Real-world descriptions of how a group, tool or campaign used a technique.
21 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareSquirrelwaffle | Squirrelwaffle has collected the victim’s external IP address. |
| T1027.002 Software Packing |
MalwareSquirrelwaffle | Squirrelwaffle has been packed with a custom packer to hide payloads. |
| T1027.013 Encrypted/Encoded File |
MalwareSquirrelwaffle | Squirrelwaffle has been obfuscated with a XOR-based algorithm. |
| T1033 System Owner/User Discovery |
MalwareSquirrelwaffle | Squirrelwaffle can collect the user name from a compromised host. |
| T1041 Exfiltration Over C2 Channel |
MalwareSquirrelwaffle | Squirrelwaffle has exfiltrated victim data using HTTP POST requests to its C2 servers. |
| T1059.001 PowerShell |
MalwareSquirrelwaffle | Squirrelwaffle has used PowerShell to execute its payload. |
| T1059.003 Windows Command Shell |
MalwareSquirrelwaffle | Squirrelwaffle has used `cmd.exe` for execution. |
| T1059.005 Visual Basic |
MalwareSquirrelwaffle | Squirrelwaffle has used malicious VBA macros in Microsoft Word documents and Excel spreadsheets that execute an `AutoOpen` subroutine. |
| T1071.001 Web Protocols |
MalwareSquirrelwaffle | Squirrelwaffle has used HTTP POST requests for C2 communications. |
| T1082 System Information Discovery |
MalwareSquirrelwaffle | Squirrelwaffle has gathered victim computer information and configurations. |
| T1105 Ingress Tool Transfer |
MalwareSquirrelwaffle | Squirrelwaffle has downloaded and executed additional encoded payloads. |
| T1132.001 Standard Encoding |
MalwareSquirrelwaffle | Squirrelwaffle has encoded its communications to C2 servers using Base64. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSquirrelwaffle | Squirrelwaffle has decrypted files and payloads using a XOR-based algorithm. |
| T1204.001 Malicious Link |
MalwareSquirrelwaffle | Squirrelwaffle has relied on victims to click on a malicious link send via phishing campaigns. |
| T1204.002 Malicious File |
MalwareSquirrelwaffle | Squirrelwaffle has relied on users enabling malicious macros within Microsoft Excel and Word attachments. |
| T1218.010 Regsvr32 |
MalwareSquirrelwaffle | Squirrelwaffle has been executed using `regsvr32.exe`. |
| T1218.011 Rundll32 |
MalwareSquirrelwaffle | Squirrelwaffle has been executed using `rundll32.exe`. |
| T1497 Virtualization/Sandbox Evasion |
MalwareSquirrelwaffle | Squirrelwaffle has contained a hardcoded list of IP addresses to block that belong to sandboxes and analysis platforms. |
| T1560.003 Archive via Custom Method |
MalwareSquirrelwaffle | Squirrelwaffle has encrypted collected data using a XOR-based algorithm. |
| T1566.001 Spearphishing Attachment |
MalwareSquirrelwaffle | Squirrelwaffle has been distributed via malicious Microsoft Office documents within spam emails. |
| T1566.002 Spearphishing Link |
MalwareSquirrelwaffle | Squirrelwaffle has been distributed through phishing emails containing a malicious URL. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.