Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareSamurai | Samurai can leverage an exfiltration module to download arbitrary files from compromised machines. |
| T1012 Query Registry |
MalwareSamurai | Samurai can query `SOFTWARE\Microsoft\.NETFramework\policy\v2.0` for discovery. |
| T1027 Obfuscated Files or Information |
MalwareSamurai | Samurai can encrypt the names of requested APIs. |
| T1027.004 Compile After Delivery |
MalwareSamurai | Samurai can compile and execute downloaded modules at runtime. |
| T1027.007 Dynamic API Resolution |
MalwareSamurai | Samurai can encrypt API name strings with an XOR-based algorithm. |
| T1027.015 Compression |
MalwareSamurai | Samurai can deliver its final payload as a compressed, encrypted and base64-encoded blob. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSamurai | Samurai has created the directory `%COMMONPROGRAMFILES%\Microsoft Shared\wmi\` to contain DLLs for loading successive stages. |
| T1059.003 Windows Command Shell |
MalwareSamurai | Samurai can use a remote command module for execution via the Windows command line. |
| T1071.001 Web Protocols |
MalwareSamurai | Samurai can use a .NET HTTPListener class to receive and handle HTTP POST requests. |
| T1083 File and Directory Discovery |
MalwareSamurai | Samurai can use a specific module for file enumeration. |
| T1090 Proxy |
MalwareSamurai | Samurai has the ability to proxy connections to specified remote IPs and ports through a a proxy module. |
| T1095 Non-Application Layer Protocol |
MalwareSamurai | Samurai can use a proxy module to forward TCP packets to external hosts. |
| T1105 Ingress Tool Transfer |
MalwareSamurai | Samurai has been used to deploy other malware including Ninja. |
| T1106 Native API |
MalwareSamurai | Samurai has the ability to call Windows APIs. |
| T1112 Modify Registry |
MalwareSamurai | The Samurai loader component can create multiple Registry keys to force the svchost.exe process to load the final backdoor. |
| T1132.001 Standard Encoding |
MalwareSamurai | Samurai can base64 encode data sent in C2 communications prior to its encryption. |
| T1518 Software Discovery |
MalwareSamurai | Samurai can check for the presence and version of the .NET framework. |
| T1543.003 Windows Service |
MalwareSamurai | Samurai can create a service at `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost` to trigger execution and maintain persistence. |
| T1573.001 Symmetric Cryptography |
MalwareSamurai | Samurai can encrypt C2 communications with AES. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.