ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0635×

16 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareBoomBox

BoomBox can encrypt data using AES prior to exfiltration.

T1033
System Owner/User Discovery
MalwareBoomBox

BoomBox can enumerate the username on a compromised host.

T1036
Masquerading
MalwareBoomBox

BoomBox has the ability to mask malicious data strings as PDF files.

T1071.001
Web Protocols
MalwareBoomBox

BoomBox has used HTTP POST requests for C2.

T1082
System Information Discovery
MalwareBoomBox

BoomBox can enumerate the hostname, domain, and IP of a compromised host.

T1083
File and Directory Discovery
MalwareBoomBox

BoomBox can search for specific files and directories on a machine.

T1087.002
Domain Account
MalwareBoomBox

BoomBox has the ability to execute an LDAP query to enumerate the distinguished name, SAM account name, and display name for all domain users.

T1087.003
Email Account
MalwareBoomBox

BoomBox can execute an LDAP query to discover e-mail accounts for domain users.

T1102
Web Service
MalwareBoomBox

BoomBox can download files from Dropbox using a hardcoded access token.

T1105
Ingress Tool Transfer
MalwareBoomBox

BoomBox has the ability to download next stage malware components to a compromised system.

T1140
Deobfuscate/Decode Files or Information
MalwareBoomBox

BoomBox can decrypt AES-encrypted files downloaded from C2.

T1204.002
Malicious File
MalwareBoomBox

BoomBox has gained execution through user interaction with a malicious file.

T1218.011
Rundll32
MalwareBoomBox

BoomBox can use RunDLL32 for execution.

T1480
Execution Guardrails
MalwareBoomBox

BoomBox can check its current working directory and for the presence of a specific file and terminate if specific values are not found.

T1547.001
Registry Run Keys / Startup Folder
MalwareBoomBox

BoomBox can establish persistence by writing the Registry value MicroNativeCacheSvc to HKCU\Software\Microsoft\Windows\CurrentVersion\Run.

T1567.002
Exfiltration to Cloud Storage
MalwareBoomBox

BoomBox can upload data to dedicated per-victim folders in Dropbox.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.