ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1070×

26 examples

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareBlack Basta

Black Basta can check whether the service name `FAX` is present.

T1018
Remote System Discovery
MalwareBlack Basta

Black Basta can use LDAP queries to connect to AD and iterate over connected workstations.

T1027.001
Binary Padding
MalwareBlack Basta

Black Basta had added data prior to the Portable Executable (PE) header to prevent automatic scanners from identifying the payload.

T1036.004
Masquerade Task or Service
MalwareBlack Basta

Black Basta has established persistence by creating a new service named `FAX` after deleting the legitimate service by the same name.

T1036.005
Match Legitimate Resource Name or Location
MalwareBlack Basta

The Black Basta dropper has mimicked an application for creating USB bootable drivers.

T1047
Windows Management Instrumentation
MalwareBlack Basta

Black Basta has used WMI to execute files over the network.

T1059.001
PowerShell
MalwareBlack Basta

Black Basta has used PowerShell scripts for discovery and to execute files over the network.

T1059.003
Windows Command Shell
MalwareBlack Basta

Black Basta can use `cmd.exe` to enable shadow copy deletion.

T1082
System Information Discovery
MalwareBlack Basta

Black Basta can collect system boot configuration and CPU information.

T1083
File and Directory Discovery
MalwareBlack Basta

Black Basta can enumerate specific files for encryption.

T1106
Native API
MalwareBlack Basta

Black Basta has the ability to use native APIs for numerous functions including discovery and defense evasion.

T1112
Modify Registry
MalwareBlack Basta

Black Basta has modified the Registry to enable itself to run in safe mode, to change the icons and file extensions for encrypted files, and to add the malware path for persistence.

T1204.002
Malicious File
MalwareBlack Basta

Black Basta has been downloaded and executed from malicious Excel files.

T1222.002
Linux and Mac Permissions
MalwareBlack Basta

The Black Basta binary can use `chmod` to gain full permissions to targeted files.

T1480.002
Mutual Exclusion
MalwareBlack Basta

Black Basta will check for the presence of a hard-coded mutex `dsajdhas.0` before executing.

T1486
Data Encrypted for Impact
MalwareBlack Basta

Black Basta can encrypt files with the ChaCha20 cypher and using a multithreaded process to increase speed. Black Basta has also encrypted files while the victim system is in safe mode, appending `.basta` upon completion.

T1490
Inhibit System Recovery
MalwareBlack Basta

Black Basta can delete shadow copies using vssadmin.exe.

T1491.001
Internal Defacement
MalwareBlack Basta

Black Basta has set the desktop wallpaper on victims' machines to display a ransom note.

T1497
Virtualization/Sandbox Evasion
MalwareBlack Basta

Black Basta can make a random number of calls to the `kernel32.beep` function to hinder log analysis.

T1497.001
System Checks
MalwareBlack Basta

Black Basta can check system flags and libraries, process timing, and API's to detect code emulation or sandboxing.

T1529
System Shutdown/Reboot
MalwareBlack Basta

Black Basta has used `ShellExecuteA` to shut down and restart the victim system.

T1543.003
Windows Service
MalwareBlack Basta

Black Basta can create a new service to establish persistence.

T1553.002
Code Signing
MalwareBlack Basta

The Black Basta dropper has been digitally signed with a certificate issued by Akeo Consulting for legitimate executables used for creating bootable USB drives.

T1622
Debugger Evasion
MalwareBlack Basta

The Black Basta dropper can check system flags, CPU registers, CPU instructions, process timing, system libraries, and APIs to determine if a debugger is present.

T1680
Local Storage Discovery
MalwareBlack Basta

Black Basta can enumerate volumes.

T1688
Safe Mode Boot
MalwareBlack Basta

Black Basta can reboot victim machines in safe mode with networking via `bcdedit /set safeboot network`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.