Real-world descriptions of how a group, tool or campaign used a technique.
31 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareIcedID | IcedID used the `ipconfig /all` command and a batch script to gather network information. |
| T1027.002 Software Packing |
MalwareIcedID | IcedID has packed and encrypted its loader module. |
| T1027.003 Steganography |
MalwareIcedID | IcedID has embedded binaries within RC4 encrypted .png files. |
| T1027.009 Embedded Payloads |
MalwareIcedID | IcedID has embedded malicious functionality in a legitimate DLL file. |
| T1027.013 Encrypted/Encoded File |
MalwareIcedID | IcedID has utilzed encrypted binaries and base64 encoded strings. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareIcedID | IcedID has modified legitimate .dll files to include malicious code. |
| T1047 Windows Management Instrumentation |
MalwareIcedID | IcedID has used WMI to execute binaries. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
MalwareIcedID | IcedID has exfiltrated collected data via HTTPS. |
| T1053.005 Scheduled Task |
MalwareIcedID | IcedID has created a scheduled task to establish persistence. |
| T1055.004 Asynchronous Procedure Call |
MalwareIcedID | IcedID has used |
| T1055.012 Process Hollowing |
MalwareIcedID | IcedID can inject a Cobalt Strike beacon into cmd.exe via process hallowing. |
| T1059.005 Visual Basic |
MalwareIcedID | IcedID has used obfuscated VBA string expressions. |
| T1069 Permission Groups Discovery |
MalwareIcedID | IcedID has the ability to identify Workgroup membership. |
| T1071.001 Web Protocols |
MalwareIcedID | IcedID has used HTTPS in communications with C2. |
| T1082 System Information Discovery |
MalwareIcedID | IcedID has the ability to identify the computer name and OS version on a compromised host. |
| T1087.002 Domain Account |
MalwareIcedID | IcedID can query LDAP and can use built-in `net` commands to identify additional users on the network to infect. |
| T1105 Ingress Tool Transfer |
MalwareIcedID | IcedID has the ability to download additional modules and a configuration file from C2. |
| T1106 Native API |
MalwareIcedID | IcedID has called |
| T1135 Network Share Discovery |
MalwareIcedID | IcedID has used the `net view /all` command to show available shares. |
| T1185 Browser Session Hijacking |
MalwareIcedID | IcedID has used web injection attacks to redirect victims to spoofed sites designed to harvest banking and other credentials. IcedID can use a self signed TLS certificate in connection with the spoofed site and simultaneously maintains a live connection with the legitimate site to display the correct URL and certificates in the browser. |
| T1189 Drive-by Compromise |
MalwareIcedID | IcedID has cloned legitimate websites/applications to distribute the malware. |
| T1204.002 Malicious File |
MalwareIcedID | IcedID has been executed through Word and Excel files with malicious embedded macros and through ISO and LNK files that execute the malicious DLL. |
| T1218.007 Msiexec |
MalwareIcedID | IcedID can inject itself into a suspended msiexec.exe process to send beacons to C2 while appearing as a normal msi application. IcedID has also used msiexec.exe to deploy the IcedID loader. |
| T1218.011 Rundll32 |
MalwareIcedID | |
| T1482 Domain Trust Discovery |
MalwareIcedID | |
| T1497 Virtualization/Sandbox Evasion |
MalwareIcedID | IcedID has manipulated Keitaro Traffic Direction System to filter researcher and sandbox traffic. |
| T1518.001 Security Software Discovery |
MalwareIcedID | IcedID can identify AV products on an infected host using the following command: |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareIcedID | IcedID has established persistence by creating a Registry run key. |
| T1566.001 Spearphishing Attachment |
MalwareIcedID | IcedID has been delivered via phishing e-mails with malicious attachments. |
| T1573.002 Asymmetric Cryptography |
MalwareIcedID | IcedID has used SSL and TLS in communications with C2. |
| T1614.001 System Language Discovery |
MalwareIcedID | IcedID used the following command to check the country/language of the active console: |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.