ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1100×

28 examples

TechniqueUsed byProcedure example
T1001
Data Obfuscation
MalwareNinja

Ninja has the ability to modify headers and URL paths to hide malicious traffic in HTTP requests.

T1001.003
Protocol or Service Impersonation
MalwareNinja

Ninja has the ability to mimic legitimate services with customized HTTP URL paths and headers to hide malicious traffic.

T1016
System Network Configuration Discovery
MalwareNinja

Ninja can enumerate the IP address on compromised systems.

T1027.013
Encrypted/Encoded File
MalwareNinja

The Ninja payload is XOR encrypted and compressed. Ninja has also XORed its configuration data with a constant value of `0xAA`.

T1027.015
Compression
MalwareNinja

Ninja has compressed its data with the LZSS algorithm.

T1029
Scheduled Transfer
MalwareNinja

Ninja can configure its agent to work only in specific time frames.

T1036.005
Match Legitimate Resource Name or Location
MalwareNinja

Ninja has used legitimate looking filenames for its loader including update.dll and x64.dll.

T1055
Process Injection
MalwareNinja

Ninja has the ability to inject an agent module into a new process and arbitrary shellcode into running processes.

T1057
Process Discovery
MalwareNinja

Ninja can enumerate processes on a targeted host.

T1070.006
Timestomp
MalwareNinja

Ninja can change or create the last access or write times.

T1071.001
Web Protocols
MalwareNinja

Ninja can use HTTP for C2 communications.

T1082
System Information Discovery
MalwareNinja

Ninja can obtain the computer name and information on the OS from targeted hosts.

T1083
File and Directory Discovery
MalwareNinja

Ninja has the ability to enumerate directory content.

T1090.001
Internal Proxy
MalwareNinja

Ninja can proxy C2 communications including to and from internal agents without internet connectivity.

T1090.003
Multi-hop Proxy
MalwareNinja

Ninja has the ability to use a proxy chain with up to 255 hops when using TCP.

T1095
Non-Application Layer Protocol
MalwareNinja

Ninja can forward TCP packets between the C2 and a remote host.

T1106
Native API
MalwareNinja

The Ninja loader can call Windows APIs for discovery, process injection, and payload decryption.

T1132.002
Non-Standard Encoding
MalwareNinja

Ninja can encode C2 communications with a base64 algorithm using a custom alphabet.

T1140
Deobfuscate/Decode Files or Information
MalwareNinja

The Ninja loader component can decrypt and decompress the payload.

T1204.002
Malicious File
MalwareNinja

Ninja has gained execution through victims opening malicious executable files embedded in zip archives.

T1218.011
Rundll32
MalwareNinja

Ninja loader components can be executed through rundll32.exe.

T1480.001
Environmental Keying
MalwareNinja

Ninja can store its final payload in the Registry under `$HKLM\SOFTWARE\Classes\Interface\` encrypted with a dynamically generated key based on the drive’s serial number.

T1543.003
Windows Service
MalwareNinja

Ninja can create the services `httpsvc` and `w3esvc` for persistence .

T1559
Inter-Process Communication
MalwareNinja

Ninja can use pipes to redirect the standard input and the standard output.

T1566.003
Spearphishing via Service
MalwareNinja

Ninja has been distributed to victims via the messaging app Telegram.

T1573.001
Symmetric Cryptography
MalwareNinja

Ninja can XOR and AES encrypt C2 messages.

T1574.001
DLL
MalwareNinja

Ninja loaders can be side-loaded with legitimate and signed executables including the VLC.exe media player.

T1680
Local Storage Discovery
MalwareNinja

Ninja can obtain information on physical drives from targeted hosts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.