ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0409×

41 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareMachete

Machete searches the File system for files of interest.

T1008
Fallback Channels
MalwareMachete

Machete has sent data over HTTP if FTP failed, and has also used a fallback server.

T1010
Application Window Discovery
MalwareMachete

Machete saves the window names.

T1016
System Network Configuration Discovery
MalwareMachete

Machete collects the MAC address of the target computer and other network configuration information.

T1016.002
Wi-Fi Discovery
MalwareMachete

Machete uses the netsh wlan show networks mode=bssid and netsh wlan show interfaces commands to list all nearby WiFi networks and connected interfaces.

T1020
Automated Exfiltration
MalwareMachete

Machete’s collected files are exfiltrated automatically to remote servers.

T1025
Data from Removable Media
MalwareMachete

Machete can find, encrypt, and upload files from fixed and removable drives.

T1027.002
Software Packing
MalwareMachete

Machete has been packed with NSIS.

T1027.010
Command Obfuscation
MalwareMachete

Machete has used pyobfuscate, zlib compression, and base64 encoding for obfuscation. Machete has also used some visual obfuscation techniques by naming variables as combinations of letters to hinder analysis.

T1029
Scheduled Transfer
MalwareMachete

Machete sends stolen data to the C2 server every 10 minutes.

T1036.004
Masquerade Task or Service
MalwareMachete

Machete renamed task names to masquerade as legitimate Google Chrome, Java, Dropbox, Adobe Reader and Python tasks.

T1036.005
Match Legitimate Resource Name or Location
MalwareMachete

Machete renamed payloads to masquerade as legitimate Google Chrome, Java, Dropbox, Adobe Reader and Python executables.

T1041
Exfiltration Over C2 Channel
MalwareMachete

Machete's collected data is exfiltrated over the same channel used for C2.

T1052.001
Exfiltration over USB
MalwareMachete

Machete has a feature to copy files from every drive onto a removable drive in a hidden folder.

T1053.005
Scheduled Task
MalwareMachete

The different components of Machete are executed by Windows Task Scheduler.

T1056.001
Keylogging
MalwareMachete

Machete logs keystrokes from the victim’s machine.

T1057
Process Discovery
MalwareMachete

Machete has a component to check for running processes to look for web browsers.

T1059.006
Python
MalwareMachete

Machete is written in Python and is used in conjunction with additional Python scripts.

T1070.004
File Deletion
MalwareMachete

Once a file is uploaded, Machete will delete it from the machine.

T1071.001
Web Protocols
MalwareMachete

Machete uses HTTP for Command & Control.

T1071.002
File Transfer Protocols
MalwareMachete

Machete uses FTP for Command & Control.

T1074.001
Local Data Staging
MalwareMachete

Machete stores files and logs in a folder on the local drive.

T1082
System Information Discovery
MalwareMachete

Machete collects the hostname of the target computer.

T1083
File and Directory Discovery
MalwareMachete

Machete produces file listings in order to search for files to be exfiltrated.

T1105
Ingress Tool Transfer
MalwareMachete

Machete can download additional files for execution on the victim’s machine.

T1113
Screen Capture
MalwareMachete

Machete captures screenshots.

T1115
Clipboard Data
MalwareMachete

Machete hijacks the clipboard data by creating an overlapped window that listens to keyboard events.

T1120
Peripheral Device Discovery
MalwareMachete

Machete detects the insertion of new devices by listening for the WM_DEVICECHANGE window message.

T1123
Audio Capture
MalwareMachete

Machete captures audio from the computer’s microphone.

T1125
Video Capture
MalwareMachete

Machete takes photos from the computer’s web camera.

T1132.001
Standard Encoding
MalwareMachete

Machete has used base64 encoding.

T1140
Deobfuscate/Decode Files or Information
MalwareMachete

Machete’s downloaded data is decrypted using AES.

T1217
Browser Information Discovery
MalwareMachete

Machete retrieves the user profile data (e.g., browsers) from Chrome and Firefox browsers.

T1547.001
Registry Run Keys / Startup Folder
MalwareMachete

Machete used the startup folder for persistence.

T1552.004
Private Keys
MalwareMachete

Machete has scanned and looked for cryptographic keys and certificate file extensions.

T1555.003
Credentials from Web Browsers
MalwareMachete

Machete collects stored credentials from several web browsers.

T1560
Archive Collected Data
MalwareMachete

Machete stores zipped files with profile data from installed web browsers.

T1560.003
Archive via Custom Method
MalwareMachete

Machete's collected data is encrypted with AES before exfiltration.

T1564.001
Hidden Files and Directories
MalwareMachete

Machete has the capability to exfiltrate stolen data to a hidden folder on a removable drive.

T1573.001
Symmetric Cryptography
MalwareMachete

Machete has used AES to exfiltrate documents.

T1573.002
Asymmetric Cryptography
MalwareMachete

Machete has used TLS-encrypted FTP to exfiltrate data.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.