ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0475×

16 examples

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
MalwareBackConfig

BackConfig has used compressed and decimal encoded VBS scripts.

T1036.005
Match Legitimate Resource Name or Location
MalwareBackConfig

BackConfig has hidden malicious payloads in %USERPROFILE%\Adobe\Driver\dwg\ and mimicked the legitimate DHCP service binary.

T1053.005
Scheduled Task
MalwareBackConfig

BackConfig has the ability to use scheduled tasks to repeatedly execute malicious payloads on a compromised host.

T1059.003
Windows Command Shell
MalwareBackConfig

BackConfig can download and run batch files to execute commands on a compromised host.

T1059.005
Visual Basic
MalwareBackConfig

BackConfig has used VBS to install its downloader component and malicious documents with VBA macro code.

T1070.004
File Deletion
MalwareBackConfig

BackConfig has the ability to remove files and folders related to previous infections.

T1071.001
Web Protocols
MalwareBackConfig

BackConfig has the ability to use HTTPS for C2 communiations.

T1082
System Information Discovery
MalwareBackConfig

BackConfig has the ability to gather the victim's computer name.

T1083
File and Directory Discovery
MalwareBackConfig

BackConfig has the ability to identify folders and files related to previous infections.

T1105
Ingress Tool Transfer
MalwareBackConfig

BackConfig can download and execute additional payloads on a compromised host.

T1106
Native API
MalwareBackConfig

BackConfig can leverage API functions such as ShellExecuteA and HttpOpenRequestA in the process of downloading and executing files.

T1137.001
Office Template Macros
MalwareBackConfig

BackConfig has the ability to use hidden columns in Excel spreadsheets to store executable files or commands for VBA macros.

T1140
Deobfuscate/Decode Files or Information
MalwareBackConfig

BackConfig has used a custom routine to decrypt strings.

T1204.001
Malicious Link
MalwareBackConfig

BackConfig has compromised victims via links to URLs hosting malicious content.

T1553.002
Code Signing
MalwareBackConfig

BackConfig has been signed with self signed digital certificates mimicking a legitimate software company.

T1564.001
Hidden Files and Directories
MalwareBackConfig

BackConfig has the ability to set folders or files to be hidden from the Windows Explorer default view.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.