Real-world descriptions of how a group, tool or campaign used a technique.
23 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareCuba | Cuba can query service status using |
| T1016 System Network Configuration Discovery |
MalwareCuba | Cuba can retrieve the ARP cache from the local system by using |
| T1027 Obfuscated Files or Information |
MalwareCuba | Cuba has used multiple layers of obfuscation to avoid analysis, including its Base64 encoded payload. |
| T1027.002 Software Packing |
MalwareCuba | Cuba has a packed payload when delivered. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCuba | Cuba has been disguised as legitimate 360 Total Security Antivirus and OpenVPN programs. |
| T1049 System Network Connections Discovery |
MalwareCuba | Cuba can use the function |
| T1056.001 Keylogging |
MalwareCuba | Cuba logs keystrokes via polling by using |
| T1057 Process Discovery |
MalwareCuba | Cuba can enumerate processes running on a victim's machine. |
| T1059.001 PowerShell |
MalwareCuba | Cuba has been dropped onto systems and used for lateral movement via obfuscated PowerShell scripts. |
| T1059.003 Windows Command Shell |
MalwareCuba | Cuba has used |
| T1070.004 File Deletion |
MalwareCuba | Cuba can use the command |
| T1083 File and Directory Discovery |
MalwareCuba | Cuba can enumerate files by using a variety of functions. |
| T1105 Ingress Tool Transfer |
MalwareCuba | Cuba can download files from its C2 server. |
| T1106 Native API |
MalwareCuba | Cuba has used several built-in API functions for discovery like GetIpNetTable and NetShareEnum. |
| T1134 Access Token Manipulation |
MalwareCuba | Cuba has used |
| T1135 Network Share Discovery |
MalwareCuba | Cuba can discover shared resources using the |
| T1486 Data Encrypted for Impact |
MalwareCuba | Cuba has the ability to encrypt system data and add the ".cuba" extension to encrypted files. |
| T1489 Service Stop |
MalwareCuba | Cuba has a hardcoded list of services and processes to terminate. |
| T1543.003 Windows Service |
MalwareCuba | Cuba can modify services by using the |
| T1564.003 Hidden Window |
MalwareCuba | Cuba has executed hidden PowerShell windows. |
| T1614.001 System Language Discovery |
MalwareCuba | Cuba can check if Russian language is installed on the infected machine by using the function |
| T1620 Reflective Code Loading |
MalwareCuba | Cuba loaded the payload into memory using PowerShell. |
| T1680 Local Storage Discovery |
MalwareCuba | Cuba can enumerate local drives, disk type, and disk free space. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.