ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0697×

26 examples

TechniqueUsed byProcedure example
T1027.015
Compression
MalwareHermeticWiper

HermeticWiper can compress 32-bit and 64-bit driver files with the Lempel-Ziv algorithm.

T1036.005
Match Legitimate Resource Name or Location
MalwareHermeticWiper

HermeticWiper has used the name `postgressql.exe` to mask a malicious payload.

T1053.005
Scheduled Task
MalwareHermeticWiper

HermeticWiper has the ability to use scheduled tasks for execution.

T1059.003
Windows Command Shell
MalwareHermeticWiper

HermeticWiper can use `cmd.exe /Q/c move CSIDL_SYSTEM_DRIVE\temp\sys.tmp1 CSIDL_WINDOWS\policydefinitions\postgresql.exe 1> \\127.0.0.1\ADMIN$\_1636727589.6007507 2>&1` to deploy on an infected system.

T1070
Indicator Removal
MalwareHermeticWiper

HermeticWiper can disable pop-up information about folders and desktop items and delete Registry keys to hide malicious services.

T1070.004
File Deletion
MalwareHermeticWiper

HermeticWiper has the ability to overwrite its own file with random bites.

T1082
System Information Discovery
MalwareHermeticWiper

HermeticWiper can determine the OS version and bitness on a targeted host.

T1083
File and Directory Discovery
MalwareHermeticWiper

HermeticWiper can enumerate common folders such as My Documents, Desktop, and AppData.

T1106
Native API
MalwareHermeticWiper

HermeticWiper can call multiple Windows API functions used for privilege escalation, service execution, and to overwrite random bites of data.

T1112
Modify Registry
MalwareHermeticWiper

HermeticWiper has the ability to modify Registry keys to disable crash dumps, colors for compressed files, and pop-up information about folders and desktop items.

T1134
Access Token Manipulation
MalwareHermeticWiper

HermeticWiper can use `AdjustTokenPrivileges` to grant itself privileges for debugging with `SeDebugPrivilege`, creating backups with `SeBackupPrivilege`, loading drivers with `SeLoadDriverPrivilege`, and shutting down a local system with `SeShutdownPrivilege`.

T1140
Deobfuscate/Decode Files or Information
MalwareHermeticWiper

HermeticWiper can decompress and copy driver files using `LZCopy`.

T1484.001
Group Policy Modification
MalwareHermeticWiper

HermeticWiper has the ability to deploy through an infected system's default domain policy.

T1485
Data Destruction
MalwareHermeticWiper

HermeticWiper can recursively wipe folders and files in `Windows`, `Program Files`, `Program Files(x86)`, `PerfLogs`, `Boot, System`, `Volume Information`, and `AppData` folders using `FSCTL_MOVE_FILE`. HermeticWiper can also overwrite symbolic links and big files in `My Documents` and on the Desktop with random bytes.

T1489
Service Stop
MalwareHermeticWiper

HermeticWiper has the ability to stop the Volume Shadow Copy service.

T1490
Inhibit System Recovery
MalwareHermeticWiper

HermeticWiper can disable the VSS service on a compromised host using the service control manager.

T1497.003
Time Based Checks
MalwareHermeticWiper

HermeticWiper has the ability to receive a command parameter to sleep prior to carrying out destructive actions on a targeted host.

T1529
System Shutdown/Reboot
MalwareHermeticWiper

HermeticWiper can initiate a system shutdown.

T1543.003
Windows Service
MalwareHermeticWiper

HermeticWiper can load drivers by creating a new service using the `CreateServiceW` API.

T1553.002
Code Signing
MalwareHermeticWiper

The HermeticWiper executable has been signed with a legitimate certificate issued to Hermetica Digital Ltd.

T1561.001
Disk Content Wipe
MalwareHermeticWiper

HermeticWiper has the ability to corrupt disk partitions and obtain raw disk access to destroy data.

T1561.002
Disk Structure Wipe
MalwareHermeticWiper

HermeticWiper has the ability to corrupt disk partitions, damage the Master Boot Record (MBR), and overwrite the Master File Table (MFT) of all available physical drives.

T1569.002
Service Execution
MalwareHermeticWiper

HermeticWiper can create system services to aid in executing the payload.

T1680
Local Storage Discovery
MalwareHermeticWiper

HermeticWiper can enumerate physical drives on a targeted host.

T1685
Disable or Modify Tools
MalwareHermeticWiper

HermeticWiper has the ability to set the `HKLM:\SYSTEM\\CurrentControlSet\\Control\\CrashControl\CrashDumpEnabled` Registry key to `0` in order to disable crash dumps.

T1685.005
Clear Windows Event Logs
MalwareHermeticWiper

HermeticWiper can overwrite the `C:\Windows\System32\winevt\Logs` file on a targeted system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.