ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0444×

21 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareShimRat

ShimRat has the capability to upload collected files to a C2.

T1008
Fallback Channels
MalwareShimRat

ShimRat has used a secondary C2 location if the first was unavailable.

T1027.002
Software Packing
MalwareShimRat

ShimRat's loader has been packed with the compressed ShimRat core DLL and the legitimate DLL for it to hijack.

T1027.015
Compression
MalwareShimRat

ShimRat has been delivered as a package that includes compressed DLL and shellcode payloads within a .dat file.

T1029
Scheduled Transfer
MalwareShimRat

ShimRat can sleep when instructed to do so by the C2.

T1036.004
Masquerade Task or Service
MalwareShimRat

ShimRat can impersonate Windows services and antivirus products to avoid detection on compromised systems.

T1059.003
Windows Command Shell
MalwareShimRat

ShimRat can be issued a command shell function from the C2.

T1070.004
File Deletion
MalwareShimRat

ShimRat can uninstall itself from compromised hosts, as well create and modify directories, delete, move, copy, and rename files.

T1071.001
Web Protocols
MalwareShimRat

ShimRat communicated over HTTP and HTTPS with C2 servers.

T1083
File and Directory Discovery
MalwareShimRat

ShimRat can list directories.

T1090.002
External Proxy
MalwareShimRat

ShimRat can use pre-configured HTTP proxies.

T1105
Ingress Tool Transfer
MalwareShimRat

ShimRat can download additional files.

T1106
Native API
MalwareShimRat

ShimRat has used Windows API functions to install the service and shim.

T1112
Modify Registry
MalwareShimRat

ShimRat has registered two registry keys for shim databases.

T1135
Network Share Discovery
MalwareShimRat

ShimRat can enumerate connected drives for infected host machines.

T1140
Deobfuscate/Decode Files or Information
MalwareShimRat

ShimRat has decompressed its core DLL using shellcode once an impersonated antivirus component was running on a system.

T1543.003
Windows Service
MalwareShimRat

ShimRat has installed a Windows service to maintain persistence on victim machines.

T1546.011
Application Shimming
MalwareShimRat

ShimRat has installed shim databases in the AppPatch folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareShimRat

ShimRat has installed a registry based start-up key HKCU\Software\microsoft\windows\CurrentVersion\Run to maintain persistence should other methods fail.

T1548.002
Bypass User Account Control
MalwareShimRat

ShimRat has hijacked the cryptbase.dll within migwiz.exe to escalate privileges. This prevented the User Access Control window from appearing.

T1574
Hijack Execution Flow
MalwareShimRat

ShimRat can hijack the cryptbase.dll within migwiz.exe to escalate privileges and bypass UAC controls.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.