ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0386×

35 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareUrsnif

Ursnif has collected files from victim machines, including certificates and cookies.

T1007
System Service Discovery
MalwareUrsnif

Ursnif has gathered information about running services.

T1012
Query Registry
MalwareUrsnif

Ursnif has used Reg to query the Registry for installed programs.

T1027.010
Command Obfuscation
MalwareUrsnif

Ursnif droppers execute base64 encoded PowerShell commands.

T1027.013
Encrypted/Encoded File
MalwareUrsnif

Ursnif has used an XOR-based algorithm to encrypt Tor clients dropped to disk. Ursnif droppers have also been delivered as password-protected zip files that execute base64 encoded PowerShell commands.

T1036.005
Match Legitimate Resource Name or Location
MalwareUrsnif

Ursnif has used strings from legitimate system files and existing folders for its file, folder, and Registry entry names.

T1041
Exfiltration Over C2 Channel
MalwareUrsnif

Ursnif has used HTTP POSTs to exfil gathered information.

T1047
Windows Management Instrumentation
MalwareUrsnif

Ursnif droppers have used WMI classes to execute PowerShell commands.

T1055.005
Thread Local Storage
MalwareUrsnif

Ursnif has injected code into target processes via thread local storage callbacks.

T1055.012
Process Hollowing
MalwareUrsnif

Ursnif has used process hollowing to inject into child processes.

T1056.004
Credential API Hooking
MalwareUrsnif

Ursnif has hooked APIs to perform a wide variety of information theft, such as monitoring traffic from browsers.

T1057
Process Discovery
MalwareUrsnif

Ursnif has gathered information about running processes.

T1059.001
PowerShell
MalwareUrsnif

Ursnif droppers have used PowerShell in download cradles to download and execute the malware's full executable payload.

T1059.005
Visual Basic
MalwareUrsnif

Ursnif droppers have used VBA macros to download and execute the malware's full executable payload.

T1070.004
File Deletion
MalwareUrsnif

Ursnif has deleted data staged in tmp files after exfiltration.

T1071.001
Web Protocols
MalwareUrsnif

Ursnif has used HTTPS for C2.

T1074.001
Local Data Staging
MalwareUrsnif

Ursnif has used tmp files to stage gathered information.

T1080
Taint Shared Content
MalwareUrsnif

Ursnif has copied itself to and infected files in network drives for propagation.

T1082
System Information Discovery
MalwareUrsnif

Ursnif has used Systeminfo to gather system information.

T1090
Proxy
MalwareUrsnif

Ursnif has used a peer-to-peer (P2P) network for C2.

T1090.003
Multi-hop Proxy
MalwareUrsnif

Ursnif has used Tor for C2.

T1091
Replication Through Removable Media
MalwareUrsnif

Ursnif has copied itself to and infected removable drives for propagation.

T1105
Ingress Tool Transfer
MalwareUrsnif

Ursnif has dropped payload and configuration files to disk. Ursnif has also been used to download and execute additional payloads.

T1106
Native API
MalwareUrsnif

Ursnif has used CreateProcessW to create child processes.

T1112
Modify Registry
MalwareUrsnif

Ursnif has used Registry modifications as part of its installation routine.

T1113
Screen Capture
MalwareUrsnif

Ursnif has used hooked APIs to take screenshots.

T1132
Data Encoding
MalwareUrsnif

Ursnif has used encoded data in HTTP URLs for C2.

T1140
Deobfuscate/Decode Files or Information
MalwareUrsnif

Ursnif has used crypto key information stored in the Registry to decrypt Tor clients dropped to disk.

T1185
Browser Session Hijacking
MalwareUrsnif

Ursnif has injected HTML codes into banking sites to steal sensitive online banking information (ex: usernames and passwords).

T1497.003
Time Based Checks
MalwareUrsnif

Ursnif has used a 30 minute delay after execution to evade sandbox monitoring tools.

T1543.003
Windows Service
MalwareUrsnif

Ursnif has registered itself as a system service in the Registry for automatic execution at system startup.

T1547.001
Registry Run Keys / Startup Folder
MalwareUrsnif

Ursnif has used Registry Run keys to establish automatic execution at system startup.

T1559.001
Component Object Model
MalwareUrsnif

Ursnif droppers have used COM objects to execute the malware's full executable payload.

T1564.003
Hidden Window
MalwareUrsnif

Ursnif droppers have used COM properties to execute malware in hidden windows.

T1568.002
Domain Generation Algorithms
MalwareUrsnif

Ursnif has used a DGA to generate domain names for C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.