ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0582×

16 examples

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareLookBack

LookBack can enumerate services on the victim machine.

T1036.005
Match Legitimate Resource Name or Location
MalwareLookBack

LookBack has a C2 proxy tool that masquerades as GUP.exe, which is software used by Notepad++.

T1057
Process Discovery
MalwareLookBack

LookBack can list running processes.

T1059.003
Windows Command Shell
MalwareLookBack

LookBack executes the cmd.exe command.

T1059.005
Visual Basic
MalwareLookBack

LookBack has used VBA macros in Microsoft Word attachments to drop additional files to the host.

T1070.004
File Deletion
MalwareLookBack

LookBack removes itself after execution and can delete files on the system.

T1071.001
Web Protocols
MalwareLookBack

LookBack’s C2 proxy tool sends data to a C2 server over HTTP.

T1083
File and Directory Discovery
MalwareLookBack

LookBack can retrieve file listings from the victim machine.

T1095
Non-Application Layer Protocol
MalwareLookBack

LookBack uses a custom binary protocol over sockets for C2 communications.

T1113
Screen Capture
MalwareLookBack

LookBack can take desktop screenshots.

T1140
Deobfuscate/Decode Files or Information
MalwareLookBack

LookBack has a function that decrypts malicious data.

T1489
Service Stop
MalwareLookBack

LookBack can kill processes and delete services.

T1529
System Shutdown/Reboot
MalwareLookBack

LookBack can shutdown and reboot the victim machine.

T1547.001
Registry Run Keys / Startup Folder
MalwareLookBack

LookBack sets up a Registry Run key to establish a persistence mechanism.

T1573.001
Symmetric Cryptography
MalwareLookBack

LookBack uses a modified version of RC4 for data transfer.

T1574.001
DLL
MalwareLookBack

LookBack side loads its communications module as a DLL into the libcurl.dll loader.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.