ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0476×

34 examples

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareValak

Valak can communicate over multiple C2 hosts.

T1012
Query Registry
MalwareValak

Valak can use the Registry for code updates and to collect credentials.

T1016
System Network Configuration Discovery
MalwareValak

Valak has the ability to identify the domain and the MAC and IP addresses of an infected machine.

T1027
Obfuscated Files or Information
MalwareValak

Valak has the ability to base64 encode and XOR encrypt strings.

T1027.002
Software Packing
MalwareValak

Valak has used packed DLL payloads.

T1027.011
Fileless Storage
MalwareValak

Valak has the ability to store information regarding the C2 server and downloads in the Registry key HKCU\Software\ApplicationContainer\Appsw64.

T1033
System Owner/User Discovery
MalwareValak

Valak can gather information regarding the user.

T1041
Exfiltration Over C2 Channel
MalwareValak

Valak has the ability to exfiltrate data over the C2 channel.

T1047
Windows Management Instrumentation
MalwareValak

Valak can use wmic process call create in a scheduled task to launch plugins and for execution.

T1053.005
Scheduled Task
MalwareValak

Valak has used scheduled tasks to execute additional payloads and to gain persistence on a compromised host.

T1057
Process Discovery
MalwareValak

Valak has the ability to enumerate running processes on a compromised host.

T1059.001
PowerShell
MalwareValak

Valak has used PowerShell to download additional modules.

T1059.007
JavaScript
MalwareValak

Valak can execute JavaScript containing configuration data for establishing persistence.

T1071.001
Web Protocols
MalwareValak

Valak has used HTTP in communications with C2.

T1082
System Information Discovery
MalwareValak

Valak can determine the Windows version and computer name on a compromised host.

T1087.001
Local Account
MalwareValak

Valak has the ability to enumerate local admin accounts.

T1087.002
Domain Account
MalwareValak

Valak has the ability to enumerate domain admin accounts.

T1104
Multi-Stage Channels
MalwareValak

Valak can download additional modules and malware capable of using separate C2 channels.

T1105
Ingress Tool Transfer
MalwareValak

Valak has downloaded a variety of modules and payloads to the compromised host, including IcedID and NetSupport Manager RAT-based malware.

T1112
Modify Registry
MalwareValak

Valak has the ability to modify the Registry key HKCU\Software\ApplicationContainer\Appsw64 to store information regarding the C2 server and downloads.

T1113
Screen Capture
MalwareValak

Valak has the ability to take screenshots on a compromised host.

T1114.002
Remote Email Collection
MalwareValak

Valak can collect sensitive mailing information from Exchange servers, including credentials and the domain certificate of an enterprise.

T1119
Automated Collection
MalwareValak

Valak can download a module to search for and build a report of harvested credential data.

T1132.001
Standard Encoding
MalwareValak

Valak has returned C2 data as encoded ASCII.

T1140
Deobfuscate/Decode Files or Information
MalwareValak

Valak has the ability to decode and decrypt downloaded files.

T1204.002
Malicious File
MalwareValak

Valak has been executed via Microsoft Word documents containing malicious macros.

T1218.010
Regsvr32
MalwareValak

Valak has used regsvr32.exe to launch malicious DLLs.

T1518.001
Security Software Discovery
MalwareValak

Valak can determine if a compromised host has security products installed.

T1552.002
Credentials in Registry
MalwareValak

Valak can use the clientgrabber module to steal e-mail credentials from the Registry.

T1555.004
Windows Credential Manager
MalwareValak

Valak can use a .NET compiled module named exchgrabber to enumerate credentials from the Credential Manager.

T1559.002
Dynamic Data Exchange
MalwareValak

Valak can execute tasks via OLE.

T1564.004
NTFS File Attributes
MalwareValak

Valak has the ability save and execute files as alternate data streams (ADS).

T1566.001
Spearphishing Attachment
MalwareValak

Valak has been delivered via spearphishing e-mails with password protected ZIP files.

T1566.002
Spearphishing Link
MalwareValak

Valak has been delivered via malicious links in e-mail.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.