ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0681×

28 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
MalwareLizar

Lizar can run Mimikatz to harvest credentials.

T1016
System Network Configuration Discovery
MalwareLizar

Lizar has retrieved network information from a compromised host, such as the MAC address.

T1027
Obfuscated Files or Information
MalwareLizar

Lizar has obfuscated the fingerprint of the victim system, the local IP address, and the Fowler-Noll-V 1 (FNV-1) hash of the local IP address using an XOR operation. The data is then sent to the C2 server.

T1033
System Owner/User Discovery
MalwareLizar

Lizar can collect the username from the system.

T1049
System Network Connections Discovery
MalwareLizar

Lizar has a plugin to retrieve information about all active network sessions on the infected server.

T1055
Process Injection
MalwareLizar

Lizar can migrate the loader into another process.

T1055.001
Dynamic-link Library Injection
MalwareLizar

Lizar has used the PowerKatz plugin that can be loaded into the address space of a PowerShell process through reflective DLL loading.

T1055.002
Portable Executable Injection
MalwareLizar

Lizar can execute PE files in the address space of the specified process.

T1057
Process Discovery
MalwareLizar

Lizar has a plugin designed to obtain a list of processes.

T1059.001
PowerShell
MalwareLizar

Lizar has used PowerShell scripts.

T1059.003
Windows Command Shell
MalwareLizar

Lizar has a command to open the command-line on the infected system.

T1059.006
Python
MalwareLizar

Lizar has used Python scripts (ps2x.py script and ps2p.py) to execute files on remote hosts using the Impacket library.

T1082
System Information Discovery
MalwareLizar

Lizar can collect the computer name from the machine.

T1087.003
Email Account
MalwareLizar

Lizar can collect email accounts from Microsoft Outlook and Mozilla Thunderbird.

T1095
Non-Application Layer Protocol
MalwareLizar

Lizar has used a raw TCP connection to communicate with the C2 server.

T1105
Ingress Tool Transfer
MalwareLizar

Lizar can download additional plugins, files, and tools.

T1106
Native API
MalwareLizar

Lizar has used various Windows API functions on a victim's machine.

T1113
Screen Capture
MalwareLizar

Lizar can take JPEG screenshots of an infected system. Lizar has also used a plugin to take a screenshot of the infected system.

T1132.002
Non-Standard Encoding
MalwareLizar

Lizar has used a complex XOR operation to obfuscate C2 communications.

T1140
Deobfuscate/Decode Files or Information
MalwareLizar

Lizar has decrypted its configuration data, such as the C2 IP address, ports and other network communication.

T1217
Browser Information Discovery
MalwareLizar

Lizar can retrieve browser history and database files.

T1518.001
Security Software Discovery
MalwareLizar

Lizar can search for processes associated with an anti-virus product from list.

T1555.003
Credentials from Web Browsers
MalwareLizar

Lizar has a module to collect usernames and passwords stored in browsers.

T1555.004
Windows Credential Manager
MalwareLizar

Lizar has a plugin that can retrieve credentials from Internet Explorer and Microsoft Edge using `vaultcmd.exe` and another that can collect RDP access credentials using the `CredEnumerateW` function.

T1560
Archive Collected Data
MalwareLizar

Lizar has encrypted data before sending it to the server.

T1573
Encrypted Channel
MalwareLizar

Lizar can support encrypted communications between the client and server.

T1588.002
Tool
MalwareLizar

FIN7 has obtained and used tools such as Impacket, Mimikatz, and PsExec.

T1620
Reflective Code Loading
MalwareLizar

Lizar has used the Reflective DLL injection module from Github to inject itself into a process’s memory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.