Real-world descriptions of how a group, tool or campaign used a technique.
28 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
MalwareNinja | Ninja has the ability to modify headers and URL paths to hide malicious traffic in HTTP requests. |
| T1001.003 Protocol or Service Impersonation |
MalwareNinja | Ninja has the ability to mimic legitimate services with customized HTTP URL paths and headers to hide malicious traffic. |
| T1016 System Network Configuration Discovery |
MalwareNinja | Ninja can enumerate the IP address on compromised systems. |
| T1027.013 Encrypted/Encoded File |
MalwareNinja | The Ninja payload is XOR encrypted and compressed. Ninja has also XORed its configuration data with a constant value of `0xAA`. |
| T1027.015 Compression |
MalwareNinja | Ninja has compressed its data with the LZSS algorithm. |
| T1029 Scheduled Transfer |
MalwareNinja | Ninja can configure its agent to work only in specific time frames. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareNinja | Ninja has used legitimate looking filenames for its loader including update.dll and x64.dll. |
| T1055 Process Injection |
MalwareNinja | Ninja has the ability to inject an agent module into a new process and arbitrary shellcode into running processes. |
| T1057 Process Discovery |
MalwareNinja | Ninja can enumerate processes on a targeted host. |
| T1070.006 Timestomp |
MalwareNinja | Ninja can change or create the last access or write times. |
| T1071.001 Web Protocols |
MalwareNinja | Ninja can use HTTP for C2 communications. |
| T1082 System Information Discovery |
MalwareNinja | Ninja can obtain the computer name and information on the OS from targeted hosts. |
| T1083 File and Directory Discovery |
MalwareNinja | Ninja has the ability to enumerate directory content. |
| T1090.001 Internal Proxy |
MalwareNinja | Ninja can proxy C2 communications including to and from internal agents without internet connectivity. |
| T1090.003 Multi-hop Proxy |
MalwareNinja | Ninja has the ability to use a proxy chain with up to 255 hops when using TCP. |
| T1095 Non-Application Layer Protocol |
MalwareNinja | Ninja can forward TCP packets between the C2 and a remote host. |
| T1106 Native API |
MalwareNinja | The Ninja loader can call Windows APIs for discovery, process injection, and payload decryption. |
| T1132.002 Non-Standard Encoding |
MalwareNinja | Ninja can encode C2 communications with a base64 algorithm using a custom alphabet. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareNinja | The Ninja loader component can decrypt and decompress the payload. |
| T1204.002 Malicious File |
MalwareNinja | Ninja has gained execution through victims opening malicious executable files embedded in zip archives. |
| T1218.011 Rundll32 |
MalwareNinja | Ninja loader components can be executed through rundll32.exe. |
| T1480.001 Environmental Keying |
MalwareNinja | Ninja can store its final payload in the Registry under `$HKLM\SOFTWARE\Classes\Interface\` encrypted with a dynamically generated key based on the drive’s serial number. |
| T1543.003 Windows Service |
MalwareNinja | Ninja can create the services `httpsvc` and `w3esvc` for persistence . |
| T1559 Inter-Process Communication |
MalwareNinja | Ninja can use pipes to redirect the standard input and the standard output. |
| T1566.003 Spearphishing via Service |
MalwareNinja | Ninja has been distributed to victims via the messaging app Telegram. |
| T1573.001 Symmetric Cryptography |
MalwareNinja | Ninja can XOR and AES encrypt C2 messages. |
| T1574.001 DLL |
MalwareNinja | Ninja loaders can be side-loaded with legitimate and signed executables including the VLC.exe media player. |
| T1680 Local Storage Discovery |
MalwareNinja | Ninja can obtain information on physical drives from targeted hosts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.