Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareDiavol | Diavol can enumerate victims' local and external IPs when registering with C2. |
| T1018 Remote System Discovery |
MalwareDiavol | Diavol can use the ARP table to find remote hosts to scan. |
| T1021.002 SMB/Windows Admin Shares |
MalwareDiavol | Diavol can spread throughout a network via SMB prior to encryption. |
| T1027 Obfuscated Files or Information |
MalwareDiavol | Diavol has Base64 encoded the RSA public key used for encrypting files. |
| T1027.003 Steganography |
MalwareDiavol | Diavol has obfuscated its main code routines within bitmap images as part of its anti-analysis techniques. |
| T1033 System Owner/User Discovery |
MalwareDiavol | Diavol can collect the username from a compromised host. |
| T1057 Process Discovery |
MalwareDiavol | Diavol has used `CreateToolhelp32Snapshot`, `Process32First`, and `Process32Next` API calls to enumerate the running processes in the system. |
| T1071.001 Web Protocols |
MalwareDiavol | Diavol has used HTTP GET and POST requests for C2. |
| T1082 System Information Discovery |
MalwareDiavol | Diavol can collect the computer name and OS version from the system. |
| T1083 File and Directory Discovery |
MalwareDiavol | Diavol has a command to traverse the files and directories in a given path. |
| T1105 Ingress Tool Transfer |
MalwareDiavol | Diavol can receive configuration updates and additional payloads including wscpy.exe from C2. |
| T1106 Native API |
MalwareDiavol | Diavol has used several API calls like `GetLogicalDriveStrings`, `SleepEx`, `SystemParametersInfoAPI`, `CryptEncrypt`, and others to execute parts of its attack. |
| T1135 Network Share Discovery |
MalwareDiavol | Diavol has a `ENMDSKS` command to enumerates available network shares. |
| T1485 Data Destruction |
MalwareDiavol | Diavol can delete specified files from a targeted system. |
| T1486 Data Encrypted for Impact |
MalwareDiavol | Diavol has encrypted files using an RSA key though the `CryptEncrypt` API and has appended filenames with ".lock64". |
| T1489 Service Stop |
MalwareDiavol | Diavol will terminate services using the Service Control Manager (SCM) API. |
| T1490 Inhibit System Recovery |
MalwareDiavol | Diavol can delete shadow copies using the `IVssBackupComponents` COM object to call the `DeleteSnapshots` method. |
| T1491.001 Internal Defacement |
MalwareDiavol | After encryption, Diavol will capture the desktop background window, set the background color to black, and change the desktop wallpaper to a newly created bitmap image with the text “All your files are encrypted! For more information see “README-FOR-DECRYPT.txt". |
| T1685 Disable or Modify Tools |
MalwareDiavol | Diavol can attempt to stop security software. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.