ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0659×

19 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareDiavol

Diavol can enumerate victims' local and external IPs when registering with C2.

T1018
Remote System Discovery
MalwareDiavol

Diavol can use the ARP table to find remote hosts to scan.

T1021.002
SMB/Windows Admin Shares
MalwareDiavol

Diavol can spread throughout a network via SMB prior to encryption.

T1027
Obfuscated Files or Information
MalwareDiavol

Diavol has Base64 encoded the RSA public key used for encrypting files.

T1027.003
Steganography
MalwareDiavol

Diavol has obfuscated its main code routines within bitmap images as part of its anti-analysis techniques.

T1033
System Owner/User Discovery
MalwareDiavol

Diavol can collect the username from a compromised host.

T1057
Process Discovery
MalwareDiavol

Diavol has used `CreateToolhelp32Snapshot`, `Process32First`, and `Process32Next` API calls to enumerate the running processes in the system.

T1071.001
Web Protocols
MalwareDiavol

Diavol has used HTTP GET and POST requests for C2.

T1082
System Information Discovery
MalwareDiavol

Diavol can collect the computer name and OS version from the system.

T1083
File and Directory Discovery
MalwareDiavol

Diavol has a command to traverse the files and directories in a given path.

T1105
Ingress Tool Transfer
MalwareDiavol

Diavol can receive configuration updates and additional payloads including wscpy.exe from C2.

T1106
Native API
MalwareDiavol

Diavol has used several API calls like `GetLogicalDriveStrings`, `SleepEx`, `SystemParametersInfoAPI`, `CryptEncrypt`, and others to execute parts of its attack.

T1135
Network Share Discovery
MalwareDiavol

Diavol has a `ENMDSKS` command to enumerates available network shares.

T1485
Data Destruction
MalwareDiavol

Diavol can delete specified files from a targeted system.

T1486
Data Encrypted for Impact
MalwareDiavol

Diavol has encrypted files using an RSA key though the `CryptEncrypt` API and has appended filenames with ".lock64".

T1489
Service Stop
MalwareDiavol

Diavol will terminate services using the Service Control Manager (SCM) API.

T1490
Inhibit System Recovery
MalwareDiavol

Diavol can delete shadow copies using the `IVssBackupComponents` COM object to call the `DeleteSnapshots` method.

T1491.001
Internal Defacement
MalwareDiavol

After encryption, Diavol will capture the desktop background window, set the background color to black, and change the desktop wallpaper to a newly created bitmap image with the text “All your files are encrypted! For more information see “README-FOR-DECRYPT.txt".

T1685
Disable or Modify Tools
MalwareDiavol

Diavol can attempt to stop security software.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.