ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0696×

24 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareFlagpro

Flagpro can collect data from a compromised host, including Windows authentication information.

T1010
Application Window Discovery
MalwareFlagpro

Flagpro can check the name of the window displayed on the system.

T1016
System Network Configuration Discovery
MalwareFlagpro

Flagpro has been used to execute the ipconfig /all command on a victim system.

T1018
Remote System Discovery
MalwareFlagpro

Flagpro has been used to execute net view on a targeted system.

T1027
Obfuscated Files or Information
MalwareFlagpro

Flagpro has been delivered within ZIP or RAR password-protected archived files.

T1029
Scheduled Transfer
MalwareFlagpro

Flagpro has the ability to wait for a specified time interval between communicating with and executing commands from C2.

T1033
System Owner/User Discovery
MalwareFlagpro

Flagpro has been used to run the whoami command on the system.

T1036
Masquerading
MalwareFlagpro

Flagpro can download malicious files with a .tmp extension and append them with .exe prior to execution.

T1041
Exfiltration Over C2 Channel
MalwareFlagpro

Flagpro has exfiltrated data to the C2 server.

T1049
System Network Connections Discovery
MalwareFlagpro

Flagpro has been used to execute netstat -ano on a compromised host.

T1057
Process Discovery
MalwareFlagpro

Flagpro has been used to run the tasklist command on a compromised system.

T1059.003
Windows Command Shell
MalwareFlagpro

Flagpro can use `cmd.exe` to execute commands received from C2.

T1059.005
Visual Basic
MalwareFlagpro

Flagpro can execute malicious VBA macros embedded in .xlsm files.

T1069.001
Local Groups
MalwareFlagpro

Flagpro has been used to execute the net localgroup administrators command on a targeted system.

T1070
Indicator Removal
MalwareFlagpro

Flagpro can close specific Windows Security and Internet Explorer dialog boxes to mask external connections.

T1071.001
Web Protocols
MalwareFlagpro

Flagpro can communicate with its C2 using HTTP.

T1105
Ingress Tool Transfer
MalwareFlagpro

Flagpro can download additional malware from the C2 server.

T1106
Native API
MalwareFlagpro

Flagpro can use Native API to enable obfuscation including `GetLastError` and `GetTickCount`.

T1132.001
Standard Encoding
MalwareFlagpro

Flagpro has encoded bidirectional data communications between a target system and C2 server using Base64.

T1135
Network Share Discovery
MalwareFlagpro

Flagpro has been used to execute `net view` to discover mapped network shares.

T1204.002
Malicious File
MalwareFlagpro

Flagpro has relied on users clicking a malicious attachment delivered through spearphishing.

T1547.001
Registry Run Keys / Startup Folder
MalwareFlagpro

Flagpro has dropped an executable file to the startup directory.

T1566.001
Spearphishing Attachment
MalwareFlagpro

Flagpro has been distributed via spearphishing as an email attachment.

T1614.001
System Language Discovery
MalwareFlagpro

Flagpro can check whether the target system is using Japanese, Taiwanese, or English through detection of specific Windows Security and Internet Explorer dialog.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.