ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1066×

28 examples

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareDarkTortilla

DarkTortilla can retrieve information about a compromised system's running services.

T1016.001
Internet Connection Discovery
MalwareDarkTortilla

DarkTortilla can check for internet connectivity by issuing HTTP GET requests.

T1027
Obfuscated Files or Information
MalwareDarkTortilla

DarkTortilla has been obfuscated with the DeepSea .NET and ConfuserEx code obfuscators.

T1036
Masquerading
MalwareDarkTortilla

DarkTortilla's payload has been renamed `PowerShellInfo.exe`.

T1047
Windows Management Instrumentation
MalwareDarkTortilla

DarkTortilla can use WMI queries to obtain system information.

T1055.001
Dynamic-link Library Injection
MalwareDarkTortilla

DarkTortilla can use a .NET-based DLL named `RunPe6` for process injection.

T1056.001
Keylogging
MalwareDarkTortilla

DarkTortilla can download a keylogging module.

T1057
Process Discovery
MalwareDarkTortilla

DarkTortilla can enumerate a list of running processes on a compromised system.

T1059.003
Windows Command Shell
MalwareDarkTortilla

DarkTortilla can use `cmd.exe` to add registry keys for persistence.

T1071.001
Web Protocols
MalwareDarkTortilla

DarkTortilla has used HTTP and HTTPS for C2.

T1082
System Information Discovery
MalwareDarkTortilla

DarkTortilla can obtain system information by querying the `Win32_ComputerSystem`, `Win32_BIOS`, `Win32_MotherboardDevice`, `Win32_PnPEntity`, and `Win32_DiskDrive` WMI objects.

T1102
Web Service
MalwareDarkTortilla

DarkTortilla can retrieve its primary payload from public sites such as Pastebin and Textbin.

T1105
Ingress Tool Transfer
MalwareDarkTortilla

DarkTortilla can download additional packages for keylogging, cryptocurrency mining, and other capabilities; it can also retrieve malicious payloads such as Agent Tesla, AsyncRat, NanoCore, RedLine, Cobalt Strike, and Metasploit.

T1106
Native API
MalwareDarkTortilla

DarkTortilla can use a variety of API calls for persistence and defense evasion.

T1112
Modify Registry
MalwareDarkTortilla

DarkTortilla has modified registry keys for persistence.

T1115
Clipboard Data
MalwareDarkTortilla

DarkTortilla can download a clipboard information stealer module.

T1140
Deobfuscate/Decode Files or Information
MalwareDarkTortilla

DarkTortilla can decrypt its payload and associated configuration elements using the Rijndael cipher.

T1204.002
Malicious File
MalwareDarkTortilla

DarkTortilla has relied on a user to open a malicious document or archived file delivered via email for initial execution.

T1497.001
System Checks
MalwareDarkTortilla

DarkTortilla can search a compromised system's running processes and services to detect Hyper-V, QEMU, Virtual PC, Virtual Box, and VMware, as well as Sandboxie.

T1497.003
Time Based Checks
MalwareDarkTortilla

DarkTortilla can implement the `kernel32.dll` Sleep function to delay execution for up to 300 seconds before implementing persistence or processing an addon package.

T1518.001
Security Software Discovery
MalwareDarkTortilla

DarkTortilla can check for the Kaspersky Anti-Virus suite.

T1547.001
Registry Run Keys / Startup Folder
MalwareDarkTortilla

DarkTortilla has established persistence via the `Software\Microsoft\Windows NT\CurrentVersion\Run` registry key and by creating a .lnk shortcut file in the Windows startup folder.

T1547.004
Winlogon Helper DLL
MalwareDarkTortilla

DarkTortilla has established persistence via the `Software\Microsoft\Windows NT\CurrentVersion\Winlogon` registry key.

T1559.001
Component Object Model
MalwareDarkTortilla

DarkTortilla has used the `WshShortcut` COM object to create a .lnk shortcut file in the Windows startup folder.

T1564
Hide Artifacts
MalwareDarkTortilla

DarkTortilla has used `%HiddenReg%` and `%HiddenKey%` as part of its persistence via the Windows registry.

T1566.001
Spearphishing Attachment
MalwareDarkTortilla

DarkTortilla has been distributed via spearphishing emails containing archive attachments, with file types such as .iso, .zip, .img, .dmg, and .tar, as well as through malicious documents.

T1574.012
COR_PROFILER
MalwareDarkTortilla

DarkTortilla can detect profilers by verifying the `COR_ENABLE_PROFILING` environment variable is present and active.

T1622
Debugger Evasion
MalwareDarkTortilla

DarkTortilla can detect debuggers by using functions such as `DebuggerIsAttached` and `DebuggerIsLogging`. DarkTortilla can also detect profilers by verifying the `COR_ENABLE_PROFILING` environment variable is present and active.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.