ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0491×

26 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareStrongPity

StrongPity can identify the IP address of a compromised host.

T1020
Automated Exfiltration
MalwareStrongPity

StrongPity can automatically exfiltrate collected documents to the C2 server.

T1027.013
Encrypted/Encoded File
MalwareStrongPity

StrongPity has used encrypted strings in its dropper component.

T1036.004
Masquerade Task or Service
MalwareStrongPity

StrongPity has named services to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
MalwareStrongPity

StrongPity has been bundled with legitimate software installation files for disguise.

T1041
Exfiltration Over C2 Channel
MalwareStrongPity

StrongPity can exfiltrate collected documents through C2 channels.

T1057
Process Discovery
MalwareStrongPity

StrongPity can determine if a user is logged in by checking to see if explorer.exe is running.

T1059.001
PowerShell
MalwareStrongPity

StrongPity can use PowerShell to add files to the Windows Defender exclusions list.

T1070.004
File Deletion
MalwareStrongPity

StrongPity can delete previously exfiltrated files from the compromised host.

T1071.001
Web Protocols
MalwareStrongPity

StrongPity can use HTTP and HTTPS in C2 communications.

T1083
File and Directory Discovery
MalwareStrongPity

StrongPity can parse the hard drive on a compromised host to identify specific file extensions.

T1090.003
Multi-hop Proxy
MalwareStrongPity

StrongPity can use multiple layers of proxy servers to hide terminal nodes in its infrastructure.

T1105
Ingress Tool Transfer
MalwareStrongPity

StrongPity can download files to specified targets.

T1119
Automated Collection
MalwareStrongPity

StrongPity has a file searcher component that can automatically collect and archive files based on a predefined list of file extensions.

T1204.002
Malicious File
MalwareStrongPity

StrongPity has been executed via compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities.

T1518.001
Security Software Discovery
MalwareStrongPity

StrongPity can identify if ESET or BitDefender antivirus are installed before dropping its payload.

T1543.003
Windows Service
MalwareStrongPity

StrongPity has created new services and modified existing services for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareStrongPity

StrongPity can use the HKCU\Software\Microsoft\Windows\CurrentVersion\Run Registry key for persistence.

T1553.002
Code Signing
MalwareStrongPity

StrongPity has been signed with self-signed certificates.

T1560.003
Archive via Custom Method
MalwareStrongPity

StrongPity can compress and encrypt archived files into multiple .sft files with a repeated xor encryption scheme.

T1564.003
Hidden Window
MalwareStrongPity

StrongPity has the ability to hide the console window for its document search module from the user.

T1569.002
Service Execution
MalwareStrongPity

StrongPity can install a service to execute itself as a service.

T1571
Non-Standard Port
MalwareStrongPity

StrongPity has used HTTPS over port 1402 in C2 communication.

T1573.002
Asymmetric Cryptography
MalwareStrongPity

StrongPity has encrypted C2 traffic using SSL/TLS.

T1680
Local Storage Discovery
MalwareStrongPity

StrongPity can identify the hard disk volume serial number on a compromised host.

T1685
Disable or Modify Tools
MalwareStrongPity

StrongPity can add directories used by the malware to the Windows Defender exclusions list to prevent detection.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.