Real-world descriptions of how a group, tool or campaign used a technique.
20 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareRising Sun | Rising Sun has collected data and files from a compromised host. |
| T1012 Query Registry |
MalwareRising Sun | Rising Sun has identified the OS product name from a compromised host by searching the registry for `SOFTWARE\MICROSOFT\Windows NT\ CurrentVersion | ProductName`. |
| T1016 System Network Configuration Discovery |
MalwareRising Sun | Rising Sun can detect network adapter and IP address information. |
| T1016.001 Internet Connection Discovery |
MalwareRising Sun | Rising Sun can test a connection to a specified network IP address over a specified port number. |
| T1027.013 Encrypted/Encoded File |
MalwareRising Sun | Configuration data used by Rising Sun has been encrypted using an RC4 stream algorithm. |
| T1033 System Owner/User Discovery |
MalwareRising Sun | Rising Sun can detect the username of the infected host. |
| T1041 Exfiltration Over C2 Channel |
MalwareRising Sun | Rising Sun can send data gathered from the infected machine via HTTP POST request to the C2. |
| T1057 Process Discovery |
MalwareRising Sun | Rising Sun can enumerate all running processes and process information on an infected machine. |
| T1059.003 Windows Command Shell |
MalwareRising Sun | Rising Sun has executed commands using `cmd.exe /c “<command> > <%temp%>\AM<random>. tmp” 2>&1`. |
| T1070 Indicator Removal |
MalwareRising Sun | Rising Sun can clear a memory blog in the process by overwriting it with junk bytes. |
| T1070.004 File Deletion |
MalwareRising Sun | Rising Sun can delete files and artifacts it creates. |
| T1071.001 Web Protocols |
MalwareRising Sun | Rising Sun has used HTTP and HTTPS for command and control. |
| T1082 System Information Discovery |
MalwareRising Sun | Rising Sun can detect the computer name and operating system. |
| T1083 File and Directory Discovery |
MalwareRising Sun | Rising Sun can enumerate information about files from the infected system, including file size, attributes, creation time, last access time, and write time. Rising Sun can enumerate the compilation timestamp of Windows executable files. |
| T1106 Native API |
MalwareRising Sun | Rising Sun used dynamic API resolutions to various Windows APIs by leveraging `LoadLibrary()` and `GetProcAddress()`. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRising Sun | Rising Sun has decrypted itself using a single-byte XOR scheme. Additionally, Rising Sun can decrypt its configuration data at runtime. |
| T1560.003 Archive via Custom Method |
MalwareRising Sun | Rising Sun can archive data using RC4 encryption and Base64 encoding prior to exfiltration. |
| T1564.001 Hidden Files and Directories |
MalwareRising Sun | Rising Sun can modify file attributes to hide files. |
| T1573.002 Asymmetric Cryptography |
MalwareRising Sun | Rising Sun variants can use SSL for encrypting C2 communications. |
| T1680 Local Storage Discovery |
MalwareRising Sun | Rising Sun can detect drive information, including drive type, total number of bytes on disk, total number of free bytes on disk, and name of a specified volume. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.