ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0559×

36 examples

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwareSUNBURST

SUNBURST added junk bytes to its C2 over HTTP.

T1001.002
Steganography
MalwareSUNBURST

SUNBURST C2 data attempted to appear as benign XML related to .NET assemblies or as a faux JSON blob.

T1001.003
Protocol or Service Impersonation
MalwareSUNBURST

SUNBURST masqueraded its network traffic as the Orion Improvement Program (OIP) protocol.

T1005
Data from Local System
MalwareSUNBURST

SUNBURST collected information from a compromised host.

T1007
System Service Discovery
MalwareSUNBURST

SUNBURST collected a list of service names that were hashed using a FNV-1a + XOR algorithm to check against similarly-hashed hardcoded blocklists.

T1012
Query Registry
MalwareSUNBURST

SUNBURST collected the registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid from compromised hosts.

T1016
System Network Configuration Discovery
MalwareSUNBURST

SUNBURST collected all network interface MAC addresses that are up and not loopback devices, as well as IP address, DHCP configuration, and domain information.

T1027
Obfuscated Files or Information
MalwareSUNBURST

SUNBURST obfuscated collected system information using a FNV-1a + XOR algorithm.

T1027.005
Indicator Removal from Tools
MalwareSUNBURST

SUNBURST source code used generic variable names and pre-obfuscated strings, and was likely sanitized of developer comments before being added to SUNSPOT.

T1027.015
Compression
MalwareSUNBURST

SUNBURST strings were compressed and encoded in Base64.

T1033
System Owner/User Discovery
MalwareSUNBURST

SUNBURST collected the username from a compromised host.

T1036.005
Match Legitimate Resource Name or Location
MalwareSUNBURST

SUNBURST created VBScripts that were named after existing services or folders to blend into legitimate activities.

T1047
Windows Management Instrumentation
MalwareSUNBURST

SUNBURST used the WMI query Select * From Win32_SystemDriver to retrieve a driver listing.

T1057
Process Discovery
MalwareSUNBURST

SUNBURST collected a list of process names that were hashed using a FNV-1a + XOR algorithm to check against similarly-hashed hardcoded blocklists.

T1059.005
Visual Basic
MalwareSUNBURST

SUNBURST used VBScripts to initiate the execution of payloads.

T1070
Indicator Removal
MalwareSUNBURST

SUNBURST removed HTTP proxy registry values to clean up traces of execution.

T1070.004
File Deletion
MalwareSUNBURST

SUNBURST had a command to delete files.

T1070.007
Clear Network Connection History and Configurations
MalwareSUNBURST

SUNBURST also removed the firewall rules it created during execution.

T1070.009
Clear Persistence
MalwareSUNBURST

SUNBURST removed IFEO registry values to clean up traces of persistence.

T1071.001
Web Protocols
MalwareSUNBURST

SUNBURST communicated via HTTP GET or HTTP POST requests to third party servers for C2.

T1071.004
DNS
MalwareSUNBURST

SUNBURST used DNS for C2 traffic designed to mimic normal SolarWinds API communications.

T1082
System Information Discovery
MalwareSUNBURST

SUNBURST collected hostname and OS version.

T1083
File and Directory Discovery
MalwareSUNBURST

SUNBURST had commands to enumerate files and directories.

T1105
Ingress Tool Transfer
MalwareSUNBURST

SUNBURST delivered different payloads, including TEARDROP in at least one instance.

T1112
Modify Registry
MalwareSUNBURST

SUNBURST had commands that allow an attacker to write or delete registry keys, and was observed stopping services by setting their HKLM\SYSTEM\CurrentControlSet\services\\[service_name]\\Start registry entries to value 4. It also deleted previously-created Image File Execution Options (IFEO) Debugger registry values and registry keys related to HTTP proxy to clean up traces of its activity.

T1124
System Time Discovery
MalwareSUNBURST

SUNBURST collected device `UPTIME`.

T1132.001
Standard Encoding
MalwareSUNBURST

SUNBURST used Base64 encoding in its C2 traffic.

T1218.011
Rundll32
MalwareSUNBURST

SUNBURST used Rundll32 to execute payloads.

T1497.001
System Checks
MalwareSUNBURST

SUNBURST checked the domain name of the compromised host to verify it was running in a real environment.

T1497.003
Time Based Checks
MalwareSUNBURST

SUNBURST remained dormant after initial access for a period of up to two weeks.

T1518.001
Security Software Discovery
MalwareSUNBURST

SUNBURST checked for a variety of antivirus/endpoint detection agents prior to execution.

T1546.012
Image File Execution Options Injection
MalwareSUNBURST

SUNBURST created an Image File Execution Options (IFEO) Debugger registry value for the process dllhost.exe to trigger the installation of Cobalt Strike.

T1553.002
Code Signing
MalwareSUNBURST

SUNBURST was digitally signed by SolarWinds from March - May 2020.

T1568
Dynamic Resolution
MalwareSUNBURST

SUNBURST dynamically resolved C2 infrastructure for randomly-generated subdomains within a parent domain.

T1573.001
Symmetric Cryptography
MalwareSUNBURST

SUNBURST encrypted C2 traffic using a single-byte-XOR cipher.

T1685
Disable or Modify Tools
MalwareSUNBURST

SUNBURST attempted to disable software security services following checks against a FNV-1a + XOR hashed hardcoded blocklist.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.