Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareBitPaymer | BitPaymer can enumerate existing Windows services on the host that are configured to run as LocalSystem. |
| T1012 Query Registry |
MalwareBitPaymer | BitPaymer can use the RegEnumKeyW to iterate through Registry keys. |
| T1018 Remote System Discovery |
MalwareBitPaymer | BitPaymer can use |
| T1027.013 Encrypted/Encoded File |
MalwareBitPaymer | BitPaymer has used RC4-encrypted strings and string hashes to avoid identifiable strings within the binary. |
| T1070.006 Timestomp |
MalwareBitPaymer | BitPaymer can modify the timestamp of an executable so that it can be identified and restored by the decryption tool. |
| T1087.001 Local Account |
MalwareBitPaymer | BitPaymer can enumerate the sessions for each user logged onto the infected host. |
| T1106 Native API |
MalwareBitPaymer | BitPaymer has used dynamic API resolution to avoid identifiable strings within the binary, including |
| T1112 Modify Registry |
MalwareBitPaymer | BitPaymer can set values in the Registry to help in execution. |
| T1134.001 Token Impersonation/Theft |
MalwareBitPaymer | BitPaymer can use the tokens of users to create processes on infected systems. |
| T1135 Network Share Discovery |
MalwareBitPaymer | BitPaymer can search for network shares on the domain or workgroup using |
| T1222.001 Windows Permissions |
MalwareBitPaymer | BitPaymer can use |
| T1480 Execution Guardrails |
MalwareBitPaymer | BitPaymer compares file names and paths to a list of excluded names and directory names during encryption. |
| T1486 Data Encrypted for Impact |
MalwareBitPaymer | BitPaymer can import a hard-coded RSA 1024-bit public key, generate a 128-bit RC4 key for each file, and encrypt the file in place, appending |
| T1490 Inhibit System Recovery |
MalwareBitPaymer | BitPaymer attempts to remove the backup shadow files from the host using |
| T1543.003 Windows Service |
MalwareBitPaymer | BitPaymer has attempted to install itself as a service to maintain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBitPaymer | BitPaymer has set the run key |
| T1548.002 Bypass User Account Control |
MalwareBitPaymer | BitPaymer can suppress UAC prompts by setting the |
| T1564.004 NTFS File Attributes |
MalwareBitPaymer | BitPaymer has copied itself to the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.