ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1030×

21 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareSquirrelwaffle

Squirrelwaffle has collected the victim’s external IP address.

T1027.002
Software Packing
MalwareSquirrelwaffle

Squirrelwaffle has been packed with a custom packer to hide payloads.

T1027.013
Encrypted/Encoded File
MalwareSquirrelwaffle

Squirrelwaffle has been obfuscated with a XOR-based algorithm.

T1033
System Owner/User Discovery
MalwareSquirrelwaffle

Squirrelwaffle can collect the user name from a compromised host.

T1041
Exfiltration Over C2 Channel
MalwareSquirrelwaffle

Squirrelwaffle has exfiltrated victim data using HTTP POST requests to its C2 servers.

T1059.001
PowerShell
MalwareSquirrelwaffle

Squirrelwaffle has used PowerShell to execute its payload.

T1059.003
Windows Command Shell
MalwareSquirrelwaffle

Squirrelwaffle has used `cmd.exe` for execution.

T1059.005
Visual Basic
MalwareSquirrelwaffle

Squirrelwaffle has used malicious VBA macros in Microsoft Word documents and Excel spreadsheets that execute an `AutoOpen` subroutine.

T1071.001
Web Protocols
MalwareSquirrelwaffle

Squirrelwaffle has used HTTP POST requests for C2 communications.

T1082
System Information Discovery
MalwareSquirrelwaffle

Squirrelwaffle has gathered victim computer information and configurations.

T1105
Ingress Tool Transfer
MalwareSquirrelwaffle

Squirrelwaffle has downloaded and executed additional encoded payloads.

T1132.001
Standard Encoding
MalwareSquirrelwaffle

Squirrelwaffle has encoded its communications to C2 servers using Base64.

T1140
Deobfuscate/Decode Files or Information
MalwareSquirrelwaffle

Squirrelwaffle has decrypted files and payloads using a XOR-based algorithm.

T1204.001
Malicious Link
MalwareSquirrelwaffle

Squirrelwaffle has relied on victims to click on a malicious link send via phishing campaigns.

T1204.002
Malicious File
MalwareSquirrelwaffle

Squirrelwaffle has relied on users enabling malicious macros within Microsoft Excel and Word attachments.

T1218.010
Regsvr32
MalwareSquirrelwaffle

Squirrelwaffle has been executed using `regsvr32.exe`.

T1218.011
Rundll32
MalwareSquirrelwaffle

Squirrelwaffle has been executed using `rundll32.exe`.

T1497
Virtualization/Sandbox Evasion
MalwareSquirrelwaffle

Squirrelwaffle has contained a hardcoded list of IP addresses to block that belong to sandboxes and analysis platforms.

T1560.003
Archive via Custom Method
MalwareSquirrelwaffle

Squirrelwaffle has encrypted collected data using a XOR-based algorithm.

T1566.001
Spearphishing Attachment
MalwareSquirrelwaffle

Squirrelwaffle has been distributed via malicious Microsoft Office documents within spam emails.

T1566.002
Spearphishing Link
MalwareSquirrelwaffle

Squirrelwaffle has been distributed through phishing emails containing a malicious URL.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.