Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareSocGholish | SocGholish has the ability to enumerate the domain name of a victim, as well as if the host is a member of an Active Directory domain. |
| T1027.013 Encrypted/Encoded File |
MalwareSocGholish | SocGholish has single or double Base-64 encoded references to its second-stage server URLs. |
| T1027.015 Compression |
MalwareSocGholish | The SocGholish JavaScript payload has been delivered within a compressed ZIP archive. |
| T1033 System Owner/User Discovery |
MalwareSocGholish | SocGholish can use `whoami` to obtain the username from a compromised host. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSocGholish | SocGholish has been named `AutoUpdater.js` to mimic legitimate update files. |
| T1047 Windows Management Instrumentation |
MalwareSocGholish | SocGholish has used WMI calls for script execution and system profiling. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareSocGholish | SocGholish can exfiltrate data directly to its C2 domain via HTTP. |
| T1057 Process Discovery |
MalwareSocGholish | SocGholish can list processes on targeted hosts. |
| T1059.007 JavaScript |
MalwareSocGholish | The SocGholish payload is executed as JavaScript. |
| T1074.001 Local Data Staging |
MalwareSocGholish | SocGholish can send output from `whoami` to a local temp file using the naming convention `rad<5-hex-chars>.tmp`. |
| T1082 System Information Discovery |
MalwareSocGholish | SocGholish has the ability to enumerate system information including the victim computer name. |
| T1102 Web Service |
MalwareSocGholish | SocGholish has used Amazon Web Services to host second-stage servers. |
| T1105 Ingress Tool Transfer |
MalwareSocGholish | SocGholish can download additional malware to infected hosts. |
| T1189 Drive-by Compromise |
MalwareSocGholish | SocGholish has been distributed through compromised websites with malicious content often masquerading as browser updates. |
| T1204.001 Malicious Link |
MalwareSocGholish | SocGholish has lured victims into interacting with malicious links on compromised websites for execution. |
| T1482 Domain Trust Discovery |
MalwareSocGholish | SocGholish can profile compromised systems to identify domain trust relationships. |
| T1518 Software Discovery |
MalwareSocGholish | SocGholish can identify the victim's browser in order to serve the correct fake update page. |
| T1566.002 Spearphishing Link |
MalwareSocGholish | SocGholish has been spread via emails containing malicious links. |
| T1614 System Location Discovery |
MalwareSocGholish | SocGholish can use IP-based geolocation to limit infections to victims in North America, Europe, and a small number of Asian-Pacific nations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.