ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0554×

25 examples

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareEgregor

Egregor's payloads are custom-packed, archived and encrypted to prevent analysis.

T1033
System Owner/User Discovery
MalwareEgregor

Egregor has used tools to gather information about users.

T1036.004
Masquerade Task or Service
MalwareEgregor

Egregor has masqueraded the svchost.exe process to exfiltrate data.

T1039
Data from Network Shared Drive
MalwareEgregor

Egregor can collect any files found in the enumerated drivers before sending it to its C2 channel.

T1049
System Network Connections Discovery
MalwareEgregor

Egregor can enumerate all connected drives.

T1055
Process Injection
MalwareEgregor

Egregor can inject its payload into iexplore.exe process.

T1059.001
PowerShell
MalwareEgregor

Egregor has used an encoded PowerShell command by a service created by Cobalt Strike for lateral movement.

T1059.003
Windows Command Shell
MalwareEgregor

Egregor has used batch files for execution and can launch Internet Explorer from cmd.exe.

T1069.002
Domain Groups
MalwareEgregor

Egregor can conduct Active Directory reconnaissance using tools such as Sharphound or AdFind.

T1071.001
Web Protocols
MalwareEgregor

Egregor has communicated with its C2 servers via HTTPS protocol.

T1082
System Information Discovery
MalwareEgregor

Egregor can perform a language check of the infected system and can query the CPU information (cupid).

T1105
Ingress Tool Transfer
MalwareEgregor

Egregor has the ability to download files from its C2 server.

T1106
Native API
MalwareEgregor

Egregor has used the Windows API to make detection more difficult.

T1124
System Time Discovery
MalwareEgregor

Egregor contains functionality to query the local/system time.

T1140
Deobfuscate/Decode Files or Information
MalwareEgregor

Egregor has been decrypted before execution.

T1197
BITS Jobs
MalwareEgregor

Egregor has used BITSadmin to download and execute malicious DLLs.

T1218.010
Regsvr32
MalwareEgregor

Egregor has used regsvr32.exe to execute malicious DLLs.

T1218.011
Rundll32
MalwareEgregor

Egregor has used rundll32 during execution.

T1219
Remote Access Tools
MalwareEgregor

Egregor has checked for the LogMein event log in an attempt to encrypt files in remote machines.

T1484.001
Group Policy Modification
MalwareEgregor

Egregor can modify the GPO to evade detection.

T1486
Data Encrypted for Impact
MalwareEgregor

Egregor can encrypt all non-system files using a hybrid AES-RSA algorithm prior to displaying a ransom note.

T1497
Virtualization/Sandbox Evasion
MalwareEgregor

Egregor has used multiple anti-analysis and anti-sandbox techniques to prevent automated analysis by sandboxes.

T1497.003
Time Based Checks
MalwareEgregor

Egregor can perform a long sleep (greater than or equal to 3 minutes) to evade detection.

T1574.001
DLL
MalwareEgregor

Egregor has used DLL side-loading to execute its payload.

T1685
Disable or Modify Tools
MalwareEgregor

Egregor has disabled Windows Defender to evade protections.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.