Real-world descriptions of how a group, tool or campaign used a technique.
36 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareAstaroth | Astaroth collects the external IP address from the system. |
| T1027.002 Software Packing |
MalwareAstaroth | Astaroth uses a software packer called Pe123\RPolyCryptor. |
| T1027.010 Command Obfuscation |
MalwareAstaroth | Astaroth has obfuscated and randomized parts of the JScript code it is initiating. |
| T1027.013 Encrypted/Encoded File |
MalwareAstaroth | Astaroth has used an XOR-based algorithm to encrypt payloads twice with different keys. |
| T1041 Exfiltration Over C2 Channel |
MalwareAstaroth | Astaroth exfiltrates collected information from its r1.log file to the external C2 server. |
| T1047 Windows Management Instrumentation |
MalwareAstaroth | Astaroth uses WMIC to execute payloads. |
| T1055.012 Process Hollowing |
MalwareAstaroth | Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code. |
| T1056.001 Keylogging |
MalwareAstaroth | Astaroth logs keystrokes from the victim's machine. |
| T1057 Process Discovery |
MalwareAstaroth | Astaroth searches for different processes on the system. |
| T1059.003 Windows Command Shell |
MalwareAstaroth | Astaroth spawns a CMD process to execute commands. |
| T1059.005 Visual Basic |
MalwareAstaroth | Astaroth has used malicious VBS e-mail attachments for execution. |
| T1059.007 JavaScript |
MalwareAstaroth | Astaroth uses JavaScript to perform its core functionalities. |
| T1074.001 Local Data Staging |
MalwareAstaroth | Astaroth collects data in a plaintext file named r1.log before exfiltration. |
| T1082 System Information Discovery |
MalwareAstaroth | Astaroth collects the machine name and keyboard language from the system. |
| T1102.001 Dead Drop Resolver |
MalwareAstaroth | Astaroth can store C2 information on cloud hosting services such as AWS and CloudFlare and websites like YouTube and Facebook. |
| T1105 Ingress Tool Transfer |
MalwareAstaroth | Astaroth uses certutil and BITSAdmin to download additional malware. |
| T1115 Clipboard Data |
MalwareAstaroth | Astaroth collects information from the clipboard by using the OpenClipboard() and GetClipboardData() libraries. |
| T1124 System Time Discovery |
MalwareAstaroth | Astaroth collects the timestamp from the infected machine. |
| T1129 Shared Modules |
MalwareAstaroth | Astaroth uses the LoadLibraryExW() function to load additional modules. |
| T1132.001 Standard Encoding |
MalwareAstaroth | Astaroth encodes data using Base64 before sending it to the C2 server. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAstaroth | Astaroth uses a fromCharCode() deobfuscation method to avoid explicitly writing execution commands and to hide its code. |
| T1204.002 Malicious File |
MalwareAstaroth | Astaroth has used malicious files including VBS, LNK, and HTML for execution. |
| T1218.001 Compiled HTML File |
MalwareAstaroth | Astaroth uses ActiveX objects for file execution and manipulation. |
| T1218.010 Regsvr32 |
MalwareAstaroth | Astaroth can be loaded through regsvr32.exe. |
| T1220 XSL Script Processing |
MalwareAstaroth | Astaroth executes embedded JScript or VBScript in an XSL stylesheet located on a remote domain. |
| T1497.001 System Checks |
MalwareAstaroth | Astaroth can check for Windows product ID's used by sandboxes and usernames and disk serial numbers associated with analyst environments. |
| T1518.001 Security Software Discovery |
MalwareAstaroth | Astaroth checks for the presence of Avast antivirus in the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAstaroth | Astaroth creates a startup item for persistence. |
| T1547.009 Shortcut Modification |
MalwareAstaroth | Astaroth's initial payload is a malicious .LNK file. |
| T1552 Unsecured Credentials |
MalwareAstaroth | Astaroth uses an external software known as NetPass to recover passwords. |
| T1555 Credentials from Password Stores |
MalwareAstaroth | Astaroth uses an external software known as NetPass to recover passwords. |
| T1564.003 Hidden Window |
MalwareAstaroth | Astaroth loads its module with the XSL script parameter |
| T1564.004 NTFS File Attributes |
MalwareAstaroth | Astaroth can abuse alternate data streams (ADS) to store content for malicious payloads. |
| T1566.001 Spearphishing Attachment |
MalwareAstaroth | Astaroth has been delivered via malicious e-mail attachments. |
| T1568.002 Domain Generation Algorithms |
MalwareAstaroth | Astaroth has used a DGA in C2 communications. |
| T1574.001 DLL |
MalwareAstaroth | Astaroth can launch itself via DLL Search Order Hijacking. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.