ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0449×

23 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareMaze

Maze has decrypted strings and other important information during the encryption process. Maze also calls certain functions dynamically to hinder analysis.

T1027.016
Junk Code Insertion
MalwareMaze

Maze has inserted large blocks of junk code, including some components to decrypt strings and other important information for later in the encryption process.

T1036.004
Masquerade Task or Service
MalwareMaze

Maze operators have created scheduled tasks masquerading as "Windows Update Security", "Windows Update Security Patches", and "Google Chrome Security Update" designed to launch the ransomware.

T1047
Windows Management Instrumentation
MalwareMaze

Maze has used WMI to attempt to delete the shadow volumes on a machine, and to connect a virtual machine to the network domain of the victim organization's network.

T1049
System Network Connections Discovery
MalwareMaze

Maze has used the "WNetOpenEnumW", "WNetEnumResourceW”, “WNetCloseEnum” and “WNetAddConnection2W” functions to enumerate the network resources on the infected machine.

T1053.005
Scheduled Task
MalwareMaze

Maze has created scheduled tasks using name variants such as "Windows Update Security", "Windows Update Security Patches", and "Google Chrome Security Update", to launch Maze at a specific time.

T1055.001
Dynamic-link Library Injection
MalwareMaze

Maze has injected the malware DLL into a target process.

T1057
Process Discovery
MalwareMaze

Maze has gathered all of the running system processes.

T1059.003
Windows Command Shell
MalwareMaze

The Maze encryption process has used batch scripts with various commands.

T1070
Indicator Removal
MalwareMaze

Maze has used the “Wow64RevertWow64FsRedirection” function following attempts to delete the shadow volumes, in order to leave the system in the same state as it was prior to redirection.

T1071.001
Web Protocols
MalwareMaze

Maze has communicated to hard-coded IP addresses via HTTP.

T1082
System Information Discovery
MalwareMaze

Maze has checked the language of the infected system using the "GetUSerDefaultUILanguage" function.

T1106
Native API
MalwareMaze

Maze has used several Windows API functions throughout the encryption process including IsDebuggerPresent, TerminateProcess, Process32FirstW, among others.

T1218.007
Msiexec
MalwareMaze

Maze has delivered components for its ransomware attacks using MSI files, some of which have been executed from the command-line using msiexec.

T1486
Data Encrypted for Impact
MalwareMaze

Maze has disrupted systems by encrypting files on targeted machines, claiming to decrypt files if a ransom payment is made. Maze has used the ChaCha algorithm, based on Salsa20, and an RSA algorithm to encrypt files.

T1489
Service Stop
MalwareMaze

Maze has stopped SQL services to ensure it can encrypt any database.

T1490
Inhibit System Recovery
MalwareMaze

Maze has attempted to delete the shadow volumes of infected machines, once before and once after the encryption process.

T1529
System Shutdown/Reboot
MalwareMaze

Maze has issued a shutdown command on a victim machine that, upon reboot, will run the ransomware within a VM.

T1547.001
Registry Run Keys / Startup Folder
MalwareMaze

Maze has created a file named "startup_vrun.bat" in the Startup folder of a virtual machine to establish persistence.

T1564.006
Run Virtual Instance
MalwareMaze

Maze operators have used VirtualBox and a Windows 7 virtual machine to run the ransomware; the virtual machine's configuration file mapped the shared network drives of the target company, presumably so Maze can encrypt files on the shared drives as well as the local machine.

T1568
Dynamic Resolution
MalwareMaze

Maze has forged POST strings with a random choice from a list of possibilities including "forum", "php", "view", etc. while making connection with the C2, hindering detection efforts.

T1614.001
System Language Discovery
MalwareMaze

Maze has checked the language of the machine with function GetUserDefaultUILanguage and terminated execution if the language matches with an entry in the predefined list.

T1685
Disable or Modify Tools
MalwareMaze

Maze has disabled dynamic analysis and other security tools including IDA debugger, x32dbg, and OllyDbg. It has also disabled Windows Defender's Real-Time Monitoring feature and attempted to disable endpoint protection services.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.