download follow-on payloads and items via malicious `url` parameters in obfuscated PowerShell code.

T1106
Native API
MalwareEmotet

Emotet has used `CreateProcess` to create a new process to run its executable and `WNetEnumResourceW` to enumerate non-hidden shares.

T1110.001
Password Guessing
MalwareEmotet

Emotet has been observed using a hard coded list of passwords to brute force user accounts.

T1114
Email Collection
MalwareEmotet

Emotet has been observed leveraging a module that can scrape email addresses from Outlook.

T1114.001
Local Email Collection
MalwareEmotet

Emotet has been observed leveraging a module that scrapes email data from Outlook.

T1132.001
Standard Encoding
MalwareEmotet

Emotet has used Google’s Protobufs to serialize data sent to and from the C2 server. Additionally, Emotet has used Base64 to encode data before sending to the C2 server.

T1134.001
Token Impersonation/Theft
MalwareEmotet

Emotet has the ability to duplicate the user’s token. For example, Emotet may use a variant of Google’s ProtoBuf to send messages that specify how code will be executed.

T1135
Network Share Discovery
MalwareEmotet

Emotet has enumerated non-hidden network shares using `WNetEnumResourceW`.

T1140
Deobfuscate/Decode Files or Information
MalwareEmotet

Emotet has used a self-extracting RAR file to deliver modules to victims. Emotet has also extracted embedded executables from files using hard-coded buffer offsets.

T1204.001
Malicious Link
MalwareEmotet

Emotet has relied upon users clicking on a malicious link delivered through spearphishing.

T1204.002
Malicious File
MalwareEmotet

Emotet has relied upon users clicking on a malicious attachment delivered through spearphishing.

T1210
Exploitation of Remote Services
MalwareEmotet

Emotet has been seen exploiting SMB via a vulnerability exploit like EternalBlue (MS17-010) to achieve lateral movement and propagation.

T1218.010
Regsvr32
MalwareEmotet

Emotet uses RegSvr32 to execute the DLL payload.

T1543.003
Windows Service
MalwareEmotet

Emotet has been observed creating new services to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareEmotet

Emotet has been observed adding the downloaded payload to the HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run key to maintain persistence.

T1552.001
Credentials In Files
MalwareEmotet

Emotet has been observed leveraging a module that retrieves passwords stored on a system for the current logged-on user.

T1555.003
Credentials from Web Browsers
MalwareEmotet

Emotet has been observed dropping browser password grabber modules.

T1566.001
Spearphishing Attachment
MalwareEmotet

Emotet has been delivered by phishing emails containing attachments.

T1566.002
Spearphishing Link
MalwareEmotet

Emotet has been delivered by phishing emails containing links.

T1570
Lateral Tool Transfer
MalwareEmotet

Emotet has copied itself to remote systems using the `service.exe` filename.

T1571
Non-Standard Port
MalwareEmotet

Emotet has used HTTP over ports such as 20, 22, 443, 7080, and 50000, in addition to using ports commonly associated with HTTP/S.

T1573
Encrypted Channel
MalwareEmotet

Emotet has encrypted data before sending to the C2 server.

T1573.001
Symmetric Cryptography
MalwareEmotet

Emotet is known to use RSA keys for encrypting C2 traffic.

T1620
Reflective Code Loading
MalwareEmotet

Emotet has reflectively loaded payloads into memory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.