ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0453×

16 examples

TechniqueUsed byProcedure example
T1027.015
Compression
MalwarePony

Pony attachments have been delivered via compressed archive files.

T1027.016
Junk Code Insertion
MalwarePony

Pony obfuscates memory flow by adding junk instructions when executing to make analysis more difficult.

T1036
Masquerading
MalwarePony

Pony has used the Adobe Reader icon for the downloaded file to look more trustworthy.

T1059.003
Windows Command Shell
MalwarePony

Pony has used batch scripts to delete itself after execution.

T1070.004
File Deletion
MalwarePony

Pony has used scripts to delete itself after execution.

T1071.001
Web Protocols
MalwarePony

Pony has sent collected information to the C2 via HTTP POST request.

T1082
System Information Discovery
MalwarePony

Pony has collected the Service Pack, language, and region information to send to the C2.

T1087.001
Local Account
MalwarePony

Pony has used the NetUserEnum function to enumerate local accounts.

T1105
Ingress Tool Transfer
MalwarePony

Pony can download additional files onto the infected system.

T1106
Native API
MalwarePony

Pony has used several Windows functions for various purposes.

T1110.001
Password Guessing
MalwarePony

Pony has used a small dictionary of common passwords against a collected list of local accounts.

T1204.001
Malicious Link
MalwarePony

Pony has attempted to lure targets into clicking links in spoofed emails from legitimate banks.

T1204.002
Malicious File
MalwarePony

Pony has attempted to lure targets into downloading an attached executable (ZIP, RAR, or CAB archives) or document (PDF or other MS Office format).

T1497.003
Time Based Checks
MalwarePony

Pony has delayed execution using a built-in function to avoid detection and analysis.

T1566.001
Spearphishing Attachment
MalwarePony

Pony has been delivered via spearphishing attachments.

T1566.002
Spearphishing Link
MalwarePony

Pony has been delivered via spearphishing emails which contained malicious links.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.