Real-world descriptions of how a group, tool or campaign used a technique.
23 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareMaze | Maze has decrypted strings and other important information during the encryption process. Maze also calls certain functions dynamically to hinder analysis. |
| T1027.016 Junk Code Insertion |
MalwareMaze | Maze has inserted large blocks of junk code, including some components to decrypt strings and other important information for later in the encryption process. |
| T1036.004 Masquerade Task or Service |
MalwareMaze | Maze operators have created scheduled tasks masquerading as "Windows Update Security", "Windows Update Security Patches", and "Google Chrome Security Update" designed to launch the ransomware. |
| T1047 Windows Management Instrumentation |
MalwareMaze | Maze has used WMI to attempt to delete the shadow volumes on a machine, and to connect a virtual machine to the network domain of the victim organization's network. |
| T1049 System Network Connections Discovery |
MalwareMaze | Maze has used the "WNetOpenEnumW", "WNetEnumResourceW”, “WNetCloseEnum” and “WNetAddConnection2W” functions to enumerate the network resources on the infected machine. |
| T1053.005 Scheduled Task |
MalwareMaze | Maze has created scheduled tasks using name variants such as "Windows Update Security", "Windows Update Security Patches", and "Google Chrome Security Update", to launch Maze at a specific time. |
| T1055.001 Dynamic-link Library Injection |
MalwareMaze | Maze has injected the malware DLL into a target process. |
| T1057 Process Discovery |
MalwareMaze | Maze has gathered all of the running system processes. |
| T1059.003 Windows Command Shell |
MalwareMaze | The Maze encryption process has used batch scripts with various commands. |
| T1070 Indicator Removal |
MalwareMaze | Maze has used the “Wow64RevertWow64FsRedirection” function following attempts to delete the shadow volumes, in order to leave the system in the same state as it was prior to redirection. |
| T1071.001 Web Protocols |
MalwareMaze | Maze has communicated to hard-coded IP addresses via HTTP. |
| T1082 System Information Discovery |
MalwareMaze | Maze has checked the language of the infected system using the "GetUSerDefaultUILanguage" function. |
| T1106 Native API |
MalwareMaze | Maze has used several Windows API functions throughout the encryption process including IsDebuggerPresent, TerminateProcess, Process32FirstW, among others. |
| T1218.007 Msiexec |
MalwareMaze | Maze has delivered components for its ransomware attacks using MSI files, some of which have been executed from the command-line using |
| T1486 Data Encrypted for Impact |
MalwareMaze | Maze has disrupted systems by encrypting files on targeted machines, claiming to decrypt files if a ransom payment is made. Maze has used the ChaCha algorithm, based on Salsa20, and an RSA algorithm to encrypt files. |
| T1489 Service Stop |
MalwareMaze | Maze has stopped SQL services to ensure it can encrypt any database. |
| T1490 Inhibit System Recovery |
MalwareMaze | Maze has attempted to delete the shadow volumes of infected machines, once before and once after the encryption process. |
| T1529 System Shutdown/Reboot |
MalwareMaze | Maze has issued a shutdown command on a victim machine that, upon reboot, will run the ransomware within a VM. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMaze | Maze has created a file named "startup_vrun.bat" in the Startup folder of a virtual machine to establish persistence. |
| T1564.006 Run Virtual Instance |
MalwareMaze | Maze operators have used VirtualBox and a Windows 7 virtual machine to run the ransomware; the virtual machine's configuration file mapped the shared network drives of the target company, presumably so Maze can encrypt files on the shared drives as well as the local machine. |
| T1568 Dynamic Resolution |
MalwareMaze | Maze has forged POST strings with a random choice from a list of possibilities including "forum", "php", "view", etc. while making connection with the C2, hindering detection efforts. |
| T1614.001 System Language Discovery |
MalwareMaze | Maze has checked the language of the machine with function |
| T1685 Disable or Modify Tools |
MalwareMaze | Maze has disabled dynamic analysis and other security tools including IDA debugger, x32dbg, and OllyDbg. It has also disabled Windows Defender's Real-Time Monitoring feature and attempted to disable endpoint protection services. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.