ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1138×

18 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareGootloader

Gootloader can use an embedded script to check the IP address of potential victims visiting compromised websites.

T1027
Obfuscated Files or Information
MalwareGootloader

The Gootloader first stage script is obfuscated using random alpha numeric strings.

T1055.002
Portable Executable Injection
MalwareGootloader

Gootloader can use its own PE loader to execute payloads in memory.

T1055.012
Process Hollowing
MalwareGootloader

Gootloader can inject its Delphi executable into ImagingDevices.exe using a process hollowing technique.

T1059.001
PowerShell
MalwareGootloader

Gootloader can use an encoded PowerShell stager to write to the Registry for persistence.

T1059.007
JavaScript
MalwareGootloader

Gootloader can execute a Javascript file for initial infection.

T1069.002
Domain Groups
MalwareGootloader

Gootloader can determine if a targeted system is part of an Active Directory domain by expanding the %USERDNSDOMAIN% environment variable.

T1082
System Information Discovery
MalwareGootloader

Gootloader can inspect the User-Agent string in GET request header information to determine the operating system of targeted systems.

T1105
Ingress Tool Transfer
MalwareGootloader

Gootloader can fetch second stage code from hardcoded web domains.

T1132.001
Standard Encoding
MalwareGootloader

Gootloader can retrieve a Base64 encoded stager from C2.

T1140
Deobfuscate/Decode Files or Information
MalwareGootloader

Gootloader has the ability to decode and decrypt malicious payloads prior to execution.

T1204.001
Malicious Link
MalwareGootloader

Gootloader has been executed through malicious links presented to users as internet search results.

T1497.003
Time Based Checks
MalwareGootloader

Gootloader can designate a sleep period of more than 22 seconds between stages of infection.

T1547.001
Registry Run Keys / Startup Folder
MalwareGootloader

Gootloader can create an autorun entry for a PowerShell script to run at reboot.

T1584.001
Domains
MalwareGootloader

Gootloader has used compromised legitimate domains to as a delivery network for malicious payloads.

T1584.006
Web Services
MalwareGootloader

Gootloader can insert malicious scripts to compromise vulnerable content management systems (CMS).

T1614
System Location Discovery
MalwareGootloader

Gootloader can use IP geolocation to determine if the person browsing to a compromised site is within a targeted territory such as the US, Canada, Germany, and South Korea.

T1614.001
System Language Discovery
MalwareGootloader

Gootloader can determine if a victim's computer is running an operating system with specific language preferences.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.