ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0533×

24 examples

TechniqueUsed byProcedure example
T1001
Data Obfuscation
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has hashed a string containing system information prior to exfiltration via POST requests.

T1005
Data from Local System
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has uploaded files and information from victim machines.

T1007
System Service Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has the capability to enumerate services.

T1033
System Owner/User Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has collected the username from a victim machine.

T1036.004
Masquerade Task or Service
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has named a service it establishes on victim machines as "TaskFrame" to hide its malicious purpose.

T1036.005
Match Legitimate Resource Name or Location
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has mimicked the names of known executables, such as mediaplayer.exe.

T1041
Exfiltration Over C2 Channel
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has sent system information to a C2 server via HTTP and HTTPS POST requests.

T1049
System Network Connections Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA can enumerate open ports on a victim machine.

T1055
Process Injection
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA can inject into running processes on a compromised host.

T1056.001
Keylogging
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has a keylogging capability.

T1057
Process Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has enumerated processes by ID, name, or privileges.

T1059.003
Windows Command Shell
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA can open a command line to execute commands.

T1070.004
File Deletion
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has deleted itself and the 'index.dat' file on a compromised machine to remove recent Internet history from the system.

T1071.001
Web Protocols
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has used HTTP and HTTPS for C2 communications.

T1082
System Information Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has collected system name, OS version, adapter information, and memory usage from a victim machine.

T1083
File and Directory Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA can enumerate files and directories.

T1105
Ingress Tool Transfer
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has downloaded files onto a victim machine.

T1112
Modify Registry
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA can add, modify, and/or delete registry keys. It has changed the proxy configuration of a victim system by modifying the HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap registry.

T1113
Screen Capture
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has taken a screenshot of a victim's desktop, named it "Filter3.jpg", and stored it in the local directory.

T1489
Service Stop
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has the capability to stop processes and services.

T1543.003
Windows Service
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has created a service on victim machines named "TaskFrame" to establish persistence.

T1564.001
Hidden Files and Directories
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has been created with a hidden attribute to insure it's not visible to the victim.

T1569.002
Service Execution
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has the capability to start services.

T1680
Local Storage Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has collected disk information from a victim machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.