ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0512×

21 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareFatDuke

FatDuke can copy files and directories from a compromised host.

T1008
Fallback Channels
MalwareFatDuke

FatDuke has used several C2 servers per targeted organization.

T1012
Query Registry
MalwareFatDuke

FatDuke can get user agent strings for the default browser from HKCU\Software\Classes\http\shell\open\command.

T1016
System Network Configuration Discovery
MalwareFatDuke

FatDuke can identify the MAC address on the target computer.

T1027
Obfuscated Files or Information
MalwareFatDuke

FatDuke can use base64 encoding, string stacking, and opaque predicates for obfuscation.

T1027.002
Software Packing
MalwareFatDuke

FatDuke has been regularly repacked by its operators to create large binaries and evade detection.

T1027.016
Junk Code Insertion
MalwareFatDuke

FatDuke has been packed with junk code and strings.

T1036.012
Browser Fingerprint
MalwareFatDuke

FatDuke has attempted to mimic a compromised user's traffic by using the same user agent as the installed browser.

T1057
Process Discovery
MalwareFatDuke

FatDuke can list running processes on the localhost.

T1059.001
PowerShell
MalwareFatDuke

FatDuke has the ability to execute PowerShell scripts.

T1070.004
File Deletion
MalwareFatDuke

FatDuke can secure delete its DLL.

T1071.001
Web Protocols
MalwareFatDuke

FatDuke can be controlled via a custom C2 protocol over HTTP.

T1082
System Information Discovery
MalwareFatDuke

FatDuke can collect the user name, Windows version, computer name, and available space on discs from a compromised host.

T1083
File and Directory Discovery
MalwareFatDuke

FatDuke can enumerate directories on target machines.

T1090.001
Internal Proxy
MalwareFatDuke

FatDuke can used pipes to connect machines with restricted internet access to remote machines via other infected hosts.

T1106
Native API
MalwareFatDuke

FatDuke can call ShellExecuteW to open the default browser on the URL localhost.

T1140
Deobfuscate/Decode Files or Information
MalwareFatDuke

FatDuke can decrypt AES encrypted C2 communications.

T1218.011
Rundll32
MalwareFatDuke

FatDuke can execute via rundll32.

T1497.003
Time Based Checks
MalwareFatDuke

FatDuke can turn itself on or off at random intervals.

T1547.001
Registry Run Keys / Startup Folder
MalwareFatDuke

FatDuke has used HKLM\SOFTWARE\Microsoft\CurrentVersion\Run to establish persistence.

T1573.001
Symmetric Cryptography
MalwareFatDuke

FatDuke can AES encrypt C2 communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.