ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0376×

21 examples

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
MalwareHOPLIGHT

HOPLIGHT has the capability to harvest credentials and passwords from the SAM database.

T1008
Fallback Channels
MalwareHOPLIGHT

HOPLIGHT has multiple C2 channels in place in case one fails.

T1012
Query Registry
MalwareHOPLIGHT

A variant of HOPLIGHT hooks lsass.exe, and lsass.exe then checks the Registry for the data value 'rdpproto' under the key SYSTEM\CurrentControlSet\Control\Lsa Name.

T1041
Exfiltration Over C2 Channel
MalwareHOPLIGHT

HOPLIGHT has used its C2 channel to exfiltrate data.

T1047
Windows Management Instrumentation
MalwareHOPLIGHT

HOPLIGHT has used WMI to recompile the Managed Object Format (MOF) files in the WMI repository.

T1055
Process Injection
MalwareHOPLIGHT

HOPLIGHT has injected into running processes.

T1059.003
Windows Command Shell
MalwareHOPLIGHT

HOPLIGHT can launch cmd.exe to execute commands on the system.

T1082
System Information Discovery
MalwareHOPLIGHT

HOPLIGHT has been observed collecting victim machine information like OS version.

T1083
File and Directory Discovery
MalwareHOPLIGHT

HOPLIGHT has been observed enumerating system drives and partitions.

T1090
Proxy
MalwareHOPLIGHT

HOPLIGHT has multiple proxy options that mask traffic between the malware and the remote operators.

T1105
Ingress Tool Transfer
MalwareHOPLIGHT

HOPLIGHT has the ability to connect to a remote host in order to upload and download files.

T1112
Modify Registry
MalwareHOPLIGHT

HOPLIGHT has modified Managed Object Format (MOF) files within the Registry to run specific commands and create persistence on the system.

T1124
System Time Discovery
MalwareHOPLIGHT

HOPLIGHT has been observed collecting system time from victim machines.

T1132.001
Standard Encoding
MalwareHOPLIGHT

HOPLIGHT has utilized Zlib compression to obfuscate the communications payload.

T1546.003
Windows Management Instrumentation Event Subscription
MalwareHOPLIGHT

HOPLIGHT can use WMI event subscriptions to create persistence.

T1550.002
Pass the Hash
MalwareHOPLIGHT

HOPLIGHT has been observed loading several APIs associated with Pass the Hash.

T1569.002
Service Execution
MalwareHOPLIGHT

HOPLIGHT has used svchost.exe to execute a malicious DLL .

T1571
Non-Standard Port
MalwareHOPLIGHT

HOPLIGHT has connected outbound over TCP port 443 with a FakeTLS method.

T1652
Device Driver Discovery
MalwareHOPLIGHT

HOPLIGHT can enumerate device drivers located in the registry at `HKLM\Software\WBEM\WDM`.

T1680
Local Storage Discovery
MalwareHOPLIGHT

HOPLIGHT has been observed collecting victim machine volume information.

T1686
Disable or Modify System Firewall
MalwareHOPLIGHT

HOPLIGHT has modified the firewall using netsh.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.