ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0661×

21 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareFoggyWeb

FoggyWeb can retrieve configuration data from a compromised AD FS server.

T1027.004
Compile After Delivery
MalwareFoggyWeb

FoggyWeb can compile and execute source code sent to the compromised AD FS server via a specific HTTP POST.

T1027.013
Encrypted/Encoded File
MalwareFoggyWeb

FoggyWeb has been XOR-encoded.

T1036
Masquerading
MalwareFoggyWeb

FoggyWeb can masquerade the output of C2 commands as a fake, but legitimately formatted WebP file.

T1036.005
Match Legitimate Resource Name or Location
MalwareFoggyWeb

FoggyWeb can be disguised as a Visual Studio file such as `Windows.Data.TimeZones.zh-PH.pri` to evade detection. Also, FoggyWeb's loader can mimic a genuine `dll` file that carries out the same import functions as the legitimate Windows `version.dll` file.

T1040
Network Sniffing
MalwareFoggyWeb

FoggyWeb can configure custom listeners to passively monitor all incoming HTTP GET and POST requests sent to the AD FS server from the intranet/internet and intercept HTTP requests that match the custom URI patterns defined by the actor.

T1041
Exfiltration Over C2 Channel
MalwareFoggyWeb

FoggyWeb can remotely exfiltrate sensitive information from a compromised AD FS server.

T1057
Process Discovery
MalwareFoggyWeb

FoggyWeb's loader can enumerate all Common Language Runtimes (CLRs) and running Application Domains in the compromised AD FS server's Microsoft.IdentityServer.ServiceHost.exe process.

T1071.001
Web Protocols
MalwareFoggyWeb

FoggyWeb has the ability to communicate with C2 servers over HTTP GET/POST requests.

T1083
File and Directory Discovery
MalwareFoggyWeb

FoggyWeb's loader can check for the FoggyWeb backdoor .pri file on a compromised AD FS server.

T1105
Ingress Tool Transfer
MalwareFoggyWeb

FoggyWeb can receive additional malicious components from an actor controlled C2 server and execute them on a compromised AD FS server.

T1106
Native API
MalwareFoggyWeb

FoggyWeb's loader can use API functions to load the FoggyWeb backdoor into the same Application Domain within which the legitimate AD FS managed code is executed.

T1129
Shared Modules
MalwareFoggyWeb

FoggyWeb's loader can call the load() function to load the FoggyWeb dll into an Application Domain on a compromised AD FS server.

T1140
Deobfuscate/Decode Files or Information
MalwareFoggyWeb

FoggyWeb can be decrypted in memory using a Lightweight Encryption Algorithm (LEA)-128 key and decoded using a XOR key.

T1550
Use Alternate Authentication Material
MalwareFoggyWeb

FoggyWeb can allow abuse of a compromised AD FS server's SAML token.

T1552.004
Private Keys
MalwareFoggyWeb

FoggyWeb can retrieve token signing certificates and token decryption certificates from a compromised AD FS server.

T1560.002
Archive via Library
MalwareFoggyWeb

FoggyWeb can invoke the `Common.Compress` method to compress data with the C# GZipStream compression class.

T1560.003
Archive via Custom Method
MalwareFoggyWeb

FoggyWeb can use a dynamic XOR key and a custom XOR methodology to encode data before exfiltration. Also, FoggyWeb can encode C2 command output within a legitimate WebP file.

T1573.001
Symmetric Cryptography
MalwareFoggyWeb

FoggyWeb has used a dynamic XOR key and custom XOR methodology for C2 communications.

T1574.001
DLL
MalwareFoggyWeb

FoggyWeb's loader has used DLL Search Order Hijacking to load malicious code instead of the legitimate `version.dll` during the `Microsoft.IdentityServer.ServiceHost.exe` execution process.

T1620
Reflective Code Loading
MalwareFoggyWeb

FoggyWeb's loader has reflectively loaded .NET-based assembly/payloads into memory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.