ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0482×

23 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareBundlore

Bundlore has obfuscated data with base64, AES, RC4, and bz2.

T1036.005
Match Legitimate Resource Name or Location
MalwareBundlore

Bundlore has disguised a malicious .app file as a Flash Player update.

T1048
Exfiltration Over Alternative Protocol
MalwareBundlore

Bundlore uses the curl -s -L -o command to exfiltrate archived data to a URL.

T1056.002
GUI Input Capture
MalwareBundlore

Bundlore prompts the user for their credentials.

T1057
Process Discovery
MalwareBundlore

Bundlore has used the ps command to list processes.

T1059.002
AppleScript
MalwareBundlore

Bundlore can use AppleScript to inject malicious JavaScript into a browser.

T1059.004
Unix Shell
MalwareBundlore

Bundlore has leveraged /bin/sh and /bin/bash to execute commands on the victim machine.

T1059.006
Python
MalwareBundlore

Bundlore has used Python scripts to execute payloads.

T1059.007
JavaScript
MalwareBundlore

Bundlore can execute JavaScript by injecting it into the victim's browser.

T1071.001
Web Protocols
MalwareBundlore

Bundlore uses HTTP requests for C2.

T1082
System Information Discovery
MalwareBundlore

Bundlore will enumerate the macOS version to determine which follow-on behaviors to execute using /usr/bin/sw_vers -productVersion.

T1098.004
SSH Authorized Keys
MalwareBundlore

Bundlore creates a new key pair with ssh-keygen and drops the newly created user key in authorized_keys to enable remote login.

T1105
Ingress Tool Transfer
MalwareBundlore

Bundlore can download and execute new versions of itself.

T1140
Deobfuscate/Decode Files or Information
MalwareBundlore

Bundlore has used openssl to decrypt AES encrypted payload data. Bundlore has also used base64 and RC4 with a hardcoded key to deobfuscate data.

T1176.001
Browser Extensions
MalwareBundlore

Bundlore can install malicious browser extensions that are used to hijack user searches.

T1189
Drive-by Compromise
MalwareBundlore

Bundlore has been spread through malicious advertisements on websites.

T1204.002
Malicious File
MalwareBundlore

Bundlore has attempted to get users to execute a malicious .app file that looks like a Flash Player update.

T1222.002
Linux and Mac Permissions
MalwareBundlore

Bundlore changes the permissions of a payload using the command chmod -R 755.

T1518
Software Discovery
MalwareBundlore

Bundlore has the ability to enumerate what browser is being used as well as version information for Safari.

T1543.001
Launch Agent
MalwareBundlore

Bundlore can persist via a LaunchAgent.

T1543.004
Launch Daemon
MalwareBundlore

Bundlore can persist via a LaunchDaemon.

T1564
Hide Artifacts
MalwareBundlore

Bundlore uses the mktemp utility to make unique file and directory names for payloads, such as TMP_DIR=`mktemp -d -t x.

T1685
Disable or Modify Tools
MalwareBundlore

Bundlore can change browser security settings to enable extensions to be installed. Bundlore uses the pkill cfprefsd command to prevent users from inspecting processes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.