Real-world descriptions of how a group, tool or campaign used a technique.
22 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
MalwareFlawedAmmyy | FlawedAmmyy may obfuscate portions of the initial C2 handshake. |
| T1005 Data from Local System |
MalwareFlawedAmmyy | FlawedAmmyy has collected information and files from a compromised machine. |
| T1033 System Owner/User Discovery |
MalwareFlawedAmmyy | FlawedAmmyy enumerates the current user during the initial infection. |
| T1041 Exfiltration Over C2 Channel |
MalwareFlawedAmmyy | FlawedAmmyy has sent data collected from a compromised host to its C2 servers. |
| T1047 Windows Management Instrumentation |
MalwareFlawedAmmyy | FlawedAmmyy leverages WMI to enumerate anti-virus on the victim. |
| T1056 Input Capture |
MalwareFlawedAmmyy | FlawedAmmyy can collect mouse events. |
| T1056.001 Keylogging |
MalwareFlawedAmmyy | FlawedAmmyy can collect keyboard events. |
| T1059.001 PowerShell |
MalwareFlawedAmmyy | FlawedAmmyy has used PowerShell to execute commands. |
| T1059.003 Windows Command Shell |
MalwareFlawedAmmyy | FlawedAmmyy has used `cmd` to execute commands on a compromised host. |
| T1069.001 Local Groups |
MalwareFlawedAmmyy | FlawedAmmyy enumerates the privilege level of the victim during the initial infection. |
| T1070.004 File Deletion |
MalwareFlawedAmmyy | FlawedAmmyy can execute batch scripts to delete files. |
| T1071.001 Web Protocols |
MalwareFlawedAmmyy | FlawedAmmyy has used HTTP for C2. |
| T1082 System Information Discovery |
MalwareFlawedAmmyy | FlawedAmmyy can collect the victim's operating system and computer name during the initial infection. |
| T1105 Ingress Tool Transfer |
MalwareFlawedAmmyy | FlawedAmmyy can transfer files from C2. |
| T1113 Screen Capture |
MalwareFlawedAmmyy | FlawedAmmyy can capture screenshots. |
| T1115 Clipboard Data |
MalwareFlawedAmmyy | FlawedAmmyy can collect clipboard data. |
| T1120 Peripheral Device Discovery |
MalwareFlawedAmmyy | FlawedAmmyy will attempt to detect if a usable smart card is current inserted into a card reader. |
| T1218.007 Msiexec |
MalwareFlawedAmmyy | FlawedAmmyy has been installed via `msiexec.exe`. |
| T1218.011 Rundll32 |
MalwareFlawedAmmyy | FlawedAmmyy has used `rundll32` for execution. |
| T1518.001 Security Software Discovery |
MalwareFlawedAmmyy | FlawedAmmyy will attempt to detect anti-virus products during the initial infection. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFlawedAmmyy | FlawedAmmyy has established persistence via the `HKCU\SOFTWARE\microsoft\windows\currentversion\run` registry key. |
| T1573.001 Symmetric Cryptography |
MalwareFlawedAmmyy | FlawedAmmyy has used SEAL encryption during the initial C2 handshake. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.