ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0446×

22 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareRyuk

Ryuk has called GetIpNetTable in attempt to identify all mounted drives and hosts that have Address Resolution Protocol (ARP) entries.

T1021.002
SMB/Windows Admin Shares
MalwareRyuk

Ryuk has used the C$ network share for lateral movement.

T1027
Obfuscated Files or Information
MalwareRyuk

Ryuk can use anti-disassembly and code transformation obfuscation techniques.

T1036
Masquerading
MalwareRyuk

Ryuk can create .dll files that actually contain a Rich Text File format document.

T1036.005
Match Legitimate Resource Name or Location
MalwareRyuk

Ryuk has constructed legitimate appearing installation folder paths by calling GetWindowsDirectoryW and then inserting a null byte at the fourth character of the path. For Windows Vista or higher, the path would appear as C:\Users\Public.

T1053.005
Scheduled Task
MalwareRyuk

Ryuk can remotely create a scheduled task to execute itself on a system.

T1055
Process Injection
MalwareRyuk

Ryuk has injected itself into remote processes to encrypt files using a combination of VirtualAlloc, WriteProcessMemory, and CreateRemoteThread.

T1057
Process Discovery
MalwareRyuk

Ryuk has called CreateToolhelp32Snapshot to enumerate all running processes.

T1059.003
Windows Command Shell
MalwareRyuk

Ryuk has used cmd.exe to create a Registry entry to establish persistence.

T1078.002
Domain Accounts
MalwareRyuk

Ryuk can use stolen domain admin accounts to move laterally within a victim domain.

T1083
File and Directory Discovery
MalwareRyuk

Ryuk has enumerated files and folders on all mounted drives.

T1106
Native API
MalwareRyuk

Ryuk has used multiple native APIs including ShellExecuteW to run executables,GetWindowsDirectoryW to create folders, and VirtualAlloc, WriteProcessMemory, and CreateRemoteThread for process injection.

T1134
Access Token Manipulation
MalwareRyuk

Ryuk has attempted to adjust its token privileges to have the SeDebugPrivilege.

T1205
Traffic Signaling
MalwareRyuk

Ryuk has used Wake-on-Lan to power on turned off systems for lateral movement.

T1222.001
Windows Permissions
MalwareRyuk

Ryuk can launch icacls <path> /grant Everyone:F /T /C /Q to delete every access-based restrictions on files and directories.

T1486
Data Encrypted for Impact
MalwareRyuk

Ryuk has used a combination of symmetric (AES) and asymmetric (RSA) encryption to encrypt files. Files have been encrypted with their own AES key and given a file extension of .RYK. Encrypted directories have had a ransom note of RyukReadMe.txt written to the directory.

T1489
Service Stop
MalwareRyuk

Ryuk has called kill.bat for stopping services, disabling services and killing processes.

T1490
Inhibit System Recovery
MalwareRyuk

Ryuk has used vssadmin Delete Shadows /all /quiet to to delete volume shadow copies and vssadmin resize shadowstorage to force deletion of shadow copies created by third-party applications.

T1547.001
Registry Run Keys / Startup Folder
MalwareRyuk

Ryuk has used the Windows command line to create a Registry entry under HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run to establish persistence.

T1614.001
System Language Discovery
MalwareRyuk

Ryuk has been observed to query the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Language and the value InstallLanguage. If the machine has the value 0x419 (Russian), 0x422 (Ukrainian), or 0x423 (Belarusian), it stops execution.

T1680
Local Storage Discovery
MalwareRyuk

Ryuk has called GetLogicalDrives to emumerate all mounted drives, and GetDriveTypeW to determine the drive type.

T1685
Disable or Modify Tools
MalwareRyuk

Ryuk has stopped services related to anti-virus.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.