Real-world descriptions of how a group, tool or campaign used a technique.
25 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareEgregor | Egregor's payloads are custom-packed, archived and encrypted to prevent analysis. |
| T1033 System Owner/User Discovery |
MalwareEgregor | Egregor has used tools to gather information about users. |
| T1036.004 Masquerade Task or Service |
MalwareEgregor | Egregor has masqueraded the svchost.exe process to exfiltrate data. |
| T1039 Data from Network Shared Drive |
MalwareEgregor | Egregor can collect any files found in the enumerated drivers before sending it to its C2 channel. |
| T1049 System Network Connections Discovery |
MalwareEgregor | Egregor can enumerate all connected drives. |
| T1055 Process Injection |
MalwareEgregor | Egregor can inject its payload into iexplore.exe process. |
| T1059.001 PowerShell |
MalwareEgregor | Egregor has used an encoded PowerShell command by a service created by Cobalt Strike for lateral movement. |
| T1059.003 Windows Command Shell |
MalwareEgregor | Egregor has used batch files for execution and can launch Internet Explorer from cmd.exe. |
| T1069.002 Domain Groups |
MalwareEgregor | Egregor can conduct Active Directory reconnaissance using tools such as Sharphound or AdFind. |
| T1071.001 Web Protocols |
MalwareEgregor | Egregor has communicated with its C2 servers via HTTPS protocol. |
| T1082 System Information Discovery |
MalwareEgregor | Egregor can perform a language check of the infected system and can query the CPU information (cupid). |
| T1105 Ingress Tool Transfer |
MalwareEgregor | Egregor has the ability to download files from its C2 server. |
| T1106 Native API |
MalwareEgregor | Egregor has used the Windows API to make detection more difficult. |
| T1124 System Time Discovery |
MalwareEgregor | Egregor contains functionality to query the local/system time. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareEgregor | Egregor has been decrypted before execution. |
| T1197 BITS Jobs |
MalwareEgregor | Egregor has used BITSadmin to download and execute malicious DLLs. |
| T1218.010 Regsvr32 |
MalwareEgregor | Egregor has used regsvr32.exe to execute malicious DLLs. |
| T1218.011 Rundll32 |
MalwareEgregor | Egregor has used rundll32 during execution. |
| T1219 Remote Access Tools |
MalwareEgregor | Egregor has checked for the LogMein event log in an attempt to encrypt files in remote machines. |
| T1484.001 Group Policy Modification |
MalwareEgregor | Egregor can modify the GPO to evade detection. |
| T1486 Data Encrypted for Impact |
MalwareEgregor | Egregor can encrypt all non-system files using a hybrid AES-RSA algorithm prior to displaying a ransom note. |
| T1497 Virtualization/Sandbox Evasion |
MalwareEgregor | Egregor has used multiple anti-analysis and anti-sandbox techniques to prevent automated analysis by sandboxes. |
| T1497.003 Time Based Checks |
MalwareEgregor | Egregor can perform a long sleep (greater than or equal to 3 minutes) to evade detection. |
| T1574.001 DLL |
MalwareEgregor | Egregor has used DLL side-loading to execute its payload. |
| T1685 Disable or Modify Tools |
MalwareEgregor | Egregor has disabled Windows Defender to evade protections. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.