ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0501×

23 examples

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwarePipeMon

PipeMon can switch to an alternate C2 domain when a particular date has been reached.

T1016
System Network Configuration Discovery
MalwarePipeMon

PipeMon can collect and send the local IP address, RDP information, and the network adapter physical address as a part of its C2 beacon.

T1027.011
Fileless Storage
MalwarePipeMon

PipeMon has stored its encrypted payload in the Registry under `HKLM\SOFTWARE\Microsoft\Print\Components\`.

T1027.013
Encrypted/Encoded File
MalwarePipeMon

PipeMon modules are stored encrypted on disk.

T1036.005
Match Legitimate Resource Name or Location
MalwarePipeMon

PipeMon modules are stored on disk with seemingly benign names including use of a file extension associated with a popular word processor.

T1055.001
Dynamic-link Library Injection
MalwarePipeMon

PipeMon can inject its modules into various processes using reflective DLL loading.

T1057
Process Discovery
MalwarePipeMon

PipeMon can iterate over the running processes to find a suitable injection target.

T1082
System Information Discovery
MalwarePipeMon

PipeMon can collect and send OS version and computer name as a part of its C2 beacon.

T1095
Non-Application Layer Protocol
MalwarePipeMon

The PipeMon communication module can use a custom protocol based on TLS over TCP.

T1105
Ingress Tool Transfer
MalwarePipeMon

PipeMon can install additional modules via C2 commands.

T1106
Native API
MalwarePipeMon

PipeMon's first stage has been executed by a call to CreateProcess with the decryption password in an argument. PipeMon has used a call to LoadLibrary to load its installer.

T1112
Modify Registry
MalwarePipeMon

PipeMon has modified the Registry to store its encrypted payload.

T1124
System Time Discovery
MalwarePipeMon

PipeMon can send time zone information from a compromised host to C2.

T1129
Shared Modules
MalwarePipeMon

PipeMon has used call to LoadLibrary to load its installer. PipeMon loads its modules using reflective loading or custom shellcode.

T1134.002
Create Process with Token
MalwarePipeMon

PipeMon can attempt to gain administrative privileges using token impersonation.

T1134.004
Parent PID Spoofing
MalwarePipeMon

PipeMon can use parent PID spoofing to elevate privileges.

T1140
Deobfuscate/Decode Files or Information
MalwarePipeMon

PipeMon can decrypt password-protected executables.

T1518.001
Security Software Discovery
MalwarePipeMon

PipeMon can check for the presence of ESET and Kaspersky security software.

T1543.003
Windows Service
MalwarePipeMon

PipeMon can establish persistence by registering a malicious DLL as an alternative Print Processor which is loaded when the print spooler service starts.

T1547.012
Print Processors
MalwarePipeMon

The PipeMon installer has modified the Registry key HKLM\SYSTEM\CurrentControlSet\Control\Print\Environments\Windows x64\Print Processors to install PipeMon as a Print Processor.

T1548.002
Bypass User Account Control
MalwarePipeMon

PipeMon installer can use UAC bypass techniques to install the payload.

T1553.002
Code Signing
MalwarePipeMon

PipeMon, its installer, and tools are signed with stolen code-signing certificates.

T1573.001
Symmetric Cryptography
MalwarePipeMon

PipeMon communications are RC4 encrypted.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.