Real-world descriptions of how a group, tool or campaign used a technique.
24 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareSombRAT | SombRAT has collected data and files from a compromised host. |
| T1007 System Service Discovery |
MalwareSombRAT | SombRAT can enumerate services on a victim machine. |
| T1027 Obfuscated Files or Information |
MalwareSombRAT | SombRAT can encrypt strings with XOR-based routines and use a custom AES storage format for plugins, configuration, C2 domains, and harvested data. |
| T1033 System Owner/User Discovery |
MalwareSombRAT | SombRAT can execute |
| T1036 Masquerading |
MalwareSombRAT | SombRAT can use a legitimate process name to hide itself. |
| T1041 Exfiltration Over C2 Channel |
MalwareSombRAT | SombRAT has uploaded collected data and files from a compromised host to its C2 server. |
| T1055.001 Dynamic-link Library Injection |
MalwareSombRAT | SombRAT can execute |
| T1057 Process Discovery |
MalwareSombRAT | SombRAT can use the |
| T1070.004 File Deletion |
MalwareSombRAT | SombRAT has the ability to run |
| T1071.004 DNS |
MalwareSombRAT | SombRAT can communicate over DNS with the C2 server. |
| T1074.001 Local Data Staging |
MalwareSombRAT | SombRAT can store harvested data in a custom database under the %TEMP% directory. |
| T1082 System Information Discovery |
MalwareSombRAT | SombRAT can execute |
| T1083 File and Directory Discovery |
MalwareSombRAT | SombRAT can execute |
| T1090 Proxy |
MalwareSombRAT | SombRAT has the ability to use an embedded SOCKS proxy in C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareSombRAT | SombRAT has the ability to use TCP sockets to send data and ICMP to ping the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareSombRAT | SombRAT has the ability to download and execute additional payloads. |
| T1106 Native API |
MalwareSombRAT | SombRAT has the ability to respawn itself using |
| T1124 System Time Discovery |
MalwareSombRAT | SombRAT can execute |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSombRAT | SombRAT can run |
| T1560.003 Archive via Custom Method |
MalwareSombRAT | SombRAT has encrypted collected data with AES-256 using a hardcoded key. |
| T1564.010 Process Argument Spoofing |
MalwareSombRAT | SombRAT has the ability to modify its process memory to hide process command-line arguments. |
| T1568.002 Domain Generation Algorithms |
MalwareSombRAT | SombRAT can use a custom DGA to generate a subdomain for C2. |
| T1573.001 Symmetric Cryptography |
MalwareSombRAT | SombRAT has encrypted its C2 communications with AES. |
| T1573.002 Asymmetric Cryptography |
MalwareSombRAT | SombRAT can SSL encrypt C2 traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.