ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0588×

18 examples

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwareGoldMax

GoldMax has used decoy traffic to surround its malicious network traffic to avoid detection.

T1016
System Network Configuration Discovery
MalwareGoldMax

GoldMax retrieved a list of the system's network interface after execution.

T1027.002
Software Packing
MalwareGoldMax

GoldMax has been packed for obfuscation.

T1027.013
Encrypted/Encoded File
MalwareGoldMax

GoldMax has written AES-encrypted and Base64-encoded configuration files to disk.

T1036.004
Masquerade Task or Service
MalwareGoldMax

GoldMax has impersonated systems management software to avoid detection.

T1036.005
Match Legitimate Resource Name or Location
MalwareGoldMax

GoldMax has used filenames that matched the system name, and appeared as a scheduled task impersonating systems management software within the corresponding ProgramData subfolder.

T1041
Exfiltration Over C2 Channel
MalwareGoldMax

GoldMax can exfiltrate files over the existing C2 channel.

T1053.003
Cron
MalwareGoldMax

The GoldMax Linux variant has used a crontab entry with a @reboot line to gain persistence.

T1053.005
Scheduled Task
MalwareGoldMax

GoldMax has used scheduled tasks to maintain persistence.

T1059.003
Windows Command Shell
MalwareGoldMax

GoldMax can spawn a command shell, and execute native commands.

T1071.001
Web Protocols
MalwareGoldMax

GoldMax has used HTTPS and HTTP GET requests with custom HTTP cookies for C2.

T1105
Ingress Tool Transfer
MalwareGoldMax

GoldMax can download and execute additional files.

T1124
System Time Discovery
MalwareGoldMax

GoldMax can check the current date-time value of the compromised system, comparing it to the hardcoded execution trigger and can send the current timestamp to the C2 server.

T1140
Deobfuscate/Decode Files or Information
MalwareGoldMax

GoldMax has decoded and decrypted the configuration file when executed.

T1497.001
System Checks
MalwareGoldMax

GoldMax will check if it is being run in a virtualized environment by comparing the collected MAC address to c8:27:cc:c2:37:5a.

T1497.003
Time Based Checks
MalwareGoldMax

GoldMax has set an execution trigger date and time, stored as an ASCII Unix/Epoch time value.

T1564.011
Ignore Process Interrupts
MalwareGoldMax

The GoldMax Linux variant has been executed with the `nohup` command to ignore hangup signals and continue to run if the terminal session was terminated.

T1573.002
Asymmetric Cryptography
MalwareGoldMax

GoldMax has RSA-encrypted its communication with the C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.