ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0483×

31 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareIcedID

IcedID used the `ipconfig /all` command and a batch script to gather network information.

T1027.002
Software Packing
MalwareIcedID

IcedID has packed and encrypted its loader module.

T1027.003
Steganography
MalwareIcedID

IcedID has embedded binaries within RC4 encrypted .png files.

T1027.009
Embedded Payloads
MalwareIcedID

IcedID has embedded malicious functionality in a legitimate DLL file.

T1027.013
Encrypted/Encoded File
MalwareIcedID

IcedID has utilzed encrypted binaries and base64 encoded strings.

T1036.005
Match Legitimate Resource Name or Location
MalwareIcedID

IcedID has modified legitimate .dll files to include malicious code.

T1047
Windows Management Instrumentation
MalwareIcedID

IcedID has used WMI to execute binaries.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
MalwareIcedID

IcedID has exfiltrated collected data via HTTPS.

T1053.005
Scheduled Task
MalwareIcedID

IcedID has created a scheduled task to establish persistence.

T1055.004
Asynchronous Procedure Call
MalwareIcedID

IcedID has used ZwQueueApcThread to inject itself into remote processes.

T1055.012
Process Hollowing
MalwareIcedID

IcedID can inject a Cobalt Strike beacon into cmd.exe via process hallowing.

T1059.005
Visual Basic
MalwareIcedID

IcedID has used obfuscated VBA string expressions.

T1069
Permission Groups Discovery
MalwareIcedID

IcedID has the ability to identify Workgroup membership.

T1071.001
Web Protocols
MalwareIcedID

IcedID has used HTTPS in communications with C2.

T1082
System Information Discovery
MalwareIcedID

IcedID has the ability to identify the computer name and OS version on a compromised host.

T1087.002
Domain Account
MalwareIcedID

IcedID can query LDAP and can use built-in `net` commands to identify additional users on the network to infect.

T1105
Ingress Tool Transfer
MalwareIcedID

IcedID has the ability to download additional modules and a configuration file from C2.

T1106
Native API
MalwareIcedID

IcedID has called ZwWriteVirtualMemory, ZwProtectVirtualMemory, ZwQueueApcThread, and NtResumeThread to inject itself into a remote process.

T1135
Network Share Discovery
MalwareIcedID

IcedID has used the `net view /all` command to show available shares.

T1185
Browser Session Hijacking
MalwareIcedID

IcedID has used web injection attacks to redirect victims to spoofed sites designed to harvest banking and other credentials. IcedID can use a self signed TLS certificate in connection with the spoofed site and simultaneously maintains a live connection with the legitimate site to display the correct URL and certificates in the browser.

T1189
Drive-by Compromise
MalwareIcedID

IcedID has cloned legitimate websites/applications to distribute the malware.

T1204.002
Malicious File
MalwareIcedID

IcedID has been executed through Word and Excel files with malicious embedded macros and through ISO and LNK files that execute the malicious DLL.

T1218.007
Msiexec
MalwareIcedID

IcedID can inject itself into a suspended msiexec.exe process to send beacons to C2 while appearing as a normal msi application. IcedID has also used msiexec.exe to deploy the IcedID loader.

T1218.011
Rundll32
MalwareIcedID

IcedID has used rundll32.exe to execute the IcedID loader.

T1482
Domain Trust Discovery
MalwareIcedID

IcedID used Nltest during initial discovery.

T1497
Virtualization/Sandbox Evasion
MalwareIcedID

IcedID has manipulated Keitaro Traffic Direction System to filter researcher and sandbox traffic.

T1518.001
Security Software Discovery
MalwareIcedID

IcedID can identify AV products on an infected host using the following command:
` WMIC.exe WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get * /Format:List`.

T1547.001
Registry Run Keys / Startup Folder
MalwareIcedID

IcedID has established persistence by creating a Registry run key.

T1566.001
Spearphishing Attachment
MalwareIcedID

IcedID has been delivered via phishing e-mails with malicious attachments.

T1573.002
Asymmetric Cryptography
MalwareIcedID

IcedID has used SSL and TLS in communications with C2.

T1614.001
System Language Discovery
MalwareIcedID

IcedID used the following command to check the country/language of the active console:
` cmd.exe /c chcp >&2`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.