ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0688×

20 examples

TechniqueUsed byProcedure example
T1036.004
Masquerade Task or Service
MalwareMeteor

Meteor has been disguised as the Windows Power Efficiency Diagnostics report tool.

T1047
Windows Management Instrumentation
MalwareMeteor

Meteor can use `wmic.exe` as part of its effort to delete shadow copies.

T1053.005
Scheduled Task
MalwareMeteor

Meteor execution begins from a scheduled task named `Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeAll` and it creates a separate scheduled task called `mstask` to run the wiper only once at 23:55:00.

T1057
Process Discovery
MalwareMeteor

Meteor can check if a specific process is running, such as Kaspersky's `avp.exe`.

T1059.001
PowerShell
MalwareMeteor

Meteor can use PowerShell commands to disable the network adapters on a victim machines.

T1059.003
Windows Command Shell
MalwareMeteor

Meteor can run `set.bat`, `update.bat`, `cache.bat`, `bcd.bat`, `msrun.bat`, and similar scripts.

T1070.004
File Deletion
MalwareMeteor

Meteor will delete the folder containing malicious scripts if it detects the hostname as `PIS-APP`, `PIS-MOB`, `WSUSPROXY`, or `PIS-DB`.

T1082
System Information Discovery
MalwareMeteor

Meteor has the ability to discover the hostname of a compromised host.

T1105
Ingress Tool Transfer
MalwareMeteor

Meteor has the ability to download additional files for execution on the victim's machine.

T1106
Native API
MalwareMeteor

Meteor can use `WinAPI` to remove a victim machine from an Active Directory domain.

T1484.001
Group Policy Modification
MalwareMeteor

Meteor can use group policy to push a scheduled task from the AD to all network machines.

T1485
Data Destruction
MalwareMeteor

Meteor can fill a victim's files and directories with zero-bytes in replacement of real content before deleting them.

T1489
Service Stop
MalwareMeteor

Meteor can disconnect all network adapters on a compromised host using `powershell -Command "Get-WmiObject -class Win32_NetworkAdapter | ForEach { If ($.NetEnabled) { $.Disable() } }" > NUL`.

T1490
Inhibit System Recovery
MalwareMeteor

Meteor can use `bcdedit` to delete different boot identifiers on a compromised host; it can also use `vssadmin.exe delete shadows /all /quiet` and `C:\\Windows\\system32\\wbem\\wmic.exe shadowcopy delete`.

T1491.001
Internal Defacement
MalwareMeteor

Meteor can change both the desktop wallpaper and the lock screen image to a custom image.

T1518.001
Security Software Discovery
MalwareMeteor

Meteor has the ability to search for Kaspersky Antivirus on a victim's machine.

T1531
Account Access Removal
MalwareMeteor

Meteor has the ability to change the password of local users on compromised hosts and can log off users.

T1564.003
Hidden Window
MalwareMeteor

Meteor can hide its console window upon execution to decrease its visibility to a victim.

T1685
Disable or Modify Tools
MalwareMeteor

Meteor can attempt to uninstall Kaspersky Antivirus or remove the Kaspersky license; it can also add all files and folders related to the attack to the Windows Defender exclusion list.

T1685.005
Clear Windows Event Logs
MalwareMeteor

Meteor can use Wevtutil to remove Security, System and Application Event Viewer logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.