Real-world descriptions of how a group, tool or campaign used a technique.
37 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
MalwareFunnyDream | FunnyDream can send compressed and obfuscated packets to C2. |
| T1005 Data from Local System |
MalwareFunnyDream | FunnyDream can upload files from victims' machines. |
| T1010 Application Window Discovery |
MalwareFunnyDream | FunnyDream has the ability to discover application windows via execution of `EnumWindows`. |
| T1012 Query Registry |
MalwareFunnyDream | FunnyDream can check `Software\Microsoft\Windows\CurrentVersion\Internet Settings` to extract the `ProxyServer` string. |
| T1016 System Network Configuration Discovery |
MalwareFunnyDream | FunnyDream can parse the `ProxyServer` string in the Registry to discover http proxies. |
| T1018 Remote System Discovery |
MalwareFunnyDream | FunnyDream can collect information about hosts on the victim network. |
| T1025 Data from Removable Media |
MalwareFunnyDream | The FunnyDream FilePakMonitor component has the ability to collect files from removable devices. |
| T1027.013 Encrypted/Encoded File |
MalwareFunnyDream | FunnyDream can Base64 encode its C2 address stored in a template binary with the `xyz0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvw_-` or |
| T1033 System Owner/User Discovery |
MalwareFunnyDream | FunnyDream has the ability to gather user information from the targeted system using `whoami/upn&whoami/fqdn&whoami/logonid&whoami/all`. |
| T1036.004 Masquerade Task or Service |
MalwareFunnyDream | FunnyDream has used a service named `WSearch` for execution. |
| T1041 Exfiltration Over C2 Channel |
MalwareFunnyDream | FunnyDream can execute commands, including gathering user information, and send the results to C2. |
| T1047 Windows Management Instrumentation |
MalwareFunnyDream | FunnyDream can use WMI to open a Windows command shell on a remote machine. |
| T1055.001 Dynamic-link Library Injection |
MalwareFunnyDream | The FunnyDream FilepakMonitor component can inject into the Bka.exe process using the `VirtualAllocEx`, `WriteProcessMemory` and `CreateRemoteThread` APIs to load the DLL component. |
| T1056.001 Keylogging |
MalwareFunnyDream | The FunnyDream Keyrecord component can capture keystrokes. |
| T1057 Process Discovery |
MalwareFunnyDream | FunnyDream has the ability to discover processes, including `Bka.exe` and `BkavUtil.exe`. |
| T1059.003 Windows Command Shell |
MalwareFunnyDream | FunnyDream can use `cmd.exe` for execution on remote hosts. |
| T1070 Indicator Removal |
MalwareFunnyDream | FunnyDream has the ability to clean traces of malware deployment. |
| T1070.004 File Deletion |
MalwareFunnyDream | FunnyDream can delete files including its dropper component. |
| T1074.001 Local Data Staging |
MalwareFunnyDream | FunnyDream can stage collected information including screen captures and logged keystrokes locally. |
| T1083 File and Directory Discovery |
MalwareFunnyDream | FunnyDream can identify files with .doc, .docx, .ppt, .pptx, .xls, .xlsx, and .pdf extensions and specific timestamps for collection. |
| T1090 Proxy |
MalwareFunnyDream | FunnyDream can identify and use configured proxies in a compromised network for C2 communication. |
| T1095 Non-Application Layer Protocol |
MalwareFunnyDream | FunnyDream can communicate with C2 over TCP and UDP. |
| T1105 Ingress Tool Transfer |
MalwareFunnyDream | FunnyDream can download additional files onto a compromised host. |
| T1106 Native API |
MalwareFunnyDream | FunnyDream can use Native API for defense evasion, discovery, and collection. |
| T1113 Screen Capture |
MalwareFunnyDream | The FunnyDream ScreenCap component can take screenshots on a compromised host. |
| T1119 Automated Collection |
MalwareFunnyDream | FunnyDream can monitor files for changes and automatically collect them. |
| T1120 Peripheral Device Discovery |
MalwareFunnyDream | The FunnyDream FilepakMonitor component can detect removable drive insertion. |
| T1124 System Time Discovery |
MalwareFunnyDream | FunnyDream can check system time to help determine when changes were made to specified files. |
| T1218.011 Rundll32 |
MalwareFunnyDream | FunnyDream can use `rundll32` for execution of its components. |
| T1518.001 Security Software Discovery |
MalwareFunnyDream | FunnyDream can identify the processes for Bkav antivirus. |
| T1543.003 Windows Service |
MalwareFunnyDream | FunnyDream has established persistence by running `sc.exe` and by setting the `WSearch` service to run automatically. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFunnyDream | FunnyDream can use a Registry Run Key and the Startup folder to establish persistence. |
| T1559.001 Component Object Model |
MalwareFunnyDream | FunnyDream can use com objects identified with `CLSID_ShellLink`(`IShellLink` and `IPersistFile`) and `WScript.Shell`(`RegWrite` method) to enable persistence mechanisms. |
| T1560.002 Archive via Library |
MalwareFunnyDream | FunnyDream has compressed collected files with zLib. |
| T1560.003 Archive via Custom Method |
MalwareFunnyDream | FunnyDream has compressed collected files with zLib and encrypted them using an XOR operation with the string key from the command line or `qwerasdf` if the command line argument doesn’t contain the key. File names are obfuscated using XOR with the same key as the compressed file content. |
| T1572 Protocol Tunneling |
MalwareFunnyDream | FunnyDream can connect to HTTP proxies via TCP to create a tunnel to C2. |
| T1680 Local Storage Discovery |
MalwareFunnyDream | FunnyDream can enumerate all logical drives on a targeted machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.