Real-world descriptions of how a group, tool or campaign used a technique.
30 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.002 Steganography |
MalwareLunarWeb | LunarWeb can receive C2 commands hidden in the structure of .jpg and .gif images. |
| T1016 System Network Configuration Discovery |
MalwareLunarWeb | LunarWeb can use shell commands to discover network adapters and configuration. |
| T1027.013 Encrypted/Encoded File |
MalwareLunarWeb | The LunarWeb install files have been encrypted with AES-256. |
| T1030 Data Transfer Size Limits |
MalwareLunarWeb | LunarWeb can split exfiltrated data that exceeds 1.33 MB in size into multiple random sized parts between 384 and 512 KB. |
| T1033 System Owner/User Discovery |
MalwareLunarWeb | LunarWeb can collect user information from the targeted host. |
| T1047 Windows Management Instrumentation |
MalwareLunarWeb | LunarWeb can use WMI queries for discovery on the victim host. |
| T1049 System Network Connections Discovery |
MalwareLunarWeb | LunarWeb can enumerate system network connections. |
| T1057 Process Discovery |
MalwareLunarWeb | LunarWeb has used shell commands to list running processes. |
| T1059.001 PowerShell |
MalwareLunarWeb | LunarWeb has the ability to run shell commands via PowerShell. |
| T1059.003 Windows Command Shell |
MalwareLunarWeb | LunarWeb can run shell commands using a BAT file with a name matching `%TEMP%\<random_9_alnum_chars>.batfile` or through cmd.exe with the `/c` and `/U` option for Unicode output. |
| T1069.001 Local Groups |
MalwareLunarWeb | LunarWeb can discover local group memberships. |
| T1070.004 File Deletion |
MalwareLunarWeb | LunarWeb can self-delete from a compromised host if safety checks of C2 connectivity fail. |
| T1071.001 Web Protocols |
MalwareLunarWeb | LunarWeb can use `POST` to send victim identification to C2 and `GET` to retrieve commands. |
| T1082 System Information Discovery |
MalwareLunarWeb | LunarWeb can use WMI queries and shell commands such as systeminfo.exe to collect the operating system, BIOS version, and domain name of the targeted system. |
| T1083 File and Directory Discovery |
MalwareLunarWeb | LunarWeb has the ability to retrieve directory listings. |
| T1090 Proxy |
MalwareLunarWeb | LunarWeb has the ability to use a HTTP proxy server for C&C communications. |
| T1104 Multi-Stage Channels |
MalwareLunarWeb | LunarWeb can use one C2 URL for first contact and to upload information about the host computer and two additional C2 URLs for getting commands. |
| T1132.001 Standard Encoding |
MalwareLunarWeb | LunarWeb can use Base64 encoding to obfuscate C2 commands. |
| T1135 Network Share Discovery |
MalwareLunarWeb | LunarWeb can identify shared resources in compromised environments. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLunarWeb | LunarWeb can decrypt strings related to communication configuration using RC4 with a static key. |
| T1497.003 Time Based Checks |
MalwareLunarWeb | LunarWeb can pause for a number of hours before entering its C2 communication loop. |
| T1518 Software Discovery |
MalwareLunarWeb | LunarWeb can list installed software on compromised systems. |
| T1518.001 Security Software Discovery |
MalwareLunarWeb | LunarWeb has run shell commands to obtain a list of installed security products. |
| T1559 Inter-Process Communication |
MalwareLunarWeb | LunarWeb can retrieve output from arbitrary processes and shell commands via a pipe. |
| T1560.001 Archive via Utility |
MalwareLunarWeb | LunarWeb can create a ZIP archive with specified files and directories. |
| T1560.002 Archive via Library |
MalwareLunarWeb | LunarWeb can zlib-compress data prior to exfiltration. |
| T1572 Protocol Tunneling |
MalwareLunarWeb | LunarWeb can run a custom binary protocol under HTTPS for C2. |
| T1573.001 Symmetric Cryptography |
MalwareLunarWeb | LunarWeb can send AES encrypted C2 commands. |
| T1573.002 Asymmetric Cryptography |
MalwareLunarWeb | LunarWeb can send short C2 commands, up to 512 bytes, encrypted with RSA-4096. |
| T1615 Group Policy Discovery |
MalwareLunarWeb | LunarWeb can capture information on group policy settings |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.