Real-world descriptions of how a group, tool or campaign used a technique.
37 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareSaint Bot | Saint Bot can collect files and information from a compromised host. |
| T1012 Query Registry |
MalwareSaint Bot | Saint Bot has used `check_registry_keys` as part of its environmental checks. |
| T1016 System Network Configuration Discovery |
MalwareSaint Bot | Saint Bot can collect the IP address of a victim machine. |
| T1027 Obfuscated Files or Information |
MalwareSaint Bot | Saint Bot has been obfuscated to help avoid detection. |
| T1027.002 Software Packing |
MalwareSaint Bot | Saint Bot has been packed using a dark market crypter. |
| T1033 System Owner/User Discovery |
MalwareSaint Bot | Saint Bot can collect the username from a compromised host. |
| T1036 Masquerading |
MalwareSaint Bot | Saint Bot has renamed malicious binaries as `wallpaper.mp4` and `slideshow.mp4` to avoid detection. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSaint Bot | Saint Bot has been disguised as a legitimate executable, including as Windows SDK. |
| T1053.005 Scheduled Task |
MalwareSaint Bot | Saint Bot has created a scheduled task named "Maintenance" to establish persistence. |
| T1055.001 Dynamic-link Library Injection |
MalwareSaint Bot | Saint Bot has injected its DLL component into `EhStorAurhn.exe`. |
| T1055.004 Asynchronous Procedure Call |
MalwareSaint Bot | Saint Bot has written its payload into a newly-created `EhStorAuthn.exe` process using `ZwWriteVirtualMemory` and executed it using `NtQueueApcThread` and `ZwAlertResumeThread`. |
| T1055.012 Process Hollowing |
MalwareSaint Bot | The Saint Bot loader has used API calls to spawn `MSBuild.exe` in a suspended state before injecting the decrypted Saint Bot binary into it. |
| T1057 Process Discovery |
MalwareSaint Bot | Saint Bot has enumerated running processes on a compromised host to determine if it is running under the process name `dfrgui.exe`. |
| T1059.001 PowerShell |
MalwareSaint Bot | Saint Bot has used PowerShell for execution. |
| T1059.003 Windows Command Shell |
MalwareSaint Bot | Saint Bot has used `cmd.exe` and `.bat` scripts for execution. |
| T1059.005 Visual Basic |
MalwareSaint Bot | Saint Bot has used `.vbs` scripts for execution. |
| T1070.004 File Deletion |
MalwareSaint Bot | Saint Bot can run a batch script named `del.bat` to remove any Saint Bot payload-linked files from a compromise system if anti-analysis or locale checks fail. |
| T1071.001 Web Protocols |
MalwareSaint Bot | Saint Bot has used HTTP for C2 communications. |
| T1082 System Information Discovery |
MalwareSaint Bot | Saint Bot can identify the OS version, CPU, and other details from a victim's machine. |
| T1083 File and Directory Discovery |
MalwareSaint Bot | Saint Bot can search a compromised host for specific files. |
| T1105 Ingress Tool Transfer |
MalwareSaint Bot | Saint Bot can download additional files onto a compromised host. |
| T1106 Native API |
MalwareSaint Bot | Saint Bot has used different API calls, including `GetProcAddress`, `VirtualAllocEx`, `WriteProcessMemory`, `CreateProcessA`, and `SetThreadContext`. |
| T1132.001 Standard Encoding |
MalwareSaint Bot | Saint Bot has used Base64 to encode its C2 communications. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSaint Bot | Saint Bot can deobfuscate strings and files for execution. |
| T1204.001 Malicious Link |
MalwareSaint Bot | Saint Bot has relied on users to click on a malicious link delivered via a spearphishing. |
| T1204.002 Malicious File |
MalwareSaint Bot | Saint Bot has relied on users to execute a malicious attachment delivered via spearphishing. |
| T1218.004 InstallUtil |
MalwareSaint Bot | Saint Bot had used `InstallUtil.exe` to download and deploy executables. |
| T1218.010 Regsvr32 |
MalwareSaint Bot | Saint Bot has used `regsvr32` to execute scripts. |
| T1497.001 System Checks |
MalwareSaint Bot | Saint Bot has run several virtual machine and sandbox checks, including checking if `Sbiedll.dll` is present in a list of loaded modules, comparing the machine name to `HAL9TH` and the user name to `JohnDoe`, and checking the BIOS version for known virtual machine identifiers. |
| T1497.003 Time Based Checks |
MalwareSaint Bot | Saint Bot has used the command `timeout 20` to pause the execution of its initial loader. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSaint Bot | Saint Bot has established persistence by being copied to the Startup directory or through the `\Software\Microsoft\Windows\CurrentVersion\Run` registry key. |
| T1548.002 Bypass User Account Control |
MalwareSaint Bot | Saint Bot has attempted to bypass UAC using `fodhelper.exe` to escalate privileges. |
| T1566.001 Spearphishing Attachment |
MalwareSaint Bot | Saint Bot has been distributed as malicious attachments within spearphishing emails. |
| T1566.002 Spearphishing Link |
MalwareSaint Bot | Saint Bot has been distributed through malicious links contained within spearphishing emails. |
| T1574 Hijack Execution Flow |
MalwareSaint Bot | Saint Bot will use the malicious file |
| T1614 System Location Discovery |
MalwareSaint Bot | Saint Bot has conducted system locale checks to see if the compromised host is in Russia, Ukraine, Belarus, Armenia, Kazakhstan, or Moldova. |
| T1622 Debugger Evasion |
MalwareSaint Bot | Saint Bot has used `is_debugger_present` as part of its environmental checks. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.