ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0428×

35 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
MalwarePoetRAT

PoetRAT used voStro.exe, a compiled pypykatz (Python version of Mimikatz), to steal credentials.

T1018
Remote System Discovery
MalwarePoetRAT

PoetRAT used Nmap for remote system discovery.

T1027
Obfuscated Files or Information
MalwarePoetRAT

PoetRAT has used a custom encryption scheme for communication between scripts.

T1027.010
Command Obfuscation
MalwarePoetRAT

PoetRAT has `pyminifier` to obfuscate scripts.

T1033
System Owner/User Discovery
MalwarePoetRAT

PoetRAT sent username, computer name, and the previously generated UUID in reply to a "who" command from C2.

T1041
Exfiltration Over C2 Channel
MalwarePoetRAT

PoetRAT has exfiltrated data over the C2 channel.

T1048
Exfiltration Over Alternative Protocol
MalwarePoetRAT

PoetRAT has used a .NET tool named dog.exe to exiltrate information over an e-mail account.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwarePoetRAT

PoetRAT has used ftp for exfiltration.

T1056.001
Keylogging
MalwarePoetRAT

PoetRAT has used a Python tool named klog.exe for keylogging.

T1057
Process Discovery
MalwarePoetRAT

PoetRAT has the ability to list all running processes.

T1059.003
Windows Command Shell
MalwarePoetRAT

PoetRAT has called cmd through a Word document macro.

T1059.005
Visual Basic
MalwarePoetRAT

PoetRAT has used Word documents with VBScripts to execute malicious activities.

T1059.006
Python
MalwarePoetRAT

PoetRAT was executed with a Python script and worked in conjunction with additional Python-based post-exploitation tools.

T1059.011
Lua
MalwarePoetRAT

PoetRAT has executed a Lua script through a Lua interpreter for Windows.

T1070.004
File Deletion
MalwarePoetRAT

PoetRAT has the ability to overwrite scripts and delete itself if a sandbox environment is detected.

T1071.001
Web Protocols
MalwarePoetRAT

PoetRAT has used HTTP and HTTPs for C2 communications.

T1071.002
File Transfer Protocols
MalwarePoetRAT

PoetRAT has used FTP for C2 communications.

T1082
System Information Discovery
MalwarePoetRAT

PoetRAT has the ability to gather information about the compromised host.

T1083
File and Directory Discovery
MalwarePoetRAT

PoetRAT has the ability to list files upon receiving the ls command from C2.

T1105
Ingress Tool Transfer
MalwarePoetRAT

PoetRAT has the ability to copy files and download/upload files into C2 channels using FTP and HTTPS.

T1112
Modify Registry
MalwarePoetRAT

PoetRAT has made registry modifications to alter its behavior upon execution.

T1113
Screen Capture
MalwarePoetRAT

PoetRAT has the ability to take screen captures.

T1119
Automated Collection
MalwarePoetRAT

PoetRAT used file system monitoring to track modification and enable automatic exfiltration.

T1125
Video Capture
MalwarePoetRAT

PoetRAT has used a Python tool named Bewmac to record the webcam on compromised hosts.

T1140
Deobfuscate/Decode Files or Information
MalwarePoetRAT

PoetRAT has used LZMA and base64 libraries to decode obfuscated scripts.

T1204.002
Malicious File
MalwarePoetRAT

PoetRAT has used spearphishing attachments to infect victims.

T1497.001
System Checks
MalwarePoetRAT

PoetRAT checked the size of the hard drive to determine if it was being run in a sandbox environment. In the event of sandbox detection, it would delete itself by overwriting the malware scripts with the contents of "License.txt" and exiting.

T1547.001
Registry Run Keys / Startup Folder
MalwarePoetRAT

PoetRAT has added a registry key in the <RUN> hive for persistence.

T1555.003
Credentials from Web Browsers
MalwarePoetRAT

PoetRAT has used a Python tool named Browdec.exe to steal browser credentials.

T1559.002
Dynamic Data Exchange
MalwarePoetRAT

PoetRAT was delivered with documents using DDE to execute malicious code.

T1560.001
Archive via Utility
MalwarePoetRAT

PoetRAT has the ability to compress files with zip.

T1564.001
Hidden Files and Directories
MalwarePoetRAT

PoetRAT has the ability to hide and unhide files.

T1566.001
Spearphishing Attachment
MalwarePoetRAT

PoetRAT was distributed via malicious Word documents.

T1571
Non-Standard Port
MalwarePoetRAT

PoetRAT used TLS to encrypt communications over port 143

T1573.002
Asymmetric Cryptography
MalwarePoetRAT

PoetRAT used TLS to encrypt command and control (C2) communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.