ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1018×

37 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareSaint Bot

Saint Bot can collect files and information from a compromised host.

T1012
Query Registry
MalwareSaint Bot

Saint Bot has used `check_registry_keys` as part of its environmental checks.

T1016
System Network Configuration Discovery
MalwareSaint Bot

Saint Bot can collect the IP address of a victim machine.

T1027
Obfuscated Files or Information
MalwareSaint Bot

Saint Bot has been obfuscated to help avoid detection.

T1027.002
Software Packing
MalwareSaint Bot

Saint Bot has been packed using a dark market crypter.

T1033
System Owner/User Discovery
MalwareSaint Bot

Saint Bot can collect the username from a compromised host.

T1036
Masquerading
MalwareSaint Bot

Saint Bot has renamed malicious binaries as `wallpaper.mp4` and `slideshow.mp4` to avoid detection.

T1036.005
Match Legitimate Resource Name or Location
MalwareSaint Bot

Saint Bot has been disguised as a legitimate executable, including as Windows SDK.

T1053.005
Scheduled Task
MalwareSaint Bot

Saint Bot has created a scheduled task named "Maintenance" to establish persistence.

T1055.001
Dynamic-link Library Injection
MalwareSaint Bot

Saint Bot has injected its DLL component into `EhStorAurhn.exe`.

T1055.004
Asynchronous Procedure Call
MalwareSaint Bot

Saint Bot has written its payload into a newly-created `EhStorAuthn.exe` process using `ZwWriteVirtualMemory` and executed it using `NtQueueApcThread` and `ZwAlertResumeThread`.

T1055.012
Process Hollowing
MalwareSaint Bot

The Saint Bot loader has used API calls to spawn `MSBuild.exe` in a suspended state before injecting the decrypted Saint Bot binary into it.

T1057
Process Discovery
MalwareSaint Bot

Saint Bot has enumerated running processes on a compromised host to determine if it is running under the process name `dfrgui.exe`.

T1059.001
PowerShell
MalwareSaint Bot

Saint Bot has used PowerShell for execution.

T1059.003
Windows Command Shell
MalwareSaint Bot

Saint Bot has used `cmd.exe` and `.bat` scripts for execution.

T1059.005
Visual Basic
MalwareSaint Bot

Saint Bot has used `.vbs` scripts for execution.

T1070.004
File Deletion
MalwareSaint Bot

Saint Bot can run a batch script named `del.bat` to remove any Saint Bot payload-linked files from a compromise system if anti-analysis or locale checks fail.

T1071.001
Web Protocols
MalwareSaint Bot

Saint Bot has used HTTP for C2 communications.

T1082
System Information Discovery
MalwareSaint Bot

Saint Bot can identify the OS version, CPU, and other details from a victim's machine.

T1083
File and Directory Discovery
MalwareSaint Bot

Saint Bot can search a compromised host for specific files.

T1105
Ingress Tool Transfer
MalwareSaint Bot

Saint Bot can download additional files onto a compromised host.

T1106
Native API
MalwareSaint Bot

Saint Bot has used different API calls, including `GetProcAddress`, `VirtualAllocEx`, `WriteProcessMemory`, `CreateProcessA`, and `SetThreadContext`.

T1132.001
Standard Encoding
MalwareSaint Bot

Saint Bot has used Base64 to encode its C2 communications.

T1140
Deobfuscate/Decode Files or Information
MalwareSaint Bot

Saint Bot can deobfuscate strings and files for execution.

T1204.001
Malicious Link
MalwareSaint Bot

Saint Bot has relied on users to click on a malicious link delivered via a spearphishing.

T1204.002
Malicious File
MalwareSaint Bot

Saint Bot has relied on users to execute a malicious attachment delivered via spearphishing.

T1218.004
InstallUtil
MalwareSaint Bot

Saint Bot had used `InstallUtil.exe` to download and deploy executables.

T1218.010
Regsvr32
MalwareSaint Bot

Saint Bot has used `regsvr32` to execute scripts.

T1497.001
System Checks
MalwareSaint Bot

Saint Bot has run several virtual machine and sandbox checks, including checking if `Sbiedll.dll` is present in a list of loaded modules, comparing the machine name to `HAL9TH` and the user name to `JohnDoe`, and checking the BIOS version for known virtual machine identifiers.

T1497.003
Time Based Checks
MalwareSaint Bot

Saint Bot has used the command `timeout 20` to pause the execution of its initial loader.

T1547.001
Registry Run Keys / Startup Folder
MalwareSaint Bot

Saint Bot has established persistence by being copied to the Startup directory or through the `\Software\Microsoft\Windows\CurrentVersion\Run` registry key.

T1548.002
Bypass User Account Control
MalwareSaint Bot

Saint Bot has attempted to bypass UAC using `fodhelper.exe` to escalate privileges.

T1566.001
Spearphishing Attachment
MalwareSaint Bot

Saint Bot has been distributed as malicious attachments within spearphishing emails.

T1566.002
Spearphishing Link
MalwareSaint Bot

Saint Bot has been distributed through malicious links contained within spearphishing emails.

T1574
Hijack Execution Flow
MalwareSaint Bot

Saint Bot will use the malicious file slideshow.mp4 if present to load the core API provided by ntdll.dll to avoid any hooks placed on calls to the original ntdll.dll file by endpoint detection and response or antimalware software.

T1614
System Location Discovery
MalwareSaint Bot

Saint Bot has conducted system locale checks to see if the compromised host is in Russia, Ukraine, Belarus, Armenia, Kazakhstan, or Moldova.

T1622
Debugger Evasion
MalwareSaint Bot

Saint Bot has used `is_debugger_present` as part of its environmental checks.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.