ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0575×

16 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareConti

Conti can retrieve the ARP cache from the local system by using the GetIpNetTable() API call and check to ensure IP addresses it connects to are for local, non-Internet, systems.

T1018
Remote System Discovery
MalwareConti

Conti has the ability to discover hosts on a target network.

T1021.002
SMB/Windows Admin Shares
MalwareConti

Conti can spread via SMB and encrypts files on different hosts, potentially compromising an entire network.

T1027
Obfuscated Files or Information
MalwareConti

Conti can use compiler-based obfuscation for its code, encrypt DLLs, and hide Windows API calls.

T1049
System Network Connections Discovery
MalwareConti

Conti can enumerate routine network connections from a compromised host.

T1055.001
Dynamic-link Library Injection
MalwareConti

Conti has loaded an encrypted DLL into memory and then executes it.

T1057
Process Discovery
MalwareConti

Conti can enumerate through all open processes to search for any that have the string “sql” in their process name.

T1059.003
Windows Command Shell
MalwareConti

Conti can utilize command line options to allow an attacker control over how it scans and encrypts files.

T1080
Taint Shared Content
MalwareConti

Conti can spread itself by infecting other remote machines via network shared drives.

T1083
File and Directory Discovery
MalwareConti

Conti can discover files on a local system.

T1106
Native API
MalwareConti

Conti has used API calls during execution.

T1135
Network Share Discovery
MalwareConti

Conti can enumerate remote open SMB network shares using NetShareEnum().

T1140
Deobfuscate/Decode Files or Information
MalwareConti

Conti has decrypted its payload using a hardcoded AES-256 key.

T1486
Data Encrypted for Impact
MalwareConti

Conti can use CreateIoCompletionPort(), PostQueuedCompletionStatus(), and GetQueuedCompletionPort() to rapidly encrypt files, excluding those with the extensions of .exe, .dll, and .lnk. It has used a different AES-256 encryption key per file with a bundled RAS-4096 public encryption key that is unique for each victim. Conti can use “Windows Restart Manager” to ensure files are unlocked and open for encryption.

T1489
Service Stop
MalwareConti

Conti can stop up to 146 Windows services related to security, backup, database, and email solutions through the use of net stop.

T1490
Inhibit System Recovery
MalwareConti

Conti can delete Windows Volume Shadow Copies using vssadmin.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.