ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0698×

16 examples

TechniqueUsed byProcedure example
T1018
Remote System Discovery
MalwareHermeticWizard

HermeticWizard can find machines on the local network by gathering known local IP addresses through `DNSGetCacheDataTable`, `GetIpNetTable`,`WNetOpenEnumW(RESOURCE_GLOBALNET, RESOURCETYPE_ANY)`,`NetServerEnum`,`GetTcpTable`, and `GetAdaptersAddresses.`

T1021.002
SMB/Windows Admin Shares
MalwareHermeticWizard

HermeticWizard can use a list of hardcoded credentials to to authenticate via NTLMSSP to the SMB shares on remote systems.

T1027.013
Encrypted/Encoded File
MalwareHermeticWizard

HermeticWizard has the ability to encrypt PE files with a reverse XOR loop.

T1036.005
Match Legitimate Resource Name or Location
MalwareHermeticWizard

HermeticWizard has been named `exec_32.dll` to mimic a legitimate MS Outlook .dll.

T1046
Network Service Discovery
MalwareHermeticWizard

HermeticWizard has the ability to scan ports on a compromised network.

T1047
Windows Management Instrumentation
MalwareHermeticWizard

HermeticWizard can use WMI to create a new process on a remote machine via `C:\windows\system32\cmd.exe /c start C:\windows\system32\\regsvr32.exe /s /iC:\windows\<filename>.dll`.

T1059.003
Windows Command Shell
MalwareHermeticWizard

HermeticWizard can use `cmd.exe` for execution on compromised hosts.

T1106
Native API
MalwareHermeticWizard

HermeticWizard can connect to remote shares using `WNetAddConnection2W`.

T1110.001
Password Guessing
MalwareHermeticWizard

HermeticWizard can use a list of hardcoded credentials in attempt to authenticate to SMB shares.

T1218.010
Regsvr32
MalwareHermeticWizard

HermeticWizard has used `regsvr32.exe /s /i` to execute malicious payloads.

T1218.011
Rundll32
MalwareHermeticWizard

HermeticWizard has the ability to create a new process using `rundll32`.

T1553.002
Code Signing
MalwareHermeticWizard

HermeticWizard has been signed by valid certificates assigned to Hermetica Digital.

T1559.001
Component Object Model
MalwareHermeticWizard

HermeticWizard can execute files on remote machines using DCOM.

T1569.002
Service Execution
MalwareHermeticWizard

HermeticWizard can use `OpenRemoteServiceManager` to create a service.

T1570
Lateral Tool Transfer
MalwareHermeticWizard

HermeticWizard can copy files to other machines on a compromised network.

T1685.005
Clear Windows Event Logs
MalwareHermeticWizard

HermeticWizard has the ability to use `wevtutil cl system` to clear event logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.