Real-world descriptions of how a group, tool or campaign used a technique.
31 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can collect files from compromised hosts. |
| T1027 Obfuscated Files or Information |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use a custom Base64 alphabet to encode an API decryption key. |
| T1027.001 Binary Padding |
MalwareCHIMNEYSWEEP | The CHIMNEYSWEEP installer has been padded with null bytes to inflate its size. |
| T1027.007 Dynamic API Resolution |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use `LoadLibrary` and `GetProcAddress` to resolve Windows API function strings at run time. |
| T1027.009 Embedded Payloads |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can extract RC4 encrypted embedded payloads for privilege escalation. |
| T1033 System Owner/User Discovery |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has included the victim's computer name and username in C2 messages sent to actor-owned infrastructure. |
| T1041 Exfiltration Over C2 Channel |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can upload collected files to the command-and-control server. |
| T1053.005 Scheduled Task |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use the Windows `SilentCleanup` scheduled task to enable payload execution. |
| T1056.001 Keylogging |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has the ability to support keylogging. |
| T1057 Process Discovery |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can check if a process name contains “creensaver.” |
| T1059.001 PowerShell |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can invoke the PowerShell command `[Reflection.Assembly]::LoadFile(\"%s\")\n$i=\"\"\n$r=[%s]::%s(\"%s\",[ref] $i)\necho $r,$i\n` to execute secondary payloads. |
| T1059.005 Visual Basic |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has executed a script named cln.vbs on compromised hosts. |
| T1070.006 Timestomp |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can time stomp its executable, previously dating it between 2010 to 2021. |
| T1071.001 Web Protocols |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can send `HTTP GET` requests to C2. |
| T1074.001 Local Data Staging |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can store captured screenshots to disk including to a covert store named `APPX.%x%x%x%x%x.tmp` where `%x` is a random value. |
| T1083 File and Directory Discovery |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has the ability to enumerate directories for files that match a set list. |
| T1102 Web Service |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has the ability to use use Telegram channels to return a list of commands to be executed, to download additional payloads, or to create a reverse shell. |
| T1105 Ingress Tool Transfer |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can download additional files from C2. |
| T1106 Native API |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use Windows APIs including `LoadLibrary` and `GetProcAddress`. |
| T1112 Modify Registry |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use the Windows Registry Environment key to change the `%windir%` variable to point to `c:\Windows` to enable payload execution. |
| T1113 Screen Capture |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can capture screenshots on targeted systems using a timer and either upload them or store them to disk. |
| T1115 Clipboard Data |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can capture content from the clipboard. |
| T1120 Peripheral Device Discovery |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can monitor for removable drives. |
| T1132.002 Non-Standard Encoding |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use a custom Base64 alphabet for encoding C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use an embedded RC4 key to decrypt Windows API function strings. |
| T1218.003 CMSTP |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use CMSTP.exe to install a malicious Microsoft Connection Manager Profile. |
| T1480 Execution Guardrails |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can execute a task which leads to execution if it finds a process name containing “creensaver.” |
| T1518.001 Security Software Discovery |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP is capable of checking whether a compromised device is running DeepFreeze by Faronics. |
| T1529 System Shutdown/Reboot |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can reboot or shutdown the targeted system or logoff the current user. |
| T1548.002 Bypass User Account Control |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can make use of the Windows `SilentCleanup` scheduled task to execute its payload with elevated privileges. |
| T1553.002 Code Signing |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has been dropped by a self-extracting archive signed with a valid digital certificate. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.