Real-world descriptions of how a group, tool or campaign used a technique.
34 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareClambling | Clambling can collect information from a compromised host. |
| T1012 Query Registry |
MalwareClambling | Clambling has the ability to enumerate Registry keys, including |
| T1016 System Network Configuration Discovery |
MalwareClambling | Clambling can enumerate the IP address of a compromised machine. |
| T1027 Obfuscated Files or Information |
MalwareClambling | The Clambling executable has been obfuscated when dropped on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareClambling | Clambling can identify the username on a compromised host. |
| T1055 Process Injection |
MalwareClambling | Clambling can inject into the `svchost.exe` process for execution. |
| T1055.012 Process Hollowing |
MalwareClambling | Clambling can execute binaries through process hollowing. |
| T1056.001 Keylogging |
MalwareClambling | Clambling can capture keystrokes on a compromised host. |
| T1057 Process Discovery |
MalwareClambling | Clambling can enumerate processes on a targeted system. |
| T1059.001 PowerShell |
MalwareClambling | The Clambling dropper can use PowerShell to download the malware. |
| T1059.003 Windows Command Shell |
MalwareClambling | Clambling can use cmd.exe for command execution. |
| T1071 Application Layer Protocol |
MalwareClambling | Clambling has the ability to use Telnet for communication. |
| T1071.001 Web Protocols |
MalwareClambling | Clambling has the ability to communicate over HTTP. |
| T1082 System Information Discovery |
MalwareClambling | Clambling can discover the hostname, computer name, and Windows version of a targeted machine. |
| T1083 File and Directory Discovery |
MalwareClambling | Clambling can browse directories on a compromised host. |
| T1095 Non-Application Layer Protocol |
MalwareClambling | Clambling has the ability to use TCP and UDP for communication. |
| T1102.002 Bidirectional Communication |
MalwareClambling | Clambling can use Dropbox to download malicious payloads, send commands, and receive information. |
| T1112 Modify Registry |
MalwareClambling | Clambling can set and delete Registry keys. |
| T1113 Screen Capture |
MalwareClambling | Clambling has the ability to capture screenshots. |
| T1115 Clipboard Data |
MalwareClambling | Clambling has the ability to capture and store clipboard data. |
| T1124 System Time Discovery |
MalwareClambling | Clambling can determine the current time. |
| T1125 Video Capture |
MalwareClambling | Clambling can record screen content in AVI format. |
| T1135 Network Share Discovery |
MalwareClambling | Clambling has the ability to enumerate network shares. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareClambling | Clambling can deobfuscate its payload prior to execution. |
| T1204.002 Malicious File |
MalwareClambling | Clambling has gained execution through luring victims into opening malicious files. |
| T1497.003 Time Based Checks |
MalwareClambling | Clambling can wait 30 minutes before initiating contact with C2. |
| T1543.003 Windows Service |
MalwareClambling | Clambling can register itself as a system service to gain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareClambling | Clambling can establish persistence by adding a Registry run key. |
| T1548.002 Bypass User Account Control |
MalwareClambling | Clambling has the ability to bypass UAC using a `passuac.dll` file. |
| T1564.001 Hidden Files and Directories |
MalwareClambling | Clambling has the ability to set its file attributes to hidden. |
| T1566.001 Spearphishing Attachment |
MalwareClambling | Clambling has been delivered to victim's machines through malicious e-mail attachments. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareClambling | Clambling can send files from a victim's machine to Dropbox. |
| T1569.002 Service Execution |
MalwareClambling | Clambling can create and start services on a compromised host. |
| T1574.001 DLL |
MalwareClambling | Clambling can store a file named `mpsvc.dll`, which opens a malicious `mpsvc.mui` file, in the same folder as the legitimate Microsoft executable `MsMpEng.exe` to gain execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.