ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0629×

25 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareRainyDay

RainyDay can use a file exfiltration tool to collect recently changed files on a compromised host.

T1007
System Service Discovery
MalwareRainyDay

RainyDay can create and register a service for execution.

T1008
Fallback Channels
MalwareRainyDay

RainyDay has the ability to switch between TCP and HTTP for C2 if one method is not working.

T1027.013
Encrypted/Encoded File
MalwareRainyDay

RainyDay has downloaded as a XOR-encrypted payload.

T1036.004
Masquerade Task or Service
MalwareRainyDay

RainyDay has named services and scheduled tasks to appear benign including "ChromeCheck" and "googleupdate."

T1036.005
Match Legitimate Resource Name or Location
MalwareRainyDay

RainyDay has used names to mimic legitimate software including "vmtoolsd.exe" to spoof Vmtools.

T1053.005
Scheduled Task
MalwareRainyDay

RainyDay can use scheduled tasks to achieve persistence.

T1057
Process Discovery
MalwareRainyDay

RainyDay can enumerate processes on a target system.

T1059.003
Windows Command Shell
MalwareRainyDay

RainyDay can use the Windows Command Shell for execution.

T1070.004
File Deletion
MalwareRainyDay

RainyDay has the ability to uninstall itself by deleting its service and files.

T1071.001
Web Protocols
MalwareRainyDay

RainyDay can use HTTP in C2 communications.

T1074.001
Local Data Staging
MalwareRainyDay

RainyDay can use a file exfiltration tool to copy files to C:\ProgramData\Adobe\temp prior to exfiltration.

T1083
File and Directory Discovery
MalwareRainyDay

RainyDay can use a file exfiltration tool to collect recently changed files with specific extensions.

T1090
Proxy
MalwareRainyDay

RainyDay can use proxy tools including boost_proxy_client for reverse proxy functionality.

T1095
Non-Application Layer Protocol
MalwareRainyDay

RainyDay can use TCP in C2 communications.

T1105
Ingress Tool Transfer
MalwareRainyDay

RainyDay can download files to a compromised host.

T1106
Native API
MalwareRainyDay

The file collection tool used by RainyDay can utilize native API including ReadDirectoryChangeW for folder monitoring.

T1113
Screen Capture
MalwareRainyDay

RainyDay has the ability to capture screenshots.

T1140
Deobfuscate/Decode Files or Information
MalwareRainyDay

RainyDay can decrypt its payload via a XOR key.

T1543.003
Windows Service
MalwareRainyDay

RainyDay can use services to establish persistence.

T1555.003
Credentials from Web Browsers
MalwareRainyDay

RainyDay can use tools to collect credentials from web browsers.

T1555.004
Windows Credential Manager
MalwareRainyDay

RainyDay can use the QuarksPwDump tool to obtain local passwords and domain cached credentials.

T1567.002
Exfiltration to Cloud Storage
MalwareRainyDay

RainyDay can use a file exfiltration tool to upload specific files to Dropbox.

T1573.001
Symmetric Cryptography
MalwareRainyDay

RainyDay can use RC4 to encrypt C2 communications.

T1574.001
DLL
MalwareRainyDay

RainyDay can use side-loading to run malicious executables.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.