ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0660×

34 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareClambling

Clambling can collect information from a compromised host.

T1012
Query Registry
MalwareClambling

Clambling has the ability to enumerate Registry keys, including KEY_CURRENT_USER\Software\Bitcoin\Bitcoin-Qt\strDataDir to search for a bitcoin wallet.

T1016
System Network Configuration Discovery
MalwareClambling

Clambling can enumerate the IP address of a compromised machine.

T1027
Obfuscated Files or Information
MalwareClambling

The Clambling executable has been obfuscated when dropped on a compromised host.

T1033
System Owner/User Discovery
MalwareClambling

Clambling can identify the username on a compromised host.

T1055
Process Injection
MalwareClambling

Clambling can inject into the `svchost.exe` process for execution.

T1055.012
Process Hollowing
MalwareClambling

Clambling can execute binaries through process hollowing.

T1056.001
Keylogging
MalwareClambling

Clambling can capture keystrokes on a compromised host.

T1057
Process Discovery
MalwareClambling

Clambling can enumerate processes on a targeted system.

T1059.001
PowerShell
MalwareClambling

The Clambling dropper can use PowerShell to download the malware.

T1059.003
Windows Command Shell
MalwareClambling

Clambling can use cmd.exe for command execution.

T1071
Application Layer Protocol
MalwareClambling

Clambling has the ability to use Telnet for communication.

T1071.001
Web Protocols
MalwareClambling

Clambling has the ability to communicate over HTTP.

T1082
System Information Discovery
MalwareClambling

Clambling can discover the hostname, computer name, and Windows version of a targeted machine.

T1083
File and Directory Discovery
MalwareClambling

Clambling can browse directories on a compromised host.

T1095
Non-Application Layer Protocol
MalwareClambling

Clambling has the ability to use TCP and UDP for communication.

T1102.002
Bidirectional Communication
MalwareClambling

Clambling can use Dropbox to download malicious payloads, send commands, and receive information.

T1112
Modify Registry
MalwareClambling

Clambling can set and delete Registry keys.

T1113
Screen Capture
MalwareClambling

Clambling has the ability to capture screenshots.

T1115
Clipboard Data
MalwareClambling

Clambling has the ability to capture and store clipboard data.

T1124
System Time Discovery
MalwareClambling

Clambling can determine the current time.

T1125
Video Capture
MalwareClambling

Clambling can record screen content in AVI format.

T1135
Network Share Discovery
MalwareClambling

Clambling has the ability to enumerate network shares.

T1140
Deobfuscate/Decode Files or Information
MalwareClambling

Clambling can deobfuscate its payload prior to execution.

T1204.002
Malicious File
MalwareClambling

Clambling has gained execution through luring victims into opening malicious files.

T1497.003
Time Based Checks
MalwareClambling

Clambling can wait 30 minutes before initiating contact with C2.

T1543.003
Windows Service
MalwareClambling

Clambling can register itself as a system service to gain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareClambling

Clambling can establish persistence by adding a Registry run key.

T1548.002
Bypass User Account Control
MalwareClambling

Clambling has the ability to bypass UAC using a `passuac.dll` file.

T1564.001
Hidden Files and Directories
MalwareClambling

Clambling has the ability to set its file attributes to hidden.

T1566.001
Spearphishing Attachment
MalwareClambling

Clambling has been delivered to victim's machines through malicious e-mail attachments.

T1567.002
Exfiltration to Cloud Storage
MalwareClambling

Clambling can send files from a victim's machine to Dropbox.

T1569.002
Service Execution
MalwareClambling

Clambling can create and start services on a compromised host.

T1574.001
DLL
MalwareClambling

Clambling can store a file named `mpsvc.dll`, which opens a malicious `mpsvc.mui` file, in the same folder as the legitimate Microsoft executable `MsMpEng.exe` to gain execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.