ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0387×

18 examples

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
MalwareKeyBoy

KeyBoy uses custom SSL libraries to impersonate SSL in C2 traffic.

T1016
System Network Configuration Discovery
MalwareKeyBoy

KeyBoy can determine the public or WAN IP address for the system.

T1027.013
Encrypted/Encoded File
MalwareKeyBoy

In one version of KeyBoy, string obfuscation routines were used to hide many of the critical values referenced in the malware.

T1056.001
Keylogging
MalwareKeyBoy

KeyBoy installs a keylogger for intercepting credentials and keystrokes.

T1059.001
PowerShell
MalwareKeyBoy

KeyBoy uses PowerShell commands to download and execute payloads.

T1059.003
Windows Command Shell
MalwareKeyBoy

KeyBoy can launch interactive shells for communicating with the victim machine.

T1059.005
Visual Basic
MalwareKeyBoy

KeyBoy uses VBS scripts for installing files and performing execution.

T1059.006
Python
MalwareKeyBoy

KeyBoy uses Python scripts for installing files and performing execution.

T1070.006
Timestomp
MalwareKeyBoy

KeyBoy time-stomped its DLL in order to evade detection.

T1082
System Information Discovery
MalwareKeyBoy

KeyBoy can gather extended system information, such as information about the operating system and memory.

T1083
File and Directory Discovery
MalwareKeyBoy

KeyBoy has a command to launch a file browser or explorer on the system.

T1105
Ingress Tool Transfer
MalwareKeyBoy

KeyBoy has a download and upload functionality.

T1113
Screen Capture
MalwareKeyBoy

KeyBoy has a command to perform screen grabbing.

T1543.003
Windows Service
MalwareKeyBoy

KeyBoy installs a service pointing to a malicious DLL dropped to disk.

T1547.004
Winlogon Helper DLL
MalwareKeyBoy

KeyBoy issues the command reg add “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon” to achieve persistence.

T1555.003
Credentials from Web Browsers
MalwareKeyBoy

KeyBoy attempts to collect passwords from browsers.

T1559.002
Dynamic Data Exchange
MalwareKeyBoy

KeyBoy uses the Dynamic Data Exchange (DDE) protocol to download remote payloads.

T1564.003
Hidden Window
MalwareKeyBoy

KeyBoy uses -w Hidden to conceal a PowerShell window that downloads a payload.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.