ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1141×

30 examples

TechniqueUsed byProcedure example
T1001.002
Steganography
MalwareLunarWeb

LunarWeb can receive C2 commands hidden in the structure of .jpg and .gif images.

T1016
System Network Configuration Discovery
MalwareLunarWeb

LunarWeb can use shell commands to discover network adapters and configuration.

T1027.013
Encrypted/Encoded File
MalwareLunarWeb

The LunarWeb install files have been encrypted with AES-256.

T1030
Data Transfer Size Limits
MalwareLunarWeb

LunarWeb can split exfiltrated data that exceeds 1.33 MB in size into multiple random sized parts between 384 and 512 KB.

T1033
System Owner/User Discovery
MalwareLunarWeb

LunarWeb can collect user information from the targeted host.

T1047
Windows Management Instrumentation
MalwareLunarWeb

LunarWeb can use WMI queries for discovery on the victim host.

T1049
System Network Connections Discovery
MalwareLunarWeb

LunarWeb can enumerate system network connections.

T1057
Process Discovery
MalwareLunarWeb

LunarWeb has used shell commands to list running processes.

T1059.001
PowerShell
MalwareLunarWeb

LunarWeb has the ability to run shell commands via PowerShell.

T1059.003
Windows Command Shell
MalwareLunarWeb

LunarWeb can run shell commands using a BAT file with a name matching `%TEMP%\<⁠random_9_alnum_chars>.batfile` or through cmd.exe with the `/c` and `/U` option for Unicode output.

T1069.001
Local Groups
MalwareLunarWeb

LunarWeb can discover local group memberships.

T1070.004
File Deletion
MalwareLunarWeb

LunarWeb can self-delete from a compromised host if safety checks of C2 connectivity fail.

T1071.001
Web Protocols
MalwareLunarWeb

LunarWeb can use `POST` to send victim identification to C2 and `GET` to retrieve commands.

T1082
System Information Discovery
MalwareLunarWeb

LunarWeb can use WMI queries and shell commands such as systeminfo.exe to collect the operating system, BIOS version, and domain name of the targeted system.

T1083
File and Directory Discovery
MalwareLunarWeb

LunarWeb has the ability to retrieve directory listings.

T1090
Proxy
MalwareLunarWeb

LunarWeb has the ability to use a HTTP proxy server for C&C communications.

T1104
Multi-Stage Channels
MalwareLunarWeb

LunarWeb can use one C2 URL for first contact and to upload information about the host computer and two additional C2 URLs for getting commands.

T1132.001
Standard Encoding
MalwareLunarWeb

LunarWeb can use Base64 encoding to obfuscate C2 commands.

T1135
Network Share Discovery
MalwareLunarWeb

LunarWeb can identify shared resources in compromised environments.

T1140
Deobfuscate/Decode Files or Information
MalwareLunarWeb

LunarWeb can decrypt strings related to communication configuration using RC4 with a static key.

T1497.003
Time Based Checks
MalwareLunarWeb

LunarWeb can pause for a number of hours before entering its C2 communication loop.

T1518
Software Discovery
MalwareLunarWeb

LunarWeb can list installed software on compromised systems.

T1518.001
Security Software Discovery
MalwareLunarWeb

LunarWeb has run shell commands to obtain a list of installed security products.

T1559
Inter-Process Communication
MalwareLunarWeb

LunarWeb can retrieve output from arbitrary processes and shell commands via a pipe.

T1560.001
Archive via Utility
MalwareLunarWeb

LunarWeb can create a ZIP archive with specified files and directories.

T1560.002
Archive via Library
MalwareLunarWeb

LunarWeb can zlib-compress data prior to exfiltration.

T1572
Protocol Tunneling
MalwareLunarWeb

LunarWeb can run a custom binary protocol under HTTPS for C2.

T1573.001
Symmetric Cryptography
MalwareLunarWeb

LunarWeb can send AES encrypted C2 commands.

T1573.002
Asymmetric Cryptography
MalwareLunarWeb

LunarWeb can send short C2 commands, up to 512 bytes, encrypted with RSA-4096.

T1615
Group Policy Discovery
MalwareLunarWeb

LunarWeb can capture information on group policy settings

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.