Real-world descriptions of how a group, tool or campaign used a technique.
21 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareShimRat | ShimRat has the capability to upload collected files to a C2. |
| T1008 Fallback Channels |
MalwareShimRat | ShimRat has used a secondary C2 location if the first was unavailable. |
| T1027.002 Software Packing |
MalwareShimRat | ShimRat's loader has been packed with the compressed ShimRat core DLL and the legitimate DLL for it to hijack. |
| T1027.015 Compression |
MalwareShimRat | ShimRat has been delivered as a package that includes compressed DLL and shellcode payloads within a .dat file. |
| T1029 Scheduled Transfer |
MalwareShimRat | ShimRat can sleep when instructed to do so by the C2. |
| T1036.004 Masquerade Task or Service |
MalwareShimRat | ShimRat can impersonate Windows services and antivirus products to avoid detection on compromised systems. |
| T1059.003 Windows Command Shell |
MalwareShimRat | ShimRat can be issued a command shell function from the C2. |
| T1070.004 File Deletion |
MalwareShimRat | ShimRat can uninstall itself from compromised hosts, as well create and modify directories, delete, move, copy, and rename files. |
| T1071.001 Web Protocols |
MalwareShimRat | ShimRat communicated over HTTP and HTTPS with C2 servers. |
| T1083 File and Directory Discovery |
MalwareShimRat | ShimRat can list directories. |
| T1090.002 External Proxy |
MalwareShimRat | ShimRat can use pre-configured HTTP proxies. |
| T1105 Ingress Tool Transfer |
MalwareShimRat | ShimRat can download additional files. |
| T1106 Native API |
MalwareShimRat | ShimRat has used Windows API functions to install the service and shim. |
| T1112 Modify Registry |
MalwareShimRat | ShimRat has registered two registry keys for shim databases. |
| T1135 Network Share Discovery |
MalwareShimRat | ShimRat can enumerate connected drives for infected host machines. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareShimRat | ShimRat has decompressed its core DLL using shellcode once an impersonated antivirus component was running on a system. |
| T1543.003 Windows Service |
MalwareShimRat | ShimRat has installed a Windows service to maintain persistence on victim machines. |
| T1546.011 Application Shimming |
MalwareShimRat | ShimRat has installed shim databases in the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareShimRat | ShimRat has installed a registry based start-up key |
| T1548.002 Bypass User Account Control |
MalwareShimRat | ShimRat has hijacked the cryptbase.dll within migwiz.exe to escalate privileges. This prevented the User Access Control window from appearing. |
| T1574 Hijack Execution Flow |
MalwareShimRat | ShimRat can hijack the cryptbase.dll within migwiz.exe to escalate privileges and bypass UAC controls. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.