ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0532×

24 examples

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareLucifer

Lucifer can check for existing stratum cryptomining information in HKLM\Software\Microsoft\Windows\CurrentVersion\spreadCpuXmr – %stratum info%.

T1016
System Network Configuration Discovery
MalwareLucifer

Lucifer can collect the IP address of a compromised host.

T1021.002
SMB/Windows Admin Shares
MalwareLucifer

Lucifer can infect victims by brute forcing SMB.

T1027.002
Software Packing
MalwareLucifer

Lucifer has used UPX packed binaries.

T1033
System Owner/User Discovery
MalwareLucifer

Lucifer has the ability to identify the username on a compromised host.

T1046
Network Service Discovery
MalwareLucifer

Lucifer can scan for open ports including TCP ports 135 and 1433.

T1047
Windows Management Instrumentation
MalwareLucifer

Lucifer can use WMI to log into remote machines for propagation.

T1049
System Network Connections Discovery
MalwareLucifer

Lucifer can identify the IP and port numbers for all remote connections from the compromised host.

T1053.005
Scheduled Task
MalwareLucifer

Lucifer has established persistence by creating the following scheduled task schtasks /create /sc minute /mo 1 /tn QQMusic ^ /tr C:Users\%USERPROFILE%\Downloads\spread.exe /F.

T1057
Process Discovery
MalwareLucifer

Lucifer can identify the process that owns remote connections.

T1059.003
Windows Command Shell
MalwareLucifer

Lucifer can issue shell commands to download and execute additional payloads.

T1071
Application Layer Protocol
MalwareLucifer

Lucifer can use the Stratum protocol on port 10001 for communication between the cryptojacking bot and the mining server.

T1082
System Information Discovery
MalwareLucifer

Lucifer can collect the computer name, system architecture, default language, and processor frequency of a compromised host.

T1105
Ingress Tool Transfer
MalwareLucifer

Lucifer can download and execute a replica of itself using certutil.

T1110.001
Password Guessing
MalwareLucifer

Lucifer has attempted to brute force TCP ports 135 (RPC) and 1433 (MSSQL) with the default username or list of usernames and passwords.

T1140
Deobfuscate/Decode Files or Information
MalwareLucifer

Lucifer can decrypt its C2 address upon execution.

T1210
Exploitation of Remote Services
MalwareLucifer

Lucifer can exploit multiple vulnerabilities including EternalBlue (CVE-2017-0144) and EternalRomance (CVE-2017-0144).

T1496.001
Compute Hijacking
MalwareLucifer

Lucifer can use system resources to mine cryptocurrency, dropping XMRig to mine Monero.

T1497.001
System Checks
MalwareLucifer

Lucifer can check for specific usernames, computer names, device drivers, DLL's, and virtual devices associated with sandboxed environments and can enter an infinite loop and stop itself if any are detected.

T1498
Network Denial of Service
MalwareLucifer

Lucifer can execute TCP, UDP, and HTTP denial of service (DoS) attacks.

T1547.001
Registry Run Keys / Startup Folder
MalwareLucifer

Lucifer can persist by setting Registry key values HKLM\Software\Microsoft\Windows\CurrentVersion\Run\QQMusic and HKCU\Software\Microsoft\Windows\CurrentVersion\Run\QQMusic.

T1570
Lateral Tool Transfer
MalwareLucifer

Lucifer can use certutil for propagation on Windows hosts within intranets.

T1573.001
Symmetric Cryptography
MalwareLucifer

Lucifer can perform a decremental-xor encryption on the initial C2 request before sending it over the wire.

T1685.005
Clear Windows Event Logs
MalwareLucifer

Lucifer can clear and remove event logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.