ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0615×

24 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareSombRAT

SombRAT has collected data and files from a compromised host.

T1007
System Service Discovery
MalwareSombRAT

SombRAT can enumerate services on a victim machine.

T1027
Obfuscated Files or Information
MalwareSombRAT

SombRAT can encrypt strings with XOR-based routines and use a custom AES storage format for plugins, configuration, C2 domains, and harvested data.

T1033
System Owner/User Discovery
MalwareSombRAT

SombRAT can execute getinfo to identify the username on a compromised host.

T1036
Masquerading
MalwareSombRAT

SombRAT can use a legitimate process name to hide itself.

T1041
Exfiltration Over C2 Channel
MalwareSombRAT

SombRAT has uploaded collected data and files from a compromised host to its C2 server.

T1055.001
Dynamic-link Library Injection
MalwareSombRAT

SombRAT can execute loadfromfile, loadfromstorage, and loadfrommem to inject a DLL from disk, storage, or memory respectively.

T1057
Process Discovery
MalwareSombRAT

SombRAT can use the getprocesslist command to enumerate processes on a compromised host.

T1070.004
File Deletion
MalwareSombRAT

SombRAT has the ability to run cancel or closeanddeletestorage to remove all files from storage and delete the storage temp file on a compromised host.

T1071.004
DNS
MalwareSombRAT

SombRAT can communicate over DNS with the C2 server.

T1074.001
Local Data Staging
MalwareSombRAT

SombRAT can store harvested data in a custom database under the %TEMP% directory.

T1082
System Information Discovery
MalwareSombRAT

SombRAT can execute getinfo to enumerate the computer name and OS version of a compromised system.

T1083
File and Directory Discovery
MalwareSombRAT

SombRAT can execute enum to enumerate files in storage on a compromised system.

T1090
Proxy
MalwareSombRAT

SombRAT has the ability to use an embedded SOCKS proxy in C2 communications.

T1095
Non-Application Layer Protocol
MalwareSombRAT

SombRAT has the ability to use TCP sockets to send data and ICMP to ping the C2 server.

T1105
Ingress Tool Transfer
MalwareSombRAT

SombRAT has the ability to download and execute additional payloads.

T1106
Native API
MalwareSombRAT

SombRAT has the ability to respawn itself using ShellExecuteW and CreateProcessW.

T1124
System Time Discovery
MalwareSombRAT

SombRAT can execute getinfo to discover the current time on a compromised host.

T1140
Deobfuscate/Decode Files or Information
MalwareSombRAT

SombRAT can run upload to decrypt and upload files from storage.

T1560.003
Archive via Custom Method
MalwareSombRAT

SombRAT has encrypted collected data with AES-256 using a hardcoded key.

T1564.010
Process Argument Spoofing
MalwareSombRAT

SombRAT has the ability to modify its process memory to hide process command-line arguments.

T1568.002
Domain Generation Algorithms
MalwareSombRAT

SombRAT can use a custom DGA to generate a subdomain for C2.

T1573.001
Symmetric Cryptography
MalwareSombRAT

SombRAT has encrypted its C2 communications with AES.

T1573.002
Asymmetric Cryptography
MalwareSombRAT

SombRAT can SSL encrypt C2 traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.