ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1099×

19 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareSamurai

Samurai can leverage an exfiltration module to download arbitrary files from compromised machines.

T1012
Query Registry
MalwareSamurai

Samurai can query `SOFTWARE\Microsoft\.NETFramework\policy\v2.0` for discovery.

T1027
Obfuscated Files or Information
MalwareSamurai

Samurai can encrypt the names of requested APIs.

T1027.004
Compile After Delivery
MalwareSamurai

Samurai can compile and execute downloaded modules at runtime.

T1027.007
Dynamic API Resolution
MalwareSamurai

Samurai can encrypt API name strings with an XOR-based algorithm.

T1027.015
Compression
MalwareSamurai

Samurai can deliver its final payload as a compressed, encrypted and base64-encoded blob.

T1036.005
Match Legitimate Resource Name or Location
MalwareSamurai

Samurai has created the directory `%COMMONPROGRAMFILES%\Microsoft Shared\wmi\` to contain DLLs for loading successive stages.

T1059.003
Windows Command Shell
MalwareSamurai

Samurai can use a remote command module for execution via the Windows command line.

T1071.001
Web Protocols
MalwareSamurai

Samurai can use a .NET HTTPListener class to receive and handle HTTP POST requests.

T1083
File and Directory Discovery
MalwareSamurai

Samurai can use a specific module for file enumeration.

T1090
Proxy
MalwareSamurai

Samurai has the ability to proxy connections to specified remote IPs and ports through a a proxy module.

T1095
Non-Application Layer Protocol
MalwareSamurai

Samurai can use a proxy module to forward TCP packets to external hosts.

T1105
Ingress Tool Transfer
MalwareSamurai

Samurai has been used to deploy other malware including Ninja.

T1106
Native API
MalwareSamurai

Samurai has the ability to call Windows APIs.

T1112
Modify Registry
MalwareSamurai

The Samurai loader component can create multiple Registry keys to force the svchost.exe process to load the final backdoor.

T1132.001
Standard Encoding
MalwareSamurai

Samurai can base64 encode data sent in C2 communications prior to its encryption.

T1518
Software Discovery
MalwareSamurai

Samurai can check for the presence and version of the .NET framework.

T1543.003
Windows Service
MalwareSamurai

Samurai can create a service at `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost` to trigger execution and maintain persistence.

T1573.001
Symmetric Cryptography
MalwareSamurai

Samurai can encrypt C2 communications with AES.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.