ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0587×

18 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwarePenquin

Penquin can report the IP of the compromised host to attacker controlled infrastructure.

T1027.005
Indicator Removal from Tools
MalwarePenquin

Penquin can remove strings from binaries.

T1027.013
Encrypted/Encoded File
MalwarePenquin

Penquin has encrypted strings in the binary for obfuscation.

T1036.005
Match Legitimate Resource Name or Location
MalwarePenquin

Penquin has mimicked the Cron binary to hide itself on compromised systems.

T1040
Network Sniffing
MalwarePenquin

Penquin can sniff network traffic to look for packets matching specific conditions.

T1041
Exfiltration Over C2 Channel
MalwarePenquin

Penquin can execute the command code do_upload to send files to C2.

T1053.003
Cron
MalwarePenquin

Penquin can use Cron to create periodic and pre-scheduled background jobs.

T1059.004
Unix Shell
MalwarePenquin

Penquin can execute remote commands using bash scripts.

T1070.004
File Deletion
MalwarePenquin

Penquin can delete downloaded executables after running them.

T1082
System Information Discovery
MalwarePenquin

Penquin can report the file system type of a compromised host to C2.

T1083
File and Directory Discovery
MalwarePenquin

Penquin can use the command code do_vslist to send file names, size, and status to C2.

T1095
Non-Application Layer Protocol
MalwarePenquin

The Penquin C2 mechanism is based on TCP and UDP packets.

T1105
Ingress Tool Transfer
MalwarePenquin

Penquin can execute the command code do_download to retrieve remote files from C2.

T1205
Traffic Signaling
MalwarePenquin

Penquin will connect to C2 only after sniffing a "magic packet" value in TCP or UDP packets matching specific conditions.

T1205.002
Socket Filters
MalwarePenquin

Penquin installs a `TCP` and `UDP` filter on the `eth0` interface.

T1222.002
Linux and Mac Permissions
MalwarePenquin

Penquin can add the executable flag to a downloaded file.

T1573.002
Asymmetric Cryptography
MalwarePenquin

Penquin can encrypt communications using the BlowFish algorithm and a symmetric key exchanged with Diffie Hellman.

T1680
Local Storage Discovery
MalwarePenquin

Penquin can report the disk space of a compromised host to C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.