ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0647×

18 examples

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwareTurian

Turian can insert pseudo-random characters into its network encryption setup.

T1016
System Network Configuration Discovery
MalwareTurian

Turian can retrieve the internal IP address of a compromised host.

T1027
Obfuscated Files or Information
MalwareTurian

Turian can use VMProtect for obfuscation.

T1033
System Owner/User Discovery
MalwareTurian

Turian can retrieve usernames.

T1036.004
Masquerade Task or Service
MalwareTurian

Turian can disguise as a legitimate service to blend into normal operations.

T1059.003
Windows Command Shell
MalwareTurian

Turian can create a remote shell and execute commands using cmd.

T1059.004
Unix Shell
MalwareTurian

Turian has the ability to use /bin/sh to execute commands.

T1059.006
Python
MalwareTurian

Turian has the ability to use Python to spawn a Unix shell.

T1071.001
Web Protocols
MalwareTurian

Turian has the ability to use HTTP for its C2.

T1074.001
Local Data Staging
MalwareTurian

Turian can store copied files in a specific directory prior to exfiltration.

T1082
System Information Discovery
MalwareTurian

Turian can retrieve system information including OS version, memory usage, local hostname, and system adapter information.

T1083
File and Directory Discovery
MalwareTurian

Turian can search for specific files and list directories.

T1105
Ingress Tool Transfer
MalwareTurian

Turian can download additional files and tools from its C2.

T1113
Screen Capture
MalwareTurian

Turian has the ability to take screenshots.

T1120
Peripheral Device Discovery
MalwareTurian

Turian can scan for removable media to collect data.

T1140
Deobfuscate/Decode Files or Information
MalwareTurian

Turian has the ability to use a XOR decryption key to extract C2 server domains and IP addresses.

T1547.001
Registry Run Keys / Startup Folder
MalwareTurian

Turian can establish persistence by adding Registry Run keys.

T1560.001
Archive via Utility
MalwareTurian

Turian can use WinRAR to create a password-protected archive for files of interest.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.