Real-world descriptions of how a group, tool or campaign used a technique.
16 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
MalwarePysa | |
| T1016 System Network Configuration Discovery |
MalwarePysa | Pysa can perform network reconnaissance using the Advanced IP Scanner tool. |
| T1021.001 Remote Desktop Protocol |
MalwarePysa | Pysa has laterally moved using RDP connections. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePysa | Pysa has executed a malicious executable by naming it svchost.exe. |
| T1046 Network Service Discovery |
MalwarePysa | Pysa can perform network reconnaissance using the Advanced Port Scanner tool. |
| T1059.001 PowerShell |
MalwarePysa | Pysa has used Powershell scripts to deploy its ransomware. |
| T1059.006 Python |
MalwarePysa | Pysa has used Python scripts to deploy ransomware. |
| T1070.004 File Deletion |
MalwarePysa | Pysa has deleted batch files after execution. |
| T1110 Brute Force |
MalwarePysa | Pysa has used brute force attempts against a central management console, as well as some Active Directory accounts. |
| T1112 Modify Registry |
MalwarePysa | Pysa has modified the registry key “SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System” and added the ransom note. |
| T1486 Data Encrypted for Impact |
MalwarePysa | Pysa has used RSA and AES-CBC encryption algorithm to encrypt a list of targeted file extensions. |
| T1489 Service Stop |
MalwarePysa | Pysa can stop services and processes. |
| T1490 Inhibit System Recovery |
MalwarePysa | Pysa has the functionality to delete shadow copies. |
| T1552.001 Credentials In Files |
MalwarePysa | Pysa has extracted credentials from the password database before encrypting the files. |
| T1569.002 Service Execution |
MalwarePysa | |
| T1685 Disable or Modify Tools |
MalwarePysa | Pysa has the capability to stop antivirus services and disable Windows Defender. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.