Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.001 Junk Data |
MalwareGoldMax | GoldMax has used decoy traffic to surround its malicious network traffic to avoid detection. |
| T1016 System Network Configuration Discovery |
MalwareGoldMax | GoldMax retrieved a list of the system's network interface after execution. |
| T1027.002 Software Packing |
MalwareGoldMax | GoldMax has been packed for obfuscation. |
| T1027.013 Encrypted/Encoded File |
MalwareGoldMax | GoldMax has written AES-encrypted and Base64-encoded configuration files to disk. |
| T1036.004 Masquerade Task or Service |
MalwareGoldMax | GoldMax has impersonated systems management software to avoid detection. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGoldMax | GoldMax has used filenames that matched the system name, and appeared as a scheduled task impersonating systems management software within the corresponding ProgramData subfolder. |
| T1041 Exfiltration Over C2 Channel |
MalwareGoldMax | GoldMax can exfiltrate files over the existing C2 channel. |
| T1053.003 Cron |
MalwareGoldMax | The GoldMax Linux variant has used a crontab entry with a |
| T1053.005 Scheduled Task |
MalwareGoldMax | GoldMax has used scheduled tasks to maintain persistence. |
| T1059.003 Windows Command Shell |
MalwareGoldMax | GoldMax can spawn a command shell, and execute native commands. |
| T1071.001 Web Protocols |
MalwareGoldMax | GoldMax has used HTTPS and HTTP GET requests with custom HTTP cookies for C2. |
| T1105 Ingress Tool Transfer |
MalwareGoldMax | GoldMax can download and execute additional files. |
| T1124 System Time Discovery |
MalwareGoldMax | GoldMax can check the current date-time value of the compromised system, comparing it to the hardcoded execution trigger and can send the current timestamp to the C2 server. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareGoldMax | GoldMax has decoded and decrypted the configuration file when executed. |
| T1497.001 System Checks |
MalwareGoldMax | GoldMax will check if it is being run in a virtualized environment by comparing the collected MAC address to |
| T1497.003 Time Based Checks |
MalwareGoldMax | GoldMax has set an execution trigger date and time, stored as an ASCII Unix/Epoch time value. |
| T1564.011 Ignore Process Interrupts |
MalwareGoldMax | The GoldMax Linux variant has been executed with the `nohup` command to ignore hangup signals and continue to run if the terminal session was terminated. |
| T1573.002 Asymmetric Cryptography |
MalwareGoldMax | GoldMax has RSA-encrypted its communication with the C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.