ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0520×

22 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareBLINDINGCAN

BLINDINGCAN has uploaded files from victim machines.

T1016
System Network Configuration Discovery
MalwareBLINDINGCAN

BLINDINGCAN has collected the victim machine's local IP address information and MAC address.

T1027.002
Software Packing
MalwareBLINDINGCAN

BLINDINGCAN has been packed with the UPX packer.

T1027.013
Encrypted/Encoded File
MalwareBLINDINGCAN

BLINDINGCAN has obfuscated code using Base64 encoding.

T1036.005
Match Legitimate Resource Name or Location
MalwareBLINDINGCAN

BLINDINGCAN has attempted to hide its payload by using legitimate file names such as "iconcache.db".

T1041
Exfiltration Over C2 Channel
MalwareBLINDINGCAN

BLINDINGCAN has sent user and system information to a C2 server via HTTP POST requests.

T1059.003
Windows Command Shell
MalwareBLINDINGCAN

BLINDINGCAN has executed commands via cmd.exe.

T1070.004
File Deletion
MalwareBLINDINGCAN

BLINDINGCAN has deleted itself and associated artifacts from victim machines.

T1070.006
Timestomp
MalwareBLINDINGCAN

BLINDINGCAN has modified file and directory timestamps.

T1071.001
Web Protocols
MalwareBLINDINGCAN

BLINDINGCAN has used HTTPS over port 443 for command and control.

T1082
System Information Discovery
MalwareBLINDINGCAN

BLINDINGCAN has collected from a victim machine the system name, processor information, and OS version.

T1083
File and Directory Discovery
MalwareBLINDINGCAN

BLINDINGCAN can search, read, write, move, and execute files.

T1105
Ingress Tool Transfer
MalwareBLINDINGCAN

BLINDINGCAN has downloaded files to a victim machine.

T1129
Shared Modules
MalwareBLINDINGCAN

BLINDINGCAN has loaded and executed DLLs in memory during runtime on a victim machine.

T1132.001
Standard Encoding
MalwareBLINDINGCAN

BLINDINGCAN has encoded its C2 traffic with Base64.

T1140
Deobfuscate/Decode Files or Information
MalwareBLINDINGCAN

BLINDINGCAN has used AES and XOR to decrypt its DLLs.

T1204.002
Malicious File
MalwareBLINDINGCAN

BLINDINGCAN has lured victims into executing malicious macros embedded within Microsoft Office documents.

T1218.011
Rundll32
MalwareBLINDINGCAN

BLINDINGCAN has used Rundll32 to load a malicious DLL.

T1553.002
Code Signing
MalwareBLINDINGCAN

BLINDINGCAN has been signed with code-signing certificates such as CodeRipper.

T1566.001
Spearphishing Attachment
MalwareBLINDINGCAN

BLINDINGCAN has been delivered by phishing emails containing malicious Microsoft Office documents.

T1573.001
Symmetric Cryptography
MalwareBLINDINGCAN

BLINDINGCAN has encrypted its C2 traffic with RC4.

T1680
Local Storage Discovery
MalwareBLINDINGCAN

BLINDINGCAN has collected disk information, including type and free space available.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.