ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1059×

28 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwaremetaMain

metaMain can collect files and system information from a compromised host.

T1027.013
Encrypted/Encoded File
MalwaremetaMain

metaMain's module file has been encrypted via XOR.

T1033
System Owner/User Discovery
MalwaremetaMain

metaMain can collect the username from a compromised host.

T1041
Exfiltration Over C2 Channel
MalwaremetaMain

metaMain can upload collected files and data to its C2 server.

T1055
Process Injection
MalwaremetaMain

metaMain can inject the loader file, Speech02.db, into a process.

T1056
Input Capture
MalwaremetaMain

metaMain can log mouse events.

T1056.001
Keylogging
MalwaremetaMain

metaMain has the ability to log keyboard events.

T1057
Process Discovery
MalwaremetaMain

metaMain can enumerate the processes that run on the platform.

T1070.004
File Deletion
MalwaremetaMain

metaMain has deleted collected items after uploading the content to its C2 server.

T1070.006
Timestomp
MalwaremetaMain

metaMain can change the `CreationTime`, `LastAccessTime`, and `LastWriteTime` file time attributes when executed with `SYSTEM` privileges.

T1071.001
Web Protocols
MalwaremetaMain

metaMain can use HTTP for C2 communications.

T1074.001
Local Data Staging
MalwaremetaMain

metaMain has stored the collected system files in a working directory.

T1082
System Information Discovery
MalwaremetaMain

metaMain can collect the computer name from a compromised host.

T1083
File and Directory Discovery
MalwaremetaMain

metaMain can recursively enumerate files in an operator-provided directory.

T1090.001
Internal Proxy
MalwaremetaMain

metaMain can create a named pipe to listen for and send data to a named pipe-based C2 server.

T1095
Non-Application Layer Protocol
MalwaremetaMain

metaMain can establish an indirect and raw TCP socket-based connection to the C2 server.

T1105
Ingress Tool Transfer
MalwaremetaMain

metaMain can download files onto compromised systems.

T1106
Native API
MalwaremetaMain

metaMain can execute an operator-provided Windows command by leveraging functions such as `WinExec`, `WriteFile`, and `ReadFile`.

T1112
Modify Registry
MalwaremetaMain

metaMain can write the process ID of a target process into the `HKEY_LOCAL_MACHINE\SOFTWARE\DDE\tpid` Registry value as part of its reflective loading activity.

T1113
Screen Capture
MalwaremetaMain

metaMain can take and save screenshots.

T1140
Deobfuscate/Decode Files or Information
MalwaremetaMain

metaMain can decrypt and load other modules.

T1205.001
Port Knocking
MalwaremetaMain

metaMain has authenticated itself to a different implant, Cryshell, through a port knocking and handshake procedure.

T1497.003
Time Based Checks
MalwaremetaMain

metaMain has delayed execution for five to six minutes during its persistence establishment process.

T1546.003
Windows Management Instrumentation Event Subscription
MalwaremetaMain

metaMain registered a WMI event subscription consumer called "hard_disk_stat" to establish persistence.

T1560.003
Archive via Custom Method
MalwaremetaMain

metaMain has used XOR-based encryption for collected files before exfiltration.

T1573.001
Symmetric Cryptography
MalwaremetaMain

metaMain can encrypt the data that it sends and receives from the C2 server using an RC4 encryption algorithm.

T1574.001
DLL
MalwaremetaMain

metaMain can support an HKCMD sideloading start method.

T1620
Reflective Code Loading
MalwaremetaMain

metaMain has reflectively loaded a DLL to read, decrypt, and load an orchestrator file.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.