ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0412×

34 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareZxShell

ZxShell can transfer files from a compromised host.

T1007
System Service Discovery
MalwareZxShell

ZxShell can check the services on the system.

T1012
Query Registry
MalwareZxShell

ZxShell can query the netsvc group value data located in the svchost group Registry key.

T1021.001
Remote Desktop Protocol
MalwareZxShell

ZxShell has remote desktop functionality.

T1021.005
VNC
MalwareZxShell

ZxShell supports functionality for VNC sessions.

T1033
System Owner/User Discovery
MalwareZxShell

ZxShell can collect the owner and organization information from the target workstation.

T1046
Network Service Discovery
MalwareZxShell

ZxShell can launch port scans.

T1055.001
Dynamic-link Library Injection
MalwareZxShell

ZxShell is injected into a shared SVCHOST process.

T1056.001
Keylogging
MalwareZxShell

ZxShell has a feature to capture a remote computer's keystrokes using a keylogger.

T1056.004
Credential API Hooking
MalwareZxShell

ZxShell hooks several API functions to spawn system threads.

T1057
Process Discovery
MalwareZxShell

ZxShell has a command, ps, to obtain a listing of processes on the system.

T1059.003
Windows Command Shell
MalwareZxShell

ZxShell can launch a reverse command shell.

T1070.004
File Deletion
MalwareZxShell

ZxShell can delete files from the system.

T1071.001
Web Protocols
MalwareZxShell

ZxShell has used HTTP for C2 connections.

T1071.002
File Transfer Protocols
MalwareZxShell

ZxShell has used FTP for C2 connections.

T1082
System Information Discovery
MalwareZxShell

ZxShell can collect the local hostname, operating system details, CPU speed, and total physical memory.

T1083
File and Directory Discovery
MalwareZxShell

ZxShell has a command to open a file manager and explorer on the system.

T1090
Proxy
MalwareZxShell

ZxShell can set up an HTTP or SOCKS proxy.

T1105
Ingress Tool Transfer
MalwareZxShell

ZxShell has a command to transfer files from a remote host.

T1106
Native API
MalwareZxShell

ZxShell can leverage native API including RegisterServiceCtrlHandler to register a service.RegisterServiceCtrlHandler

T1112
Modify Registry
MalwareZxShell

ZxShell can create Registry entries to enable services to run.

T1113
Screen Capture
MalwareZxShell

ZxShell can capture screenshots.

T1125
Video Capture
MalwareZxShell

ZxShell has a command to perform video device spying.

T1134.002
Create Process with Token
MalwareZxShell

ZxShell has a command called RunAs, which creates a new process as another user or process context.

T1136.001
Local Account
MalwareZxShell

ZxShell has a feature to create local user accounts.

T1190
Exploit Public-Facing Application
MalwareZxShell

ZxShell has been dropped through exploitation of CVE-2011-2462, CVE-2013-3163, and CVE-2014-0322.

T1218.011
Rundll32
MalwareZxShell

ZxShell has used rundll32.exe to execute other DLLs and named pipes.

T1499
Endpoint Denial of Service
MalwareZxShell

ZxShell has a feature to perform SYN flood attack on a host.

T1543.003
Windows Service
MalwareZxShell

ZxShell can create a new service using the service parser function ProcessScCommand.

T1569.002
Service Execution
MalwareZxShell

ZxShell can create a new service for execution.

T1571
Non-Standard Port
MalwareZxShell

ZxShell can use ports 1985 and 1986 in HTTP/S communication.

T1685
Disable or Modify Tools
MalwareZxShell

ZxShell can kill AV products' processes.

T1685.005
Clear Windows Event Logs
MalwareZxShell

ZxShell has a command to clear system event logs.

T1686
Disable or Modify System Firewall
MalwareZxShell

ZxShell can disable the firewall by modifying the registry key HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.