ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1142×

17 examples

TechniqueUsed byProcedure example
T1001.002
Steganography
MalwareLunarMail

LunarMail can parse IDAT chunks from .png files to look for zlib-compressed and AES encrypted C2 commands.

T1027.013
Encrypted/Encoded File
MalwareLunarMail

LunarMail has used RC4 and AES to encrypt strings and its exfiltration configuration respectively.

T1041
Exfiltration Over C2 Channel
MalwareLunarMail

LunarMail can use email image attachments with embedded data for receiving C2 commands and data exfiltration.

T1059.005
Visual Basic
MalwareLunarMail

LunarMail has been installed using a VBA macro.

T1070.004
File Deletion
MalwareLunarMail

LunarMail can delete the previously used staging directory and files on subsequent rounds of exfiltration and replace it with a new one.

T1070.008
Clear Mailbox Data
MalwareLunarMail

LunarMail can set the `PR_DELETE_AFTER_SUBMIT` flag to delete messages sent for data exfiltration.

T1071.003
Mail Protocols
MalwareLunarMail

LunarMail can communicates with C2 using email messages via the Outlook Messaging API (MAPI).

T1074.001
Local Data Staging
MalwareLunarMail

LunarMail can create a directory in `%TEMP%\` to stage data prior to exfilration.

T1082
System Information Discovery
MalwareLunarMail

LunarMail can capture environmental variables on compromised hosts.

T1083
File and Directory Discovery
MalwareLunarMail

LunarMail can search its staging directory for output files it has produced.

T1095
Non-Application Layer Protocol
MalwareLunarMail

LunarMail can ping a specific C2 URL with the ID of a victim machine in the subdomain.

T1113
Screen Capture
MalwareLunarMail

LunarMail can capture screenshots from compromised hosts.

T1114.001
Local Email Collection
MalwareLunarMail

LunarMail can capture the recipients of sent email messages from compromised accounts.

T1137.006
Add-ins
MalwareLunarMail

LunarMail has the ability to use Outlook add-ins for persistence.

T1140
Deobfuscate/Decode Files or Information
MalwareLunarMail

LunarMail can decrypt strings to retrieve configuration settings.

T1204.002
Malicious File
MalwareLunarMail

LunarMail has been installed through a malicious macro in a Microsoft Word document.

T1543
Create or Modify System Process
MalwareLunarMail

LunarMail can create an arbitrary process with a specified command line and redirect its output to a staging directory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.