ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0496×

35 examples

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareREvil

REvil can enumerate active services.

T1012
Query Registry
MalwareREvil

REvil can query the Registry to get random file extensions to append to encrypted files.

T1027.011
Fileless Storage
MalwareREvil

REvil can save encryption parameters and system information in the Registry.

T1027.013
Encrypted/Encoded File
MalwareREvil

REvil has used encrypted strings and configuration files.

T1036.005
Match Legitimate Resource Name or Location
MalwareREvil

REvil can mimic the names of known executables.

T1041
Exfiltration Over C2 Channel
MalwareREvil

REvil can exfiltrate host and malware information to C2 servers.

T1047
Windows Management Instrumentation
MalwareREvil

REvil can use WMI to monitor for and kill specific processes listed in its configuration file.

T1055
Process Injection
MalwareREvil

REvil can inject itself into running processes on a compromised host.

T1059.001
PowerShell
MalwareREvil

REvil has used PowerShell to delete volume shadow copies and download files.

T1059.003
Windows Command Shell
MalwareREvil

REvil can use the Windows command line to delete volume shadow copies and disable recovery.

T1059.005
Visual Basic
MalwareREvil

REvil has used obfuscated VBA macros for execution.

T1069.002
Domain Groups
MalwareREvil

REvil can identify the domain membership of a compromised host.

T1070.004
File Deletion
MalwareREvil

REvil can mark its binary code for deletion after reboot.

T1071.001
Web Protocols
MalwareREvil

REvil has used HTTP and HTTPS in communication with C2.

T1082
System Information Discovery
MalwareREvil

REvil can identify the username, machine name, system language, keyboard layout, and OS version on a compromised host.

T1083
File and Directory Discovery
MalwareREvil

REvil has the ability to identify specific files and directories that are not to be encrypted.

T1105
Ingress Tool Transfer
MalwareREvil

REvil can download a copy of itself from an attacker controlled IP address to the victim machine.

T1106
Native API
MalwareREvil

REvil can use Native API for execution and to retrieve active services.

T1112
Modify Registry
MalwareREvil

REvil can modify the Registry to save encryption parameters and system information.

T1134.001
Token Impersonation/Theft
MalwareREvil

REvil can obtain the token from the user that launched the explorer.exe process to avoid affecting the desktop of the SYSTEM user.

T1134.002
Create Process with Token
MalwareREvil

REvil can launch an instance of itself with administrative rights using runas.

T1140
Deobfuscate/Decode Files or Information
MalwareREvil

REvil can decode encrypted strings to enable execution of commands and payloads.

T1189
Drive-by Compromise
MalwareREvil

REvil has infected victim machines through compromised websites and exploit kits.

T1204.002
Malicious File
MalwareREvil

REvil has been executed via malicious MS Word e-mail attachments.

T1480.002
Mutual Exclusion
MalwareREvil

REvil attempts to create a mutex using a hard-coded value to ensure that no other instances of itself are running on the host.

T1485
Data Destruction
MalwareREvil

REvil has the capability to destroy files and folders.

T1486
Data Encrypted for Impact
MalwareREvil

REvil can encrypt files on victim systems and demands a ransom to decrypt the files.

T1489
Service Stop
MalwareREvil

REvil has the capability to stop services and kill processes.

T1490
Inhibit System Recovery
MalwareREvil

REvil can use vssadmin to delete volume shadow copies and bcdedit to disable recovery features.

T1566.001
Spearphishing Attachment
MalwareREvil

REvil has been distributed via malicious e-mail attachments including MS Word Documents.

T1573.002
Asymmetric Cryptography
MalwareREvil

REvil has encrypted C2 communications with the ECIES algorithm.

T1614.001
System Language Discovery
MalwareREvil

REvil can check the system language using GetUserDefaultUILanguage and GetSystemDefaultUILanguage. If the language is found in the list, the process terminates.

T1680
Local Storage Discovery
MalwareREvil

REvil can identify system drive information on a compromised host.

T1685
Disable or Modify Tools
MalwareREvil

REvil can connect to and disable the Symantec server on the victim's network.

T1688
Safe Mode Boot
MalwareREvil

REvil can force a reboot in safe mode with networking.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.