ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1124×

19 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareSocGholish

SocGholish has the ability to enumerate the domain name of a victim, as well as if the host is a member of an Active Directory domain.

T1027.013
Encrypted/Encoded File
MalwareSocGholish

SocGholish has single or double Base-64 encoded references to its second-stage server URLs.

T1027.015
Compression
MalwareSocGholish

The SocGholish JavaScript payload has been delivered within a compressed ZIP archive.

T1033
System Owner/User Discovery
MalwareSocGholish

SocGholish can use `whoami` to obtain the username from a compromised host.

T1036.005
Match Legitimate Resource Name or Location
MalwareSocGholish

SocGholish has been named `AutoUpdater.js` to mimic legitimate update files.

T1047
Windows Management Instrumentation
MalwareSocGholish

SocGholish has used WMI calls for script execution and system profiling.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareSocGholish

SocGholish can exfiltrate data directly to its C2 domain via HTTP.

T1057
Process Discovery
MalwareSocGholish

SocGholish can list processes on targeted hosts.

T1059.007
JavaScript
MalwareSocGholish

The SocGholish payload is executed as JavaScript.

T1074.001
Local Data Staging
MalwareSocGholish

SocGholish can send output from `whoami` to a local temp file using the naming convention `rad<5-hex-chars>.tmp`.

T1082
System Information Discovery
MalwareSocGholish

SocGholish has the ability to enumerate system information including the victim computer name.

T1102
Web Service
MalwareSocGholish

SocGholish has used Amazon Web Services to host second-stage servers.

T1105
Ingress Tool Transfer
MalwareSocGholish

SocGholish can download additional malware to infected hosts.

T1189
Drive-by Compromise
MalwareSocGholish

SocGholish has been distributed through compromised websites with malicious content often masquerading as browser updates.

T1204.001
Malicious Link
MalwareSocGholish

SocGholish has lured victims into interacting with malicious links on compromised websites for execution.

T1482
Domain Trust Discovery
MalwareSocGholish

SocGholish can profile compromised systems to identify domain trust relationships.

T1518
Software Discovery
MalwareSocGholish

SocGholish can identify the victim's browser in order to serve the correct fake update page.

T1566.002
Spearphishing Link
MalwareSocGholish

SocGholish has been spread via emails containing malicious links.

T1614
System Location Discovery
MalwareSocGholish

SocGholish can use IP-based geolocation to limit infections to victims in North America, Europe, and a small number of Asian-Pacific nations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.