ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1044×

37 examples

TechniqueUsed byProcedure example
T1001
Data Obfuscation
MalwareFunnyDream

FunnyDream can send compressed and obfuscated packets to C2.

T1005
Data from Local System
MalwareFunnyDream

FunnyDream can upload files from victims' machines.

T1010
Application Window Discovery
MalwareFunnyDream

FunnyDream has the ability to discover application windows via execution of `EnumWindows`.

T1012
Query Registry
MalwareFunnyDream

FunnyDream can check `Software\Microsoft\Windows\CurrentVersion\Internet Settings` to extract the `ProxyServer` string.

T1016
System Network Configuration Discovery
MalwareFunnyDream

FunnyDream can parse the `ProxyServer` string in the Registry to discover http proxies.

T1018
Remote System Discovery
MalwareFunnyDream

FunnyDream can collect information about hosts on the victim network.

T1025
Data from Removable Media
MalwareFunnyDream

The FunnyDream FilePakMonitor component has the ability to collect files from removable devices.

T1027.013
Encrypted/Encoded File
MalwareFunnyDream

FunnyDream can Base64 encode its C2 address stored in a template binary with the `xyz0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvw_-` or
`xyz0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvw_=` character sets.

T1033
System Owner/User Discovery
MalwareFunnyDream

FunnyDream has the ability to gather user information from the targeted system using `whoami/upn&whoami/fqdn&whoami/logonid&whoami/all`.

T1036.004
Masquerade Task or Service
MalwareFunnyDream

FunnyDream has used a service named `WSearch` for execution.

T1041
Exfiltration Over C2 Channel
MalwareFunnyDream

FunnyDream can execute commands, including gathering user information, and send the results to C2.

T1047
Windows Management Instrumentation
MalwareFunnyDream

FunnyDream can use WMI to open a Windows command shell on a remote machine.

T1055.001
Dynamic-link Library Injection
MalwareFunnyDream

The FunnyDream FilepakMonitor component can inject into the Bka.exe process using the `VirtualAllocEx`, `WriteProcessMemory` and `CreateRemoteThread` APIs to load the DLL component.

T1056.001
Keylogging
MalwareFunnyDream

The FunnyDream Keyrecord component can capture keystrokes.

T1057
Process Discovery
MalwareFunnyDream

FunnyDream has the ability to discover processes, including `Bka.exe` and `BkavUtil.exe`.

T1059.003
Windows Command Shell
MalwareFunnyDream

FunnyDream can use `cmd.exe` for execution on remote hosts.

T1070
Indicator Removal
MalwareFunnyDream

FunnyDream has the ability to clean traces of malware deployment.

T1070.004
File Deletion
MalwareFunnyDream

FunnyDream can delete files including its dropper component.

T1074.001
Local Data Staging
MalwareFunnyDream

FunnyDream can stage collected information including screen captures and logged keystrokes locally.

T1083
File and Directory Discovery
MalwareFunnyDream

FunnyDream can identify files with .doc, .docx, .ppt, .pptx, .xls, .xlsx, and .pdf extensions and specific timestamps for collection.

T1090
Proxy
MalwareFunnyDream

FunnyDream can identify and use configured proxies in a compromised network for C2 communication.

T1095
Non-Application Layer Protocol
MalwareFunnyDream

FunnyDream can communicate with C2 over TCP and UDP.

T1105
Ingress Tool Transfer
MalwareFunnyDream

FunnyDream can download additional files onto a compromised host.

T1106
Native API
MalwareFunnyDream

FunnyDream can use Native API for defense evasion, discovery, and collection.

T1113
Screen Capture
MalwareFunnyDream

The FunnyDream ScreenCap component can take screenshots on a compromised host.

T1119
Automated Collection
MalwareFunnyDream

FunnyDream can monitor files for changes and automatically collect them.

T1120
Peripheral Device Discovery
MalwareFunnyDream

The FunnyDream FilepakMonitor component can detect removable drive insertion.

T1124
System Time Discovery
MalwareFunnyDream

FunnyDream can check system time to help determine when changes were made to specified files.

T1218.011
Rundll32
MalwareFunnyDream

FunnyDream can use `rundll32` for execution of its components.

T1518.001
Security Software Discovery
MalwareFunnyDream

FunnyDream can identify the processes for Bkav antivirus.

T1543.003
Windows Service
MalwareFunnyDream

FunnyDream has established persistence by running `sc.exe` and by setting the `WSearch` service to run automatically.

T1547.001
Registry Run Keys / Startup Folder
MalwareFunnyDream

FunnyDream can use a Registry Run Key and the Startup folder to establish persistence.

T1559.001
Component Object Model
MalwareFunnyDream

FunnyDream can use com objects identified with `CLSID_ShellLink`(`IShellLink` and `IPersistFile`) and `WScript.Shell`(`RegWrite` method) to enable persistence mechanisms.

T1560.002
Archive via Library
MalwareFunnyDream

FunnyDream has compressed collected files with zLib.

T1560.003
Archive via Custom Method
MalwareFunnyDream

FunnyDream has compressed collected files with zLib and encrypted them using an XOR operation with the string key from the command line or `qwerasdf` if the command line argument doesn’t contain the key. File names are obfuscated using XOR with the same key as the compressed file content.

T1572
Protocol Tunneling
MalwareFunnyDream

FunnyDream can connect to HTTP proxies via TCP to create a tunnel to C2.

T1680
Local Storage Discovery
MalwareFunnyDream

FunnyDream can enumerate all logical drives on a targeted machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.