ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0589×

18 examples

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareSibot

Sibot has queried the registry for proxy server information.

T1016
System Network Configuration Discovery
MalwareSibot

Sibot checked if the compromised system is configured to use proxies.

T1027.010
Command Obfuscation
MalwareSibot

Sibot has obfuscated scripts used in execution.

T1027.011
Fileless Storage
MalwareSibot

Sibot has installed a second-stage script in the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\sibot registry key.

T1036.005
Match Legitimate Resource Name or Location
MalwareSibot

Sibot has downloaded a DLL to the C:\windows\system32\drivers\ folder and renamed it with a .sys extension.

T1047
Windows Management Instrumentation
MalwareSibot

Sibot has used WMI to discover network connections and configurations. Sibot has also used the Win32_Process class to execute a malicious DLL.

T1049
System Network Connections Discovery
MalwareSibot

Sibot has retrieved a GUID associated with a present LAN connection on a compromised machine.

T1053.005
Scheduled Task
MalwareSibot

Sibot has been executed via a scheduled task.

T1059.005
Visual Basic
MalwareSibot

Sibot executes commands using VBScript.

T1070
Indicator Removal
MalwareSibot

Sibot will delete an associated registry key if a certain server response is received.

T1070.004
File Deletion
MalwareSibot

Sibot will delete itself if a certain server response is received.

T1071.001
Web Protocols
MalwareSibot

Sibot communicated with its C2 server via HTTP GET requests.

T1102
Web Service
MalwareSibot

Sibot has used a legitimate compromised website to download DLLs to the victim's machine.

T1105
Ingress Tool Transfer
MalwareSibot

Sibot can download and execute a payload onto a compromised system.

T1112
Modify Registry
MalwareSibot

Sibot has modified the Registry to install a second-stage script in the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\sibot.

T1140
Deobfuscate/Decode Files or Information
MalwareSibot

Sibot can decrypt data received from a C2 and save to a file.

T1218.005
Mshta
MalwareSibot

Sibot has been executed via MSHTA application.

T1218.011
Rundll32
MalwareSibot

Sibot has executed downloaded DLLs with rundll32.exe.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.