Real-world descriptions of how a group, tool or campaign used a technique.
32 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareAppleSeed | AppleSeed can collect data on a compromised host. |
| T1008 Fallback Channels |
MalwareAppleSeed | AppleSeed can use a second channel for C2 when the primary channel is in upload mode. |
| T1016 System Network Configuration Discovery |
MalwareAppleSeed | AppleSeed can identify the IP of a targeted system. |
| T1025 Data from Removable Media |
MalwareAppleSeed | AppleSeed can find and collect data from removable media devices. |
| T1027 Obfuscated Files or Information |
MalwareAppleSeed | AppleSeed has the ability to Base64 encode its payload and custom encrypt API calls. |
| T1027.002 Software Packing |
MalwareAppleSeed | AppleSeed has used UPX packers for its payload DLL. |
| T1030 Data Transfer Size Limits |
MalwareAppleSeed | AppleSeed has divided files if the size is 0x1000000 bytes or more. |
| T1036 Masquerading |
MalwareAppleSeed | AppleSeed can disguise JavaScript files as PDFs. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareAppleSeed | AppleSeed has the ability to rename its payload to ESTCommon.dll to masquerade as a DLL belonging to ESTsecurity. |
| T1041 Exfiltration Over C2 Channel |
MalwareAppleSeed | AppleSeed can exfiltrate files via the C2 channel. |
| T1056.001 Keylogging |
MalwareAppleSeed | AppleSeed can use |
| T1057 Process Discovery |
MalwareAppleSeed | AppleSeed can enumerate the current process on a compromised host. |
| T1059.001 PowerShell |
MalwareAppleSeed | AppleSeed has the ability to execute its payload via PowerShell. |
| T1059.007 JavaScript |
MalwareAppleSeed | AppleSeed has the ability to use JavaScript to execute PowerShell. |
| T1070.004 File Deletion |
MalwareAppleSeed | AppleSeed can delete files from a compromised host after they are exfiltrated. |
| T1071.001 Web Protocols |
MalwareAppleSeed | AppleSeed has the ability to communicate with C2 over HTTP. |
| T1074.001 Local Data Staging |
MalwareAppleSeed | AppleSeed can stage files in a central location prior to exfiltration. |
| T1082 System Information Discovery |
MalwareAppleSeed | AppleSeed can identify the OS version of a targeted system. |
| T1083 File and Directory Discovery |
MalwareAppleSeed | AppleSeed has the ability to search for .txt, .ppt, .hwp, .pdf, and .doc files in specified directories. |
| T1106 Native API |
MalwareAppleSeed | AppleSeed has the ability to use multiple dynamically resolved API calls. |
| T1113 Screen Capture |
MalwareAppleSeed | AppleSeed can take screenshots on a compromised host by calling a series of APIs. |
| T1119 Automated Collection |
MalwareAppleSeed | AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration. |
| T1124 System Time Discovery |
MalwareAppleSeed | AppleSeed can pull a timestamp from the victim's machine. |
| T1134 Access Token Manipulation |
MalwareAppleSeed | AppleSeed can gain system level privilege by passing |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAppleSeed | AppleSeed can decode its payload prior to execution. |
| T1204.002 Malicious File |
MalwareAppleSeed | AppleSeed can achieve execution through users running malicious file attachments distributed via email. |
| T1218.010 Regsvr32 |
MalwareAppleSeed | AppleSeed can call regsvr32.exe for execution. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAppleSeed | AppleSeed has the ability to create the Registry key name |
| T1560 Archive Collected Data |
MalwareAppleSeed | AppleSeed has compressed collected data before exfiltration. |
| T1560.001 Archive via Utility |
MalwareAppleSeed | AppleSeed can zip and encrypt data collected on a target system. |
| T1566.001 Spearphishing Attachment |
MalwareAppleSeed | AppleSeed has been distributed to victims through malicious e-mail attachments. |
| T1567 Exfiltration Over Web Service |
MalwareAppleSeed | AppleSeed has exfiltrated files using web services. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.