ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0447×

28 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareLokibot

Lokibot has the ability to discover the domain name of the infected host.

T1027
Obfuscated Files or Information
MalwareLokibot

Lokibot has obfuscated strings with base64 encoding.

T1027.002
Software Packing
MalwareLokibot

Lokibot has used several packing methods for obfuscation.

T1033
System Owner/User Discovery
MalwareLokibot

Lokibot has the ability to discover the username on the infected host.

T1041
Exfiltration Over C2 Channel
MalwareLokibot

Lokibot has the ability to initiate contact with command and control (C2) to exfiltrate stolen data.

T1053
Scheduled Task/Job
MalwareLokibot

Lokibot's second stage DLL has set a timer using “timeSetEvent” to schedule its next execution.

T1053.005
Scheduled Task
MalwareLokibot

Lokibot embedded the commands schtasks /Run /TN \Microsoft\Windows\DiskCleanup\SilentCleanup /I inside a batch script.

T1055.012
Process Hollowing
MalwareLokibot

Lokibot has used process hollowing to inject itself into legitimate Windows process.

T1056.001
Keylogging
MalwareLokibot

Lokibot has the ability to capture input on the compromised host via keylogging.

T1059.001
PowerShell
MalwareLokibot

Lokibot has used PowerShell commands embedded inside batch scripts.

T1059.003
Windows Command Shell
MalwareLokibot

Lokibot has used cmd /c commands embedded within batch scripts.

T1059.005
Visual Basic
MalwareLokibot

Lokibot has used VBS scripts and XLS macros for execution.

T1070.004
File Deletion
MalwareLokibot

Lokibot will delete its dropped files after bypassing UAC.

T1071.001
Web Protocols
MalwareLokibot

Lokibot has used HTTP for C2 communications.

T1082
System Information Discovery
MalwareLokibot

Lokibot has the ability to discover the computer name and Windows product name/version.

T1083
File and Directory Discovery
MalwareLokibot

Lokibot can search for specific files on an infected host.

T1105
Ingress Tool Transfer
MalwareLokibot

Lokibot downloaded several staged items onto the victim's machine.

T1106
Native API
MalwareLokibot

Lokibot has used LoadLibrary(), GetProcAddress() and CreateRemoteThread() API functions to execute its shellcode.

T1112
Modify Registry
MalwareLokibot

Lokibot has modified the Registry as part of its UAC bypass process.

T1140
Deobfuscate/Decode Files or Information
MalwareLokibot

Lokibot has decoded and decrypted its stages multiple times using hard-coded keys to deliver the final payload, and has decoded its server response hex string using XOR.

T1204.002
Malicious File
MalwareLokibot

Lokibot has tricked recipients into enabling malicious macros by getting victims to click "enable content" in email attachments.

T1497.003
Time Based Checks
MalwareLokibot

Lokibot has performed a time-based anti-debug check before downloading its third stage.

T1548.002
Bypass User Account Control
MalwareLokibot

Lokibot has utilized multiple techniques to bypass UAC.

T1555
Credentials from Password Stores
MalwareLokibot

Lokibot has stolen credentials from multiple applications and data sources including Windows OS credentials, email clients, FTP, and SFTP clients.

T1555.003
Credentials from Web Browsers
MalwareLokibot

Lokibot has demonstrated the ability to steal credentials from multiple applications and data sources including Safari and the Chromium and Mozilla Firefox-based web browsers.

T1564.001
Hidden Files and Directories
MalwareLokibot

Lokibot has the ability to copy itself to a hidden file and directory.

T1566.001
Spearphishing Attachment
MalwareLokibot

Lokibot is delivered via a malicious XLS attachment contained within a spearhpishing email.

T1620
Reflective Code Loading
MalwareLokibot

Lokibot has reflectively loaded the decoded DLL into memory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.