Real-world descriptions of how a group, tool or campaign used a technique.
28 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwaremetaMain | metaMain can collect files and system information from a compromised host. |
| T1027.013 Encrypted/Encoded File |
MalwaremetaMain | metaMain's module file has been encrypted via XOR. |
| T1033 System Owner/User Discovery |
MalwaremetaMain | metaMain can collect the username from a compromised host. |
| T1041 Exfiltration Over C2 Channel |
MalwaremetaMain | metaMain can upload collected files and data to its C2 server. |
| T1055 Process Injection |
MalwaremetaMain | metaMain can inject the loader file, Speech02.db, into a process. |
| T1056 Input Capture |
MalwaremetaMain | metaMain can log mouse events. |
| T1056.001 Keylogging |
MalwaremetaMain | metaMain has the ability to log keyboard events. |
| T1057 Process Discovery |
MalwaremetaMain | metaMain can enumerate the processes that run on the platform. |
| T1070.004 File Deletion |
MalwaremetaMain | metaMain has deleted collected items after uploading the content to its C2 server. |
| T1070.006 Timestomp |
MalwaremetaMain | metaMain can change the `CreationTime`, `LastAccessTime`, and `LastWriteTime` file time attributes when executed with `SYSTEM` privileges. |
| T1071.001 Web Protocols |
MalwaremetaMain | metaMain can use HTTP for C2 communications. |
| T1074.001 Local Data Staging |
MalwaremetaMain | metaMain has stored the collected system files in a working directory. |
| T1082 System Information Discovery |
MalwaremetaMain | metaMain can collect the computer name from a compromised host. |
| T1083 File and Directory Discovery |
MalwaremetaMain | metaMain can recursively enumerate files in an operator-provided directory. |
| T1090.001 Internal Proxy |
MalwaremetaMain | metaMain can create a named pipe to listen for and send data to a named pipe-based C2 server. |
| T1095 Non-Application Layer Protocol |
MalwaremetaMain | metaMain can establish an indirect and raw TCP socket-based connection to the C2 server. |
| T1105 Ingress Tool Transfer |
MalwaremetaMain | metaMain can download files onto compromised systems. |
| T1106 Native API |
MalwaremetaMain | metaMain can execute an operator-provided Windows command by leveraging functions such as `WinExec`, `WriteFile`, and `ReadFile`. |
| T1112 Modify Registry |
MalwaremetaMain | metaMain can write the process ID of a target process into the `HKEY_LOCAL_MACHINE\SOFTWARE\DDE\tpid` Registry value as part of its reflective loading activity. |
| T1113 Screen Capture |
MalwaremetaMain | metaMain can take and save screenshots. |
| T1140 Deobfuscate/Decode Files or Information |
MalwaremetaMain | metaMain can decrypt and load other modules. |
| T1205.001 Port Knocking |
MalwaremetaMain | metaMain has authenticated itself to a different implant, Cryshell, through a port knocking and handshake procedure. |
| T1497.003 Time Based Checks |
MalwaremetaMain | metaMain has delayed execution for five to six minutes during its persistence establishment process. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwaremetaMain | metaMain registered a WMI event subscription consumer called "hard_disk_stat" to establish persistence. |
| T1560.003 Archive via Custom Method |
MalwaremetaMain | metaMain has used XOR-based encryption for collected files before exfiltration. |
| T1573.001 Symmetric Cryptography |
MalwaremetaMain | metaMain can encrypt the data that it sends and receives from the C2 server using an RC4 encryption algorithm. |
| T1574.001 DLL |
MalwaremetaMain | metaMain can support an HKCMD sideloading start method. |
| T1620 Reflective Code Loading |
MalwaremetaMain | metaMain has reflectively loaded a DLL to read, decrypt, and load an orchestrator file. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.