ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0381×

22 examples

TechniqueUsed byProcedure example
T1001
Data Obfuscation
MalwareFlawedAmmyy

FlawedAmmyy may obfuscate portions of the initial C2 handshake.

T1005
Data from Local System
MalwareFlawedAmmyy

FlawedAmmyy has collected information and files from a compromised machine.

T1033
System Owner/User Discovery
MalwareFlawedAmmyy

FlawedAmmyy enumerates the current user during the initial infection.

T1041
Exfiltration Over C2 Channel
MalwareFlawedAmmyy

FlawedAmmyy has sent data collected from a compromised host to its C2 servers.

T1047
Windows Management Instrumentation
MalwareFlawedAmmyy

FlawedAmmyy leverages WMI to enumerate anti-virus on the victim.

T1056
Input Capture
MalwareFlawedAmmyy

FlawedAmmyy can collect mouse events.

T1056.001
Keylogging
MalwareFlawedAmmyy

FlawedAmmyy can collect keyboard events.

T1059.001
PowerShell
MalwareFlawedAmmyy

FlawedAmmyy has used PowerShell to execute commands.

T1059.003
Windows Command Shell
MalwareFlawedAmmyy

FlawedAmmyy has used `cmd` to execute commands on a compromised host.

T1069.001
Local Groups
MalwareFlawedAmmyy

FlawedAmmyy enumerates the privilege level of the victim during the initial infection.

T1070.004
File Deletion
MalwareFlawedAmmyy

FlawedAmmyy can execute batch scripts to delete files.

T1071.001
Web Protocols
MalwareFlawedAmmyy

FlawedAmmyy has used HTTP for C2.

T1082
System Information Discovery
MalwareFlawedAmmyy

FlawedAmmyy can collect the victim's operating system and computer name during the initial infection.

T1105
Ingress Tool Transfer
MalwareFlawedAmmyy

FlawedAmmyy can transfer files from C2.

T1113
Screen Capture
MalwareFlawedAmmyy

FlawedAmmyy can capture screenshots.

T1115
Clipboard Data
MalwareFlawedAmmyy

FlawedAmmyy can collect clipboard data.

T1120
Peripheral Device Discovery
MalwareFlawedAmmyy

FlawedAmmyy will attempt to detect if a usable smart card is current inserted into a card reader.

T1218.007
Msiexec
MalwareFlawedAmmyy

FlawedAmmyy has been installed via `msiexec.exe`.

T1218.011
Rundll32
MalwareFlawedAmmyy

FlawedAmmyy has used `rundll32` for execution.

T1518.001
Security Software Discovery
MalwareFlawedAmmyy

FlawedAmmyy will attempt to detect anti-virus products during the initial infection.

T1547.001
Registry Run Keys / Startup Folder
MalwareFlawedAmmyy

FlawedAmmyy has established persistence via the `HKCU\SOFTWARE\microsoft\windows\currentversion\run` registry key.

T1573.001
Symmetric Cryptography
MalwareFlawedAmmyy

FlawedAmmyy has used SEAL encryption during the initial C2 handshake.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.