ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1086×

20 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareSnip3

Snip3 has the ability to obfuscate strings using XOR encryption.

T1027.001
Binary Padding
MalwareSnip3

Snip3 can obfuscate strings using junk Chinese characters.

T1047
Windows Management Instrumentation
MalwareSnip3

Snip3 can query the WMI class `Win32_ComputerSystem` to gather information.

T1055.012
Process Hollowing
MalwareSnip3

Snip3 can use RunPE to execute malicious payloads within a hollowed Windows process.

T1059.001
PowerShell
MalwareSnip3

Snip3 can use a PowerShell script for second-stage execution.

T1059.005
Visual Basic
MalwareSnip3

Snip3 can use visual basic scripts for first-stage execution.

T1082
System Information Discovery
MalwareSnip3

Snip3 has the ability to query `Win32_ComputerSystem` for system information.

T1102
Web Service
MalwareSnip3

Snip3 can download additional payloads from web services including Pastebin and top4top.

T1104
Multi-Stage Channels
MalwareSnip3

Snip3 can download and execute additional payloads and modules over separate communication channels.

T1105
Ingress Tool Transfer
MalwareSnip3

Snip3 can download additional payloads to compromised systems.

T1140
Deobfuscate/Decode Files or Information
MalwareSnip3

Snip3 can decode its second-stage PowerShell script prior to execution.

T1189
Drive-by Compromise
MalwareSnip3

Snip3 has been delivered to targets via downloads from malicious domains.

T1204.001
Malicious Link
MalwareSnip3

Snip3 has been executed through luring victims into clicking malicious links.

T1204.002
Malicious File
MalwareSnip3

Snip3 can gain execution through the download of visual basic files.

T1497.001
System Checks
MalwareSnip3

Snip3 has the ability to detect Windows Sandbox, VMWare, or VirtualBox by querying `Win32_ComputerSystem` to extract the `Manufacturer` string.

T1497.003
Time Based Checks
MalwareSnip3

Snip3 can execute `WScript.Sleep` to delay execution of its second stage.

T1547.001
Registry Run Keys / Startup Folder
MalwareSnip3

Snip3 can create a VBS file in startup to persist after system restarts.

T1564.003
Hidden Window
MalwareSnip3

Snip3 can execute PowerShell scripts in a hidden window.

T1566.001
Spearphishing Attachment
MalwareSnip3

Snip3 has been delivered to victims through malicious e-mail attachments.

T1566.002
Spearphishing Link
MalwareSnip3

Snip3 has been delivered to victims through e-mail links to malicious files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.