ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0458×

39 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareRamsay

Ramsay can collect Microsoft Word documents from the target's file system, as well as .txt, .doc, and .xls files from the Internet Explorer cache.

T1014
Rootkit
MalwareRamsay

Ramsay has included a rootkit to evade defenses.

T1016
System Network Configuration Discovery
MalwareRamsay

Ramsay can use ipconfig and Arp to collect network configuration information, including routing information and ARP tables.

T1025
Data from Removable Media
MalwareRamsay

Ramsay can collect data from removable media and stage it for exfiltration.

T1027
Obfuscated Files or Information
MalwareRamsay

Ramsay has base64-encoded its portable executable and hidden itself under a JPG header. Ramsay can also embed information within document footers.

T1027.003
Steganography
MalwareRamsay

Ramsay has PE data embedded within JPEG files contained within Word documents.

T1036
Masquerading
MalwareRamsay

Ramsay has masqueraded as a JPG image file.

T1036.005
Match Legitimate Resource Name or Location
MalwareRamsay

Ramsay has masqueraded as a 7zip installer.

T1039
Data from Network Shared Drive
MalwareRamsay

Ramsay can collect data from network drives and stage it for exfiltration.

T1046
Network Service Discovery
MalwareRamsay

Ramsay can scan for systems that are vulnerable to the EternalBlue exploit.

T1049
System Network Connections Discovery
MalwareRamsay

Ramsay can use netstat to enumerate network connections.

T1053.005
Scheduled Task
MalwareRamsay

Ramsay can schedule tasks via the Windows COM API to maintain persistence.

T1055.001
Dynamic-link Library Injection
MalwareRamsay

Ramsay can use ImprovedReflectiveDLLInjection to deploy components.

T1057
Process Discovery
MalwareRamsay

Ramsay can gather a list of running processes by using Tasklist.

T1059.005
Visual Basic
MalwareRamsay

Ramsay has included embedded Visual Basic scripts in malicious documents.

T1071.001
Web Protocols
MalwareRamsay

Ramsay has used HTTP for C2.

T1074.001
Local Data Staging
MalwareRamsay

Ramsay can stage data prior to exfiltration in %APPDATA%\Microsoft\UserSetting and %APPDATA%\Microsoft\UserSetting\MediaCache.

T1080
Taint Shared Content
MalwareRamsay

Ramsay can spread itself by infecting other portable executable files on networks shared drives.

T1083
File and Directory Discovery
MalwareRamsay

Ramsay can collect directory and file lists.

T1091
Replication Through Removable Media
MalwareRamsay

Ramsay can spread itself by infecting other portable executable files on removable drives.

T1106
Native API
MalwareRamsay

Ramsay can use Windows API functions such as WriteFile, CloseHandle, and GetCurrentHwProfile during its collection and file storage operations. Ramsay can execute its embedded components via CreateProcessA and ShellExecute.

T1113
Screen Capture
MalwareRamsay

Ramsay can take screenshots every 30 seconds as well as when an external removable storage device is connected.

T1119
Automated Collection
MalwareRamsay

Ramsay can conduct an initial scan for Microsoft Word documents on the local system, removable media, and connected network drives, before tagging and collecting them. It can continue tagging documents to collect with follow up scans.

T1120
Peripheral Device Discovery
MalwareRamsay

Ramsay can scan for removable media which may contain documents for collection.

T1132.001
Standard Encoding
MalwareRamsay

Ramsay has used base64 to encode its C2 traffic.

T1135
Network Share Discovery
MalwareRamsay

Ramsay can scan for network drives which may contain documents for collection.

T1140
Deobfuscate/Decode Files or Information
MalwareRamsay

Ramsay can extract its agent from the body of a malicious document.

T1203
Exploitation for Client Execution
MalwareRamsay

Ramsay has been embedded in documents exploiting CVE-2017-0199, CVE-2017-11882, and CVE-2017-8570.

T1204.002
Malicious File
MalwareRamsay

Ramsay has been executed through malicious e-mail attachments.

T1546.010
AppInit DLLs
MalwareRamsay

Ramsay can insert itself into the address space of other applications using the AppInit DLL Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareRamsay

Ramsay has created Registry Run keys to establish persistence.

T1548.002
Bypass User Account Control
MalwareRamsay

Ramsay can use UACMe for privilege escalation.

T1559.001
Component Object Model
MalwareRamsay

Ramsay can use the Windows COM API to schedule tasks and maintain persistence.

T1559.002
Dynamic Data Exchange
MalwareRamsay

Ramsay has been delivered using OLE objects in malicious documents.

T1560.001
Archive via Utility
MalwareRamsay

Ramsay can compress and archive collected files using WinRAR.

T1560.003
Archive via Custom Method
MalwareRamsay

Ramsay can store collected documents in a custom container after encrypting and compressing them using RC4 and WinRAR.

T1566.001
Spearphishing Attachment
MalwareRamsay

Ramsay has been distributed through spearphishing emails with malicious attachments.

T1574.001
DLL
MalwareRamsay

Ramsay can hijack outdated Windows application dependencies with malicious versions of its own DLL payload.

T1680
Local Storage Discovery
MalwareRamsay

Ramsay can detect system information--including disk names, total space, and remaining space--to create a hardware profile GUID which acts as a system identifier for operators.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.