ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0586×

16 examples

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE has used FakeTLS for session authentication.

T1008
Fallback Channels
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can randomly pick one of five hard-coded IP addresses for C2 communication; if one of the IP fails, it will wait 60 seconds and then try another IP address.

T1018
Remote System Discovery
MalwareTAINTEDSCRIBE

The TAINTEDSCRIBE command and execution module can perform target system enumeration.

T1027.001
Binary Padding
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can execute FileRecvWriteRand to append random bytes to the end of a file received from C2.

T1036.005
Match Legitimate Resource Name or Location
MalwareTAINTEDSCRIBE

The TAINTEDSCRIBE main executable has disguised itself as Microsoft’s Narrator.

T1057
Process Discovery
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can execute ProcessList for process discovery.

T1059.003
Windows Command Shell
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can enable Windows CLI access and execute files.

T1070.004
File Deletion
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can delete files from a compromised host.

T1070.006
Timestomp
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can change the timestamp of specified filenames.

T1083
File and Directory Discovery
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can use DirectoryList to enumerate files in a specified directory.

T1105
Ingress Tool Transfer
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can download additional modules from its C2 server.

T1124
System Time Discovery
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can execute GetLocalTime for time discovery.

T1547.001
Registry Run Keys / Startup Folder
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can copy itself into the current user’s Startup folder as “Narrator.exe” for persistence.

T1560
Archive Collected Data
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE has used FileReadZipSend to compress a file and send to C2.

T1573.001
Symmetric Cryptography
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE uses a Linear Feedback Shift Register (LFSR) algorithm for network encryption.

T1680
Local Storage Discovery
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can use DriveList to retrieve drive information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.