ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1025×

17 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareAmadey

Amadey can collect information from a compromised host.

T1016
System Network Configuration Discovery
MalwareAmadey

Amadey can identify the IP address of a victim machine.

T1027
Obfuscated Files or Information
MalwareAmadey

Amadey has obfuscated strings such as antivirus vendor names, domains, files, and others.

T1033
System Owner/User Discovery
MalwareAmadey

Amadey has collected the user name from a compromised host using `GetUserNameA`.

T1041
Exfiltration Over C2 Channel
MalwareAmadey

Amadey has sent victim data to its C2 servers.

T1071.001
Web Protocols
MalwareAmadey

Amadey has used HTTP for C2 communications.

T1082
System Information Discovery
MalwareAmadey

Amadey has collected the computer name and OS version from a compromised machine.

T1083
File and Directory Discovery
MalwareAmadey

Amadey has searched for folders associated with antivirus software.

T1105
Ingress Tool Transfer
MalwareAmadey

Amadey can download and execute files to further infect a host machine with additional malware.

T1106
Native API
MalwareAmadey

Amadey has used a variety of Windows API calls, including `GetComputerNameA`, `GetUserNameA`, and `CreateProcessA`.

T1112
Modify Registry
MalwareAmadey

Amadey has overwritten registry keys for persistence.

T1140
Deobfuscate/Decode Files or Information
MalwareAmadey

Amadey has decoded antivirus name strings.

T1518.001
Security Software Discovery
MalwareAmadey

Amadey has checked for a variety of antivirus products.

T1547.001
Registry Run Keys / Startup Folder
MalwareAmadey

Amadey has changed the Startup folder to the one containing its executable by overwriting the registry keys.

T1553.005
Mark-of-the-Web Bypass
MalwareAmadey

Amadey has modified the `:Zone.Identifier` in the ADS area to zero.

T1568.001
Fast Flux DNS
MalwareAmadey

Amadey has used fast flux DNS for its C2.

T1614
System Location Discovery
MalwareAmadey

Amadey does not run any tasks or install additional malware if the victim machine is based in Russia.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.