ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0596×

21 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareShadowPad

ShadowPad has collected the domain name of the victim system.

T1027
Obfuscated Files or Information
MalwareShadowPad

ShadowPad has encrypted its payload, a virtual file system, and various files.

T1027.011
Fileless Storage
MalwareShadowPad

ShadowPad maintains a configuration block and virtual file system in the Registry.

T1029
Scheduled Transfer
MalwareShadowPad

ShadowPad has sent data back to C2 every 8 hours.

T1033
System Owner/User Discovery
MalwareShadowPad

ShadowPad has collected the username of the victim system.

T1055
Process Injection
MalwareShadowPad

ShadowPad has injected an install module into a newly created process.

T1055.001
Dynamic-link Library Injection
MalwareShadowPad

ShadowPad has injected a DLL into svchost.exe.

T1057
Process Discovery
MalwareShadowPad

ShadowPad has collected the PID of a malicious process.

T1070
Indicator Removal
MalwareShadowPad

ShadowPad has deleted arbitrary Registry values.

T1071.001
Web Protocols
MalwareShadowPad

ShadowPad communicates over HTTP to retrieve a string that is decoded into a C2 server URL.

T1071.002
File Transfer Protocols
MalwareShadowPad

ShadowPad has used FTP for C2 communications.

T1071.004
DNS
MalwareShadowPad

ShadowPad has used DNS tunneling for C2 communications.

T1082
System Information Discovery
MalwareShadowPad

ShadowPad has discovered system information including memory status, CPU frequency, and OS versions.

T1095
Non-Application Layer Protocol
MalwareShadowPad

ShadowPad has used UDP for C2 communications.

T1105
Ingress Tool Transfer
MalwareShadowPad

ShadowPad has downloaded code from a C2 server.

T1112
Modify Registry
MalwareShadowPad

ShadowPad can modify the Registry to store and maintain a configuration block and virtual file system.

T1124
System Time Discovery
MalwareShadowPad

ShadowPad has collected the current date and time of the victim system.

T1132.002
Non-Standard Encoding
MalwareShadowPad

ShadowPad has encoded data as readable Latin characters.

T1140
Deobfuscate/Decode Files or Information
MalwareShadowPad

ShadowPad has decrypted a binary blob to start execution.

T1568.002
Domain Generation Algorithms
MalwareShadowPad

ShadowPad uses a DGA that is based on the day of the month for C2 servers.

T1680
Local Storage Discovery
MalwareShadowPad

ShadowPad has discovered system information including volume serial numbers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.