Real-world descriptions of how a group, tool or campaign used a technique.
35 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareREvil | REvil can enumerate active services. |
| T1012 Query Registry |
MalwareREvil | REvil can query the Registry to get random file extensions to append to encrypted files. |
| T1027.011 Fileless Storage |
MalwareREvil | REvil can save encryption parameters and system information in the Registry. |
| T1027.013 Encrypted/Encoded File |
MalwareREvil | REvil has used encrypted strings and configuration files. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareREvil | REvil can mimic the names of known executables. |
| T1041 Exfiltration Over C2 Channel |
MalwareREvil | REvil can exfiltrate host and malware information to C2 servers. |
| T1047 Windows Management Instrumentation |
MalwareREvil | REvil can use WMI to monitor for and kill specific processes listed in its configuration file. |
| T1055 Process Injection |
MalwareREvil | REvil can inject itself into running processes on a compromised host. |
| T1059.001 PowerShell |
MalwareREvil | REvil has used PowerShell to delete volume shadow copies and download files. |
| T1059.003 Windows Command Shell |
MalwareREvil | REvil can use the Windows command line to delete volume shadow copies and disable recovery. |
| T1059.005 Visual Basic |
MalwareREvil | REvil has used obfuscated VBA macros for execution. |
| T1069.002 Domain Groups |
MalwareREvil | REvil can identify the domain membership of a compromised host. |
| T1070.004 File Deletion |
MalwareREvil | REvil can mark its binary code for deletion after reboot. |
| T1071.001 Web Protocols |
MalwareREvil | REvil has used HTTP and HTTPS in communication with C2. |
| T1082 System Information Discovery |
MalwareREvil | REvil can identify the username, machine name, system language, keyboard layout, and OS version on a compromised host. |
| T1083 File and Directory Discovery |
MalwareREvil | REvil has the ability to identify specific files and directories that are not to be encrypted. |
| T1105 Ingress Tool Transfer |
MalwareREvil | REvil can download a copy of itself from an attacker controlled IP address to the victim machine. |
| T1106 Native API |
MalwareREvil | REvil can use Native API for execution and to retrieve active services. |
| T1112 Modify Registry |
MalwareREvil | REvil can modify the Registry to save encryption parameters and system information. |
| T1134.001 Token Impersonation/Theft |
MalwareREvil | REvil can obtain the token from the user that launched the explorer.exe process to avoid affecting the desktop of the SYSTEM user. |
| T1134.002 Create Process with Token |
MalwareREvil | REvil can launch an instance of itself with administrative rights using runas. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareREvil | REvil can decode encrypted strings to enable execution of commands and payloads. |
| T1189 Drive-by Compromise |
MalwareREvil | REvil has infected victim machines through compromised websites and exploit kits. |
| T1204.002 Malicious File |
MalwareREvil | REvil has been executed via malicious MS Word e-mail attachments. |
| T1480.002 Mutual Exclusion |
MalwareREvil | REvil attempts to create a mutex using a hard-coded value to ensure that no other instances of itself are running on the host. |
| T1485 Data Destruction |
MalwareREvil | REvil has the capability to destroy files and folders. |
| T1486 Data Encrypted for Impact |
MalwareREvil | REvil can encrypt files on victim systems and demands a ransom to decrypt the files. |
| T1489 Service Stop |
MalwareREvil | REvil has the capability to stop services and kill processes. |
| T1490 Inhibit System Recovery |
MalwareREvil | REvil can use vssadmin to delete volume shadow copies and bcdedit to disable recovery features. |
| T1566.001 Spearphishing Attachment |
MalwareREvil | REvil has been distributed via malicious e-mail attachments including MS Word Documents. |
| T1573.002 Asymmetric Cryptography |
MalwareREvil | REvil has encrypted C2 communications with the ECIES algorithm. |
| T1614.001 System Language Discovery |
MalwareREvil | REvil can check the system language using |
| T1680 Local Storage Discovery |
MalwareREvil | REvil can identify system drive information on a compromised host. |
| T1685 Disable or Modify Tools |
MalwareREvil | REvil can connect to and disable the Symantec server on the victim's network. |
| T1688 Safe Mode Boot |
MalwareREvil | REvil can force a reboot in safe mode with networking. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.