Real-world descriptions of how a group, tool or campaign used a technique.
39 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareRamsay | Ramsay can collect Microsoft Word documents from the target's file system, as well as |
| T1014 Rootkit |
MalwareRamsay | Ramsay has included a rootkit to evade defenses. |
| T1016 System Network Configuration Discovery |
MalwareRamsay | Ramsay can use ipconfig and Arp to collect network configuration information, including routing information and ARP tables. |
| T1025 Data from Removable Media |
MalwareRamsay | Ramsay can collect data from removable media and stage it for exfiltration. |
| T1027 Obfuscated Files or Information |
MalwareRamsay | Ramsay has base64-encoded its portable executable and hidden itself under a JPG header. Ramsay can also embed information within document footers. |
| T1027.003 Steganography |
MalwareRamsay | Ramsay has PE data embedded within JPEG files contained within Word documents. |
| T1036 Masquerading |
MalwareRamsay | Ramsay has masqueraded as a JPG image file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRamsay | Ramsay has masqueraded as a 7zip installer. |
| T1039 Data from Network Shared Drive |
MalwareRamsay | Ramsay can collect data from network drives and stage it for exfiltration. |
| T1046 Network Service Discovery |
MalwareRamsay | Ramsay can scan for systems that are vulnerable to the EternalBlue exploit. |
| T1049 System Network Connections Discovery |
MalwareRamsay | Ramsay can use |
| T1053.005 Scheduled Task |
MalwareRamsay | Ramsay can schedule tasks via the Windows COM API to maintain persistence. |
| T1055.001 Dynamic-link Library Injection |
MalwareRamsay | Ramsay can use |
| T1057 Process Discovery |
MalwareRamsay | Ramsay can gather a list of running processes by using Tasklist. |
| T1059.005 Visual Basic |
MalwareRamsay | Ramsay has included embedded Visual Basic scripts in malicious documents. |
| T1071.001 Web Protocols |
MalwareRamsay | Ramsay has used HTTP for C2. |
| T1074.001 Local Data Staging |
MalwareRamsay | Ramsay can stage data prior to exfiltration in |
| T1080 Taint Shared Content |
MalwareRamsay | Ramsay can spread itself by infecting other portable executable files on networks shared drives. |
| T1083 File and Directory Discovery |
MalwareRamsay | Ramsay can collect directory and file lists. |
| T1091 Replication Through Removable Media |
MalwareRamsay | Ramsay can spread itself by infecting other portable executable files on removable drives. |
| T1106 Native API |
MalwareRamsay | Ramsay can use Windows API functions such as |
| T1113 Screen Capture |
MalwareRamsay | Ramsay can take screenshots every 30 seconds as well as when an external removable storage device is connected. |
| T1119 Automated Collection |
MalwareRamsay | Ramsay can conduct an initial scan for Microsoft Word documents on the local system, removable media, and connected network drives, before tagging and collecting them. It can continue tagging documents to collect with follow up scans. |
| T1120 Peripheral Device Discovery |
MalwareRamsay | Ramsay can scan for removable media which may contain documents for collection. |
| T1132.001 Standard Encoding |
MalwareRamsay | Ramsay has used base64 to encode its C2 traffic. |
| T1135 Network Share Discovery |
MalwareRamsay | Ramsay can scan for network drives which may contain documents for collection. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRamsay | Ramsay can extract its agent from the body of a malicious document. |
| T1203 Exploitation for Client Execution |
MalwareRamsay | Ramsay has been embedded in documents exploiting CVE-2017-0199, CVE-2017-11882, and CVE-2017-8570. |
| T1204.002 Malicious File |
MalwareRamsay | Ramsay has been executed through malicious e-mail attachments. |
| T1546.010 AppInit DLLs |
MalwareRamsay | Ramsay can insert itself into the address space of other applications using the AppInit DLL Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRamsay | Ramsay has created Registry Run keys to establish persistence. |
| T1548.002 Bypass User Account Control |
MalwareRamsay | |
| T1559.001 Component Object Model |
MalwareRamsay | Ramsay can use the Windows COM API to schedule tasks and maintain persistence. |
| T1559.002 Dynamic Data Exchange |
MalwareRamsay | Ramsay has been delivered using OLE objects in malicious documents. |
| T1560.001 Archive via Utility |
MalwareRamsay | Ramsay can compress and archive collected files using WinRAR. |
| T1560.003 Archive via Custom Method |
MalwareRamsay | Ramsay can store collected documents in a custom container after encrypting and compressing them using RC4 and WinRAR. |
| T1566.001 Spearphishing Attachment |
MalwareRamsay | Ramsay has been distributed through spearphishing emails with malicious attachments. |
| T1574.001 DLL |
MalwareRamsay | Ramsay can hijack outdated Windows application dependencies with malicious versions of its own DLL payload. |
| T1680 Local Storage Discovery |
MalwareRamsay | Ramsay can detect system information--including disk names, total space, and remaining space--to create a hardware profile GUID which acts as a system identifier for operators. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.