Real-world descriptions of how a group, tool or campaign used a technique.
26 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.015 Compression |
MalwareHermeticWiper | HermeticWiper can compress 32-bit and 64-bit driver files with the Lempel-Ziv algorithm. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareHermeticWiper | HermeticWiper has used the name `postgressql.exe` to mask a malicious payload. |
| T1053.005 Scheduled Task |
MalwareHermeticWiper | HermeticWiper has the ability to use scheduled tasks for execution. |
| T1059.003 Windows Command Shell |
MalwareHermeticWiper | HermeticWiper can use `cmd.exe /Q/c move CSIDL_SYSTEM_DRIVE\temp\sys.tmp1 CSIDL_WINDOWS\policydefinitions\postgresql.exe 1> \\127.0.0.1\ADMIN$\_1636727589.6007507 2>&1` to deploy on an infected system. |
| T1070 Indicator Removal |
MalwareHermeticWiper | HermeticWiper can disable pop-up information about folders and desktop items and delete Registry keys to hide malicious services. |
| T1070.004 File Deletion |
MalwareHermeticWiper | HermeticWiper has the ability to overwrite its own file with random bites. |
| T1082 System Information Discovery |
MalwareHermeticWiper | HermeticWiper can determine the OS version and bitness on a targeted host. |
| T1083 File and Directory Discovery |
MalwareHermeticWiper | HermeticWiper can enumerate common folders such as My Documents, Desktop, and AppData. |
| T1106 Native API |
MalwareHermeticWiper | HermeticWiper can call multiple Windows API functions used for privilege escalation, service execution, and to overwrite random bites of data. |
| T1112 Modify Registry |
MalwareHermeticWiper | HermeticWiper has the ability to modify Registry keys to disable crash dumps, colors for compressed files, and pop-up information about folders and desktop items. |
| T1134 Access Token Manipulation |
MalwareHermeticWiper | HermeticWiper can use `AdjustTokenPrivileges` to grant itself privileges for debugging with `SeDebugPrivilege`, creating backups with `SeBackupPrivilege`, loading drivers with `SeLoadDriverPrivilege`, and shutting down a local system with `SeShutdownPrivilege`. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHermeticWiper | HermeticWiper can decompress and copy driver files using `LZCopy`. |
| T1484.001 Group Policy Modification |
MalwareHermeticWiper | HermeticWiper has the ability to deploy through an infected system's default domain policy. |
| T1485 Data Destruction |
MalwareHermeticWiper | HermeticWiper can recursively wipe folders and files in `Windows`, `Program Files`, `Program Files(x86)`, `PerfLogs`, `Boot, System`, `Volume Information`, and `AppData` folders using `FSCTL_MOVE_FILE`. HermeticWiper can also overwrite symbolic links and big files in `My Documents` and on the Desktop with random bytes. |
| T1489 Service Stop |
MalwareHermeticWiper | HermeticWiper has the ability to stop the Volume Shadow Copy service. |
| T1490 Inhibit System Recovery |
MalwareHermeticWiper | HermeticWiper can disable the VSS service on a compromised host using the service control manager. |
| T1497.003 Time Based Checks |
MalwareHermeticWiper | HermeticWiper has the ability to receive a command parameter to sleep prior to carrying out destructive actions on a targeted host. |
| T1529 System Shutdown/Reboot |
MalwareHermeticWiper | HermeticWiper can initiate a system shutdown. |
| T1543.003 Windows Service |
MalwareHermeticWiper | HermeticWiper can load drivers by creating a new service using the `CreateServiceW` API. |
| T1553.002 Code Signing |
MalwareHermeticWiper | The HermeticWiper executable has been signed with a legitimate certificate issued to Hermetica Digital Ltd. |
| T1561.001 Disk Content Wipe |
MalwareHermeticWiper | HermeticWiper has the ability to corrupt disk partitions and obtain raw disk access to destroy data. |
| T1561.002 Disk Structure Wipe |
MalwareHermeticWiper | HermeticWiper has the ability to corrupt disk partitions, damage the Master Boot Record (MBR), and overwrite the Master File Table (MFT) of all available physical drives. |
| T1569.002 Service Execution |
MalwareHermeticWiper | HermeticWiper can create system services to aid in executing the payload. |
| T1680 Local Storage Discovery |
MalwareHermeticWiper | HermeticWiper can enumerate physical drives on a targeted host. |
| T1685 Disable or Modify Tools |
MalwareHermeticWiper | HermeticWiper has the ability to set the `HKLM:\SYSTEM\\CurrentControlSet\\Control\\CrashControl\CrashDumpEnabled` Registry key to `0` in order to disable crash dumps. |
| T1685.005 Clear Windows Event Logs |
MalwareHermeticWiper | HermeticWiper can overwrite the `C:\Windows\System32\winevt\Logs` file on a targeted system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.