Real-world descriptions of how a group, tool or campaign used a technique.
34 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareZxShell | ZxShell can transfer files from a compromised host. |
| T1007 System Service Discovery |
MalwareZxShell | ZxShell can check the services on the system. |
| T1012 Query Registry |
MalwareZxShell | ZxShell can query the netsvc group value data located in the svchost group Registry key. |
| T1021.001 Remote Desktop Protocol |
MalwareZxShell | ZxShell has remote desktop functionality. |
| T1021.005 VNC |
MalwareZxShell | ZxShell supports functionality for VNC sessions. |
| T1033 System Owner/User Discovery |
MalwareZxShell | ZxShell can collect the owner and organization information from the target workstation. |
| T1046 Network Service Discovery |
MalwareZxShell | ZxShell can launch port scans. |
| T1055.001 Dynamic-link Library Injection |
MalwareZxShell | ZxShell is injected into a shared SVCHOST process. |
| T1056.001 Keylogging |
MalwareZxShell | ZxShell has a feature to capture a remote computer's keystrokes using a keylogger. |
| T1056.004 Credential API Hooking |
MalwareZxShell | ZxShell hooks several API functions to spawn system threads. |
| T1057 Process Discovery |
MalwareZxShell | ZxShell has a command, ps, to obtain a listing of processes on the system. |
| T1059.003 Windows Command Shell |
MalwareZxShell | ZxShell can launch a reverse command shell. |
| T1070.004 File Deletion |
MalwareZxShell | ZxShell can delete files from the system. |
| T1071.001 Web Protocols |
MalwareZxShell | ZxShell has used HTTP for C2 connections. |
| T1071.002 File Transfer Protocols |
MalwareZxShell | ZxShell has used FTP for C2 connections. |
| T1082 System Information Discovery |
MalwareZxShell | ZxShell can collect the local hostname, operating system details, CPU speed, and total physical memory. |
| T1083 File and Directory Discovery |
MalwareZxShell | ZxShell has a command to open a file manager and explorer on the system. |
| T1090 Proxy |
MalwareZxShell | ZxShell can set up an HTTP or SOCKS proxy. |
| T1105 Ingress Tool Transfer |
MalwareZxShell | ZxShell has a command to transfer files from a remote host. |
| T1106 Native API |
MalwareZxShell | ZxShell can leverage native API including |
| T1112 Modify Registry |
MalwareZxShell | ZxShell can create Registry entries to enable services to run. |
| T1113 Screen Capture |
MalwareZxShell | ZxShell can capture screenshots. |
| T1125 Video Capture |
MalwareZxShell | ZxShell has a command to perform video device spying. |
| T1134.002 Create Process with Token |
MalwareZxShell | ZxShell has a command called RunAs, which creates a new process as another user or process context. |
| T1136.001 Local Account |
MalwareZxShell | ZxShell has a feature to create local user accounts. |
| T1190 Exploit Public-Facing Application |
MalwareZxShell | ZxShell has been dropped through exploitation of CVE-2011-2462, CVE-2013-3163, and CVE-2014-0322. |
| T1218.011 Rundll32 |
MalwareZxShell | ZxShell has used rundll32.exe to execute other DLLs and named pipes. |
| T1499 Endpoint Denial of Service |
MalwareZxShell | ZxShell has a feature to perform SYN flood attack on a host. |
| T1543.003 Windows Service |
MalwareZxShell | ZxShell can create a new service using the service parser function ProcessScCommand. |
| T1569.002 Service Execution |
MalwareZxShell | ZxShell can create a new service for execution. |
| T1571 Non-Standard Port |
MalwareZxShell | ZxShell can use ports 1985 and 1986 in HTTP/S communication. |
| T1685 Disable or Modify Tools |
MalwareZxShell | ZxShell can kill AV products' processes. |
| T1685.005 Clear Windows Event Logs |
MalwareZxShell | ZxShell has a command to clear system event logs. |
| T1686 Disable or Modify System Firewall |
MalwareZxShell | ZxShell can disable the firewall by modifying the registry key |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.