ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0455×

46 examples

TechniqueUsed byProcedure example
T1010
Application Window Discovery
MalwareMetamorfo

Metamorfo can enumerate all windows on the victim’s machine.

T1027.002
Software Packing
MalwareMetamorfo

Metamorfo has used VMProtect to pack and protect files.

T1027.013
Encrypted/Encoded File
MalwareMetamorfo

Metamorfo has encrypted payloads and strings.

T1033
System Owner/User Discovery
MalwareMetamorfo

Metamorfo has collected the username from the victim's machine.

T1036.005
Match Legitimate Resource Name or Location
MalwareMetamorfo

Metamorfo has disguised an MSI file as the Adobe Acrobat Reader Installer and has masqueraded payloads as OneDrive, WhatsApp, or Spotify, for example.

T1041
Exfiltration Over C2 Channel
MalwareMetamorfo

Metamorfo can send the data it collects to the C2 server.

T1055.001
Dynamic-link Library Injection
MalwareMetamorfo

Metamorfo has injected a malicious DLL into the Windows Media Player process (wmplayer.exe).

T1056.001
Keylogging
MalwareMetamorfo

Metamorfo has a command to launch a keylogger and capture keystrokes on the victim’s machine.

T1056.002
GUI Input Capture
MalwareMetamorfo

Metamorfo has displayed fake forms on top of banking sites to intercept credentials from victims.

T1057
Process Discovery
MalwareMetamorfo

Metamorfo has performed process name checks and has monitored applications.

T1059.003
Windows Command Shell
MalwareMetamorfo

Metamorfo has used cmd.exe /c to execute files.

T1059.005
Visual Basic
MalwareMetamorfo

Metamorfo has used VBS code on victims’ systems.

T1059.007
JavaScript
MalwareMetamorfo

Metamorfo includes payloads written in JavaScript.

T1070
Indicator Removal
MalwareMetamorfo

Metamorfo has a command to delete a Registry key it uses, \Software\Microsoft\Internet Explorer\notes.

T1070.004
File Deletion
MalwareMetamorfo

Metamorfo has deleted itself from the system after execution.

T1071.001
Web Protocols
MalwareMetamorfo

Metamorfo has used HTTP for C2.

T1082
System Information Discovery
MalwareMetamorfo

Metamorfo has collected the hostname and operating system version from the compromised host.

T1083
File and Directory Discovery
MalwareMetamorfo

Metamorfo has searched the Program Files directories for specific folders and has searched for strings related to its mutexes.

T1095
Non-Application Layer Protocol
MalwareMetamorfo

Metamorfo has used raw TCP for C2.

T1102.001
Dead Drop Resolver
MalwareMetamorfo

Metamorfo has used YouTube to store and hide C&C server domains.

T1102.003
One-Way Communication
MalwareMetamorfo

Metamorfo has downloaded a zip file for execution on the system.

T1105
Ingress Tool Transfer
MalwareMetamorfo

Metamorfo has used MSI files to download additional files to execute.

T1106
Native API
MalwareMetamorfo

Metamorfo has used native WINAPI calls.

T1112
Modify Registry
MalwareMetamorfo

Metamorfo has written process names to the Registry, disabled IE browser features, deleted Registry keys, and changed the ExtendedUIHoverTime key.

T1113
Screen Capture
MalwareMetamorfo

Metamorfo can collect screenshots of the victim’s machine.

T1115
Clipboard Data
MalwareMetamorfo

Metamorfo has a function to hijack data from the clipboard by monitoring the contents of the clipboard and replacing the cryptocurrency wallet with the attacker's.

T1119
Automated Collection
MalwareMetamorfo

Metamorfo has automatically collected mouse clicks, continuous screenshots on the machine, and set timers to collect the contents of the clipboard and website browsing.

T1124
System Time Discovery
MalwareMetamorfo

Metamorfo uses JavaScript to get the system time.

T1129
Shared Modules
MalwareMetamorfo

Metamorfo had used AutoIt to load and execute the DLL payload.

T1140
Deobfuscate/Decode Files or Information
MalwareMetamorfo

Upon execution, Metamorfo has unzipped itself after being downloaded to the system and has performed string decryption.

T1204.002
Malicious File
MalwareMetamorfo

Metamorfo requires the user to double-click the executable to run the malicious HTA file or to download a malicious installer.

T1218.005
Mshta
MalwareMetamorfo

Metamorfo has used mshta.exe to execute a HTA payload.

T1218.007
Msiexec
MalwareMetamorfo

Metamorfo has used MsiExec.exe to automatically execute files.

T1497
Virtualization/Sandbox Evasion
MalwareMetamorfo

Metamorfo has embedded a "vmdetect.exe" executable to identify virtual machines at the beginning of execution.

T1518
Software Discovery
MalwareMetamorfo

Metamorfo has searched the compromised system for banking applications.

T1518.001
Security Software Discovery
MalwareMetamorfo

Metamorfo collects a list of installed antivirus software from the victim’s system.

T1547.001
Registry Run Keys / Startup Folder
MalwareMetamorfo

Metamorfo has configured persistence to the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run, Spotify =% APPDATA%\Spotify\Spotify.exe and used .LNK files in the startup folder to achieve persistence.

T1553.002
Code Signing
MalwareMetamorfo

Metamorfo has digitally signed executables using AVAST Software certificates.

T1564.003
Hidden Window
MalwareMetamorfo

Metamorfo has hidden its GUI using the ShowWindow() WINAPI call.

T1565.002
Transmitted Data Manipulation
MalwareMetamorfo

Metamorfo has a function that can watch the contents of the system clipboard for valid bitcoin addresses, which it then overwrites with the attacker's address.

T1566.001
Spearphishing Attachment
MalwareMetamorfo

Metamorfo has been delivered to victims via emails with malicious HTML attachments.

T1571
Non-Standard Port
MalwareMetamorfo

Metamorfo has communicated with hosts over raw TCP on port 9999.

T1573.001
Symmetric Cryptography
MalwareMetamorfo

Metamorfo has encrypted C2 commands with AES-256.

T1573.002
Asymmetric Cryptography
MalwareMetamorfo

Metamorfo's C2 communication has been encrypted using OpenSSL.

T1574.001
DLL
MalwareMetamorfo

Metamorfo has side-loaded its malicious DLL file.

T1685
Disable or Modify Tools
MalwareMetamorfo

Metamorfo has a function to kill processes associated with defenses and can prevent certain processes from launching.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.