ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0570×

18 examples

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareBitPaymer

BitPaymer can enumerate existing Windows services on the host that are configured to run as LocalSystem.

T1012
Query Registry
MalwareBitPaymer

BitPaymer can use the RegEnumKeyW to iterate through Registry keys.

T1018
Remote System Discovery
MalwareBitPaymer

BitPaymer can use net view to discover remote systems.

T1027.013
Encrypted/Encoded File
MalwareBitPaymer

BitPaymer has used RC4-encrypted strings and string hashes to avoid identifiable strings within the binary.

T1070.006
Timestomp
MalwareBitPaymer

BitPaymer can modify the timestamp of an executable so that it can be identified and restored by the decryption tool.

T1087.001
Local Account
MalwareBitPaymer

BitPaymer can enumerate the sessions for each user logged onto the infected host.

T1106
Native API
MalwareBitPaymer

BitPaymer has used dynamic API resolution to avoid identifiable strings within the binary, including RegEnumKeyW.

T1112
Modify Registry
MalwareBitPaymer

BitPaymer can set values in the Registry to help in execution.

T1134.001
Token Impersonation/Theft
MalwareBitPaymer

BitPaymer can use the tokens of users to create processes on infected systems.

T1135
Network Share Discovery
MalwareBitPaymer

BitPaymer can search for network shares on the domain or workgroup using net view <host>.

T1222.001
Windows Permissions
MalwareBitPaymer

BitPaymer can use icacls /reset and takeown /F to reset a targeted executable's permissions and then take ownership.

T1480
Execution Guardrails
MalwareBitPaymer

BitPaymer compares file names and paths to a list of excluded names and directory names during encryption.

T1486
Data Encrypted for Impact
MalwareBitPaymer

BitPaymer can import a hard-coded RSA 1024-bit public key, generate a 128-bit RC4 key for each file, and encrypt the file in place, appending .locked to the filename.

T1490
Inhibit System Recovery
MalwareBitPaymer

BitPaymer attempts to remove the backup shadow files from the host using vssadmin.exe Delete Shadows /All /Quiet.

T1543.003
Windows Service
MalwareBitPaymer

BitPaymer has attempted to install itself as a service to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareBitPaymer

BitPaymer has set the run key HKCU\Software\Microsoft\Windows\CurrentVersion\Run for persistence.

T1548.002
Bypass User Account Control
MalwareBitPaymer

BitPaymer can suppress UAC prompts by setting the HKCU\Software\Classes\ms-settings\shell\open\command registry key on Windows 10 or HKCU\Software\Classes\mscfile\shell\open\command on Windows 7 and launching the eventvwr.msc process, which launches BitPaymer with elevated privileges.

T1564.004
NTFS File Attributes
MalwareBitPaymer

BitPaymer has copied itself to the :bin alternate data stream of a newly created file.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.