Real-world descriptions of how a group, tool or campaign used a technique.
21 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareFatDuke | FatDuke can copy files and directories from a compromised host. |
| T1008 Fallback Channels |
MalwareFatDuke | FatDuke has used several C2 servers per targeted organization. |
| T1012 Query Registry |
MalwareFatDuke | FatDuke can get user agent strings for the default browser from |
| T1016 System Network Configuration Discovery |
MalwareFatDuke | FatDuke can identify the MAC address on the target computer. |
| T1027 Obfuscated Files or Information |
MalwareFatDuke | FatDuke can use base64 encoding, string stacking, and opaque predicates for obfuscation. |
| T1027.002 Software Packing |
MalwareFatDuke | FatDuke has been regularly repacked by its operators to create large binaries and evade detection. |
| T1027.016 Junk Code Insertion |
MalwareFatDuke | FatDuke has been packed with junk code and strings. |
| T1036.012 Browser Fingerprint |
MalwareFatDuke | FatDuke has attempted to mimic a compromised user's traffic by using the same user agent as the installed browser. |
| T1057 Process Discovery |
MalwareFatDuke | FatDuke can list running processes on the localhost. |
| T1059.001 PowerShell |
MalwareFatDuke | FatDuke has the ability to execute PowerShell scripts. |
| T1070.004 File Deletion |
MalwareFatDuke | FatDuke can secure delete its DLL. |
| T1071.001 Web Protocols |
MalwareFatDuke | FatDuke can be controlled via a custom C2 protocol over HTTP. |
| T1082 System Information Discovery |
MalwareFatDuke | FatDuke can collect the user name, Windows version, computer name, and available space on discs from a compromised host. |
| T1083 File and Directory Discovery |
MalwareFatDuke | FatDuke can enumerate directories on target machines. |
| T1090.001 Internal Proxy |
MalwareFatDuke | FatDuke can used pipes to connect machines with restricted internet access to remote machines via other infected hosts. |
| T1106 Native API |
MalwareFatDuke | FatDuke can call |
| T1140 Deobfuscate/Decode Files or Information |
MalwareFatDuke | FatDuke can decrypt AES encrypted C2 communications. |
| T1218.011 Rundll32 |
MalwareFatDuke | FatDuke can execute via rundll32. |
| T1497.003 Time Based Checks |
MalwareFatDuke | FatDuke can turn itself on or off at random intervals. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFatDuke | FatDuke has used |
| T1573.001 Symmetric Cryptography |
MalwareFatDuke | FatDuke can AES encrypt C2 communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.