Real-world descriptions of how a group, tool or campaign used a technique.
36 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.001 Junk Data |
MalwareSUNBURST | SUNBURST added junk bytes to its C2 over HTTP. |
| T1001.002 Steganography |
MalwareSUNBURST | SUNBURST C2 data attempted to appear as benign XML related to .NET assemblies or as a faux JSON blob. |
| T1001.003 Protocol or Service Impersonation |
MalwareSUNBURST | SUNBURST masqueraded its network traffic as the Orion Improvement Program (OIP) protocol. |
| T1005 Data from Local System |
MalwareSUNBURST | SUNBURST collected information from a compromised host. |
| T1007 System Service Discovery |
MalwareSUNBURST | SUNBURST collected a list of service names that were hashed using a FNV-1a + XOR algorithm to check against similarly-hashed hardcoded blocklists. |
| T1012 Query Registry |
MalwareSUNBURST | SUNBURST collected the registry value |
| T1016 System Network Configuration Discovery |
MalwareSUNBURST | SUNBURST collected all network interface MAC addresses that are up and not loopback devices, as well as IP address, DHCP configuration, and domain information. |
| T1027 Obfuscated Files or Information |
MalwareSUNBURST | SUNBURST obfuscated collected system information using a FNV-1a + XOR algorithm. |
| T1027.005 Indicator Removal from Tools |
MalwareSUNBURST | SUNBURST source code used generic variable names and pre-obfuscated strings, and was likely sanitized of developer comments before being added to SUNSPOT. |
| T1027.015 Compression |
MalwareSUNBURST | SUNBURST strings were compressed and encoded in Base64. |
| T1033 System Owner/User Discovery |
MalwareSUNBURST | SUNBURST collected the username from a compromised host. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSUNBURST | SUNBURST created VBScripts that were named after existing services or folders to blend into legitimate activities. |
| T1047 Windows Management Instrumentation |
MalwareSUNBURST | SUNBURST used the WMI query |
| T1057 Process Discovery |
MalwareSUNBURST | SUNBURST collected a list of process names that were hashed using a FNV-1a + XOR algorithm to check against similarly-hashed hardcoded blocklists. |
| T1059.005 Visual Basic |
MalwareSUNBURST | SUNBURST used VBScripts to initiate the execution of payloads. |
| T1070 Indicator Removal |
MalwareSUNBURST | SUNBURST removed HTTP proxy registry values to clean up traces of execution. |
| T1070.004 File Deletion |
MalwareSUNBURST | SUNBURST had a command to delete files. |
| T1070.007 Clear Network Connection History and Configurations |
MalwareSUNBURST | SUNBURST also removed the firewall rules it created during execution. |
| T1070.009 Clear Persistence |
MalwareSUNBURST | SUNBURST removed IFEO registry values to clean up traces of persistence. |
| T1071.001 Web Protocols |
MalwareSUNBURST | SUNBURST communicated via HTTP GET or HTTP POST requests to third party servers for C2. |
| T1071.004 DNS |
MalwareSUNBURST | SUNBURST used DNS for C2 traffic designed to mimic normal SolarWinds API communications. |
| T1082 System Information Discovery |
MalwareSUNBURST | SUNBURST collected hostname and OS version. |
| T1083 File and Directory Discovery |
MalwareSUNBURST | SUNBURST had commands to enumerate files and directories. |
| T1105 Ingress Tool Transfer |
MalwareSUNBURST | SUNBURST delivered different payloads, including TEARDROP in at least one instance. |
| T1112 Modify Registry |
MalwareSUNBURST | SUNBURST had commands that allow an attacker to write or delete registry keys, and was observed stopping services by setting their |
| T1124 System Time Discovery |
MalwareSUNBURST | SUNBURST collected device `UPTIME`. |
| T1132.001 Standard Encoding |
MalwareSUNBURST | SUNBURST used Base64 encoding in its C2 traffic. |
| T1218.011 Rundll32 |
MalwareSUNBURST | SUNBURST used Rundll32 to execute payloads. |
| T1497.001 System Checks |
MalwareSUNBURST | SUNBURST checked the domain name of the compromised host to verify it was running in a real environment. |
| T1497.003 Time Based Checks |
MalwareSUNBURST | SUNBURST remained dormant after initial access for a period of up to two weeks. |
| T1518.001 Security Software Discovery |
MalwareSUNBURST | SUNBURST checked for a variety of antivirus/endpoint detection agents prior to execution. |
| T1546.012 Image File Execution Options Injection |
MalwareSUNBURST | SUNBURST created an Image File Execution Options (IFEO) Debugger registry value for the process |
| T1553.002 Code Signing |
MalwareSUNBURST | SUNBURST was digitally signed by SolarWinds from March - May 2020. |
| T1568 Dynamic Resolution |
MalwareSUNBURST | SUNBURST dynamically resolved C2 infrastructure for randomly-generated subdomains within a parent domain. |
| T1573.001 Symmetric Cryptography |
MalwareSUNBURST | SUNBURST encrypted C2 traffic using a single-byte-XOR cipher. |
| T1685 Disable or Modify Tools |
MalwareSUNBURST | SUNBURST attempted to disable software security services following checks against a FNV-1a + XOR hashed hardcoded blocklist. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.