Real-world descriptions of how a group, tool or campaign used a technique.
30 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareWoody RAT | Woody RAT can collect information from a compromised host. |
| T1012 Query Registry |
MalwareWoody RAT | Woody RAT can search registry keys to identify antivirus programs on an compromised host. |
| T1016 System Network Configuration Discovery |
MalwareWoody RAT | Woody RAT can retrieve network interface and proxy information. |
| T1016.001 Internet Connection Discovery |
MalwareWoody RAT | Woody RAT can make `Ping` GET HTTP requests to its C2 server at regular intervals for network connectivity checks. |
| T1027.013 Encrypted/Encoded File |
MalwareWoody RAT | Woody RAT has used Base64 encoded strings and scripts. |
| T1033 System Owner/User Discovery |
MalwareWoody RAT | Woody RAT can retrieve a list of user accounts and usernames from an infected machine. |
| T1041 Exfiltration Over C2 Channel |
MalwareWoody RAT | Woody RAT can exfiltrate files from an infected machine to its C2 server. |
| T1055 Process Injection |
MalwareWoody RAT | Woody RAT can inject code into a targeted process by writing to the remote memory of an infected system and then create a remote thread. |
| T1055.012 Process Hollowing |
MalwareWoody RAT | Woody RAT can create a suspended notepad process and write shellcode to delete a file into the suspended process using `NtWriteVirtualMemory`. |
| T1057 Process Discovery |
MalwareWoody RAT | Woody RAT can call `NtQuerySystemProcessInformation` with `SystemProcessInformation` to enumerate all running processes, including associated information such as PID, parent PID, image name, and owner. |
| T1059.001 PowerShell |
MalwareWoody RAT | Woody RAT can execute PowerShell commands and scripts with the use of .NET DLL, `WoodyPowerSession`. |
| T1059.003 Windows Command Shell |
MalwareWoody RAT | Woody RAT can execute commands using `cmd.exe`. |
| T1070.004 File Deletion |
MalwareWoody RAT | Woody RAT has the ability to delete itself from disk by creating a suspended notepad process and writing shellcode to delete a file into the suspended process using `NtWriteVirtualMemory`. |
| T1071.001 Web Protocols |
MalwareWoody RAT | Woody RAT can communicate with its C2 server using HTTP requests. |
| T1082 System Information Discovery |
MalwareWoody RAT | Woody RAT can retrieve the following information from an infected machine: OS, architecture, computer name, OS build version, and environment variables. |
| T1083 File and Directory Discovery |
MalwareWoody RAT | Woody RAT can list all files and their associated attributes, including filename, type, owner, creation time, last access time, last write time, size, and permissions. |
| T1087 Account Discovery |
MalwareWoody RAT | Woody RAT can identify administrator accounts on an infected machine. |
| T1105 Ingress Tool Transfer |
MalwareWoody RAT | Woody RAT can download files from its C2 server, including the .NET DLLs, `WoodySharpExecutor` and `WoodyPowerSession`. |
| T1106 Native API |
MalwareWoody RAT | Woody RAT can use multiple native APIs, including `WriteProcessMemory`, `CreateProcess`, and `CreateRemoteThread` for process injection. |
| T1113 Screen Capture |
MalwareWoody RAT | Woody RAT has the ability to take a screenshot of the infected host desktop using Windows GDI+. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareWoody RAT | Woody RAT can deobfuscate Base64-encoded strings and scripts. |
| T1203 Exploitation for Client Execution |
MalwareWoody RAT | Woody RAT has relied on CVE-2022-30190 (Follina) for execution during delivery. |
| T1204.002 Malicious File |
MalwareWoody RAT | Woody RAT has relied on users opening a malicious email attachment for execution. |
| T1518 Software Discovery |
MalwareWoody RAT | Woody RAT can collect .NET, PowerShell, and Python information from an infected host. |
| T1518.001 Security Software Discovery |
MalwareWoody RAT | Woody RAT can detect Avast Software, Doctor Web, Kaspersky, AVG, ESET, and Sophos antivirus programs. |
| T1566.001 Spearphishing Attachment |
MalwareWoody RAT | Woody RAT has been delivered via malicious Word documents and archive files. |
| T1573.001 Symmetric Cryptography |
MalwareWoody RAT | Woody RAT can use AES-CBC to encrypt data sent to its C2 server. |
| T1573.002 Asymmetric Cryptography |
MalwareWoody RAT | Woody RAT can use RSA-4096 to encrypt data sent to its C2 server. |
| T1680 Local Storage Discovery |
MalwareWoody RAT | Woody RAT can retrieve information about storage drives from an infected machine. |
| T1685 Disable or Modify Tools |
MalwareWoody RAT | Woody RAT has suppressed all error reporting by calling `SetErrorMode` with 0x8007 as a parameter. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.