ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0640×

17 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareAvaddon

Avaddon can collect the external IP address of the victim.

T1027
Obfuscated Files or Information
MalwareAvaddon

Avaddon has used encrypted strings.

T1047
Windows Management Instrumentation
MalwareAvaddon

Avaddon uses wmic.exe to delete shadow copies.

T1057
Process Discovery
MalwareAvaddon

Avaddon has collected information about running processes.

T1059.007
JavaScript
MalwareAvaddon

Avaddon has been executed through a malicious JScript downloader.

T1083
File and Directory Discovery
MalwareAvaddon

Avaddon has searched for specific files prior to encryption.

T1106
Native API
MalwareAvaddon

Avaddon has used the Windows Crypto API to generate an AES key.

T1112
Modify Registry
MalwareAvaddon

Avaddon modifies several registry keys for persistence and UAC bypass.

T1135
Network Share Discovery
MalwareAvaddon

Avaddon has enumerated shared folders and mapped volumes.

T1140
Deobfuscate/Decode Files or Information
MalwareAvaddon

Avaddon has decrypted encrypted strings.

T1486
Data Encrypted for Impact
MalwareAvaddon

Avaddon encrypts the victim system using a combination of AES256 and RSA encryption schemes.

T1489
Service Stop
MalwareAvaddon

Avaddon looks for and attempts to stop database processes.

T1490
Inhibit System Recovery
MalwareAvaddon

Avaddon deletes backups and shadow copies using native system tools.

T1547.001
Registry Run Keys / Startup Folder
MalwareAvaddon

Avaddon uses registry run keys for persistence.

T1548.002
Bypass User Account Control
MalwareAvaddon

Avaddon bypasses UAC using the CMSTPLUA COM interface.

T1614.001
System Language Discovery
MalwareAvaddon

Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities.

T1685
Disable or Modify Tools
MalwareAvaddon

Avaddon looks for and attempts to stop anti-malware solutions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.