ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0666×

33 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareGelsemium

Gelsemium can collect data from a compromised host.

T1008
Fallback Channels
MalwareGelsemium

Gelsemium can use multiple domains and protocols in C2.

T1012
Query Registry
MalwareGelsemium

Gelsemium can open random files and Registry keys to obscure malware behavior from sandbox analysis.

T1027.011
Fileless Storage
MalwareGelsemium

Gelsemium can store its components in the Registry.

T1027.015
Compression
MalwareGelsemium

Gelsemium has the ability to compress its components.

T1027.016
Junk Code Insertion
MalwareGelsemium

Gelsemium can use junk code to hide functions and evade detection.

T1033
System Owner/User Discovery
MalwareGelsemium

Gelsemium has the ability to distinguish between a standard user and an administrator on a compromised host.

T1036.001
Invalid Code Signature
MalwareGelsemium

Gelsemium has used unverified signatures on malicious DLLs.

T1036.005
Match Legitimate Resource Name or Location
MalwareGelsemium

Gelsemium has named malicious binaries `serv.exe`, `winprint.dll`, and `chrome_elf.dll` and has set its persistence in the Registry with the key value Chrome Update to appear legitimate.

T1055.001
Dynamic-link Library Injection
MalwareGelsemium

Gelsemium has the ability to inject DLLs into specific processes.

T1057
Process Discovery
MalwareGelsemium

Gelsemium can enumerate running processes.

T1059.003
Windows Command Shell
MalwareGelsemium

Gelsemium can use a batch script to delete itself.

T1070.004
File Deletion
MalwareGelsemium

Gelsemium can delete its dropper component from the targeted system.

T1070.006
Timestomp
MalwareGelsemium

Gelsemium has the ability to perform timestomping of files on targeted systems.

T1071.001
Web Protocols
MalwareGelsemium

Gelsemium can use HTTP/S in C2 communications.

T1071.004
DNS
MalwareGelsemium

Gelsemium has the ability to use DNS in communication with C2.

T1082
System Information Discovery
MalwareGelsemium

Gelsemium can determine the operating system and whether a targeted machine has a 32 or 64 bit architecture.

T1083
File and Directory Discovery
MalwareGelsemium

Gelsemium can retrieve data from specific Windows directories, as well as open random files as part of Virtualization/Sandbox Evasion.

T1095
Non-Application Layer Protocol
MalwareGelsemium

Gelsemium has the ability to use TCP and UDP in C2 communications.

T1105
Ingress Tool Transfer
MalwareGelsemium

Gelsemium can download additional plug-ins to a compromised host.

T1106
Native API
MalwareGelsemium

Gelsemium has the ability to use various Windows API functions to perform tasks.

T1112
Modify Registry
MalwareGelsemium

Gelsemium can modify the Registry to store its components.

T1134
Access Token Manipulation
MalwareGelsemium

Gelsemium can use token manipulation to bypass UAC on Windows7 systems.

T1140
Deobfuscate/Decode Files or Information
MalwareGelsemium

Gelsemium can decompress and decrypt DLLs and shellcode.

T1497
Virtualization/Sandbox Evasion
MalwareGelsemium

Gelsemium can use junk code to generate random activity to obscure malware behavior.

T1518.001
Security Software Discovery
MalwareGelsemium

Gelsemium can check for the presence of specific security products.

T1543.003
Windows Service
MalwareGelsemium

Gelsemium can drop itself in `C:\Windows\System32\spool\prtprocs\x64\winprint.dll` as an alternative Print Processor to be loaded automatically when the spoolsv Windows service starts.

T1547.001
Registry Run Keys / Startup Folder
MalwareGelsemium

Gelsemium can set persistence with a Registry run key.

T1547.012
Print Processors
MalwareGelsemium

Gelsemium can drop itself in C:\Windows\System32\spool\prtprocs\x64\winprint.dll to be loaded automatically by the spoolsv Windows service.

T1548.002
Bypass User Account Control
MalwareGelsemium

Gelsemium can bypass UAC to elevate process privileges on a compromised host.

T1559.001
Component Object Model
MalwareGelsemium

Gelsemium can use the `IARPUinstallerStringLauncher` COM interface are part of its UAC bypass process.

T1568
Dynamic Resolution
MalwareGelsemium

Gelsemium can use dynamic DNS domain names in C2.

T1620
Reflective Code Loading
MalwareGelsemium

Gelsemium can use custom shellcode to map embedded DLLs into memory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.