ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0445×

16 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
ToolShimRatReporter

ShimRatReporter gathered the local proxy, domain, IP, routing tables, mac address, gateway, DNS servers, and DHCP status information from an infected host.

T1020
Automated Exfiltration
ToolShimRatReporter

ShimRatReporter sent collected system and network information compiled into a report to an adversary-controlled C2.

T1027
Obfuscated Files or Information
ToolShimRatReporter

ShimRatReporter encrypted gathered information with a combination of shifting and XOR using a static key.

T1036.005
Match Legitimate Resource Name or Location
ToolShimRatReporter

ShimRatReporter spoofed itself as AlphaZawgyl_font.exe, a specialized Unicode font.

T1041
Exfiltration Over C2 Channel
ToolShimRatReporter

ShimRatReporter sent generated reports to the C2 via HTTP POST requests.

T1049
System Network Connections Discovery
ToolShimRatReporter

ShimRatReporter used the Windows function GetExtendedUdpTable to detect connected UDP endpoints.

T1057
Process Discovery
ToolShimRatReporter

ShimRatReporter listed all running processes on the machine.

T1069
Permission Groups Discovery
ToolShimRatReporter

ShimRatReporter gathered the local privileges for the infected host.

T1071.001
Web Protocols
ToolShimRatReporter

ShimRatReporter communicated over HTTP with preconfigured C2 servers.

T1082
System Information Discovery
ToolShimRatReporter

ShimRatReporter gathered the operating system name and specific Windows version of an infected machine.

T1087
Account Discovery
ToolShimRatReporter

ShimRatReporter listed all non-privileged and privileged accounts available on the machine.

T1105
Ingress Tool Transfer
ToolShimRatReporter

ShimRatReporter had the ability to download additional payloads.

T1106
Native API
ToolShimRatReporter

ShimRatReporter used several Windows API functions to gather information from the infected system.

T1119
Automated Collection
ToolShimRatReporter

ShimRatReporter gathered information automatically, without instruction from a C2, related to the user and host machine that is compiled into a report and sent to the operators.

T1518
Software Discovery
ToolShimRatReporter

ShimRatReporter gathered a list of installed software on the infected host.

T1560
Archive Collected Data
ToolShimRatReporter

ShimRatReporter used LZ compression to compress initial reconnaissance reports before sending to the C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.