ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1149×

31 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can collect files from compromised hosts.

T1027
Obfuscated Files or Information
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use a custom Base64 alphabet to encode an API decryption key.

T1027.001
Binary Padding
MalwareCHIMNEYSWEEP

The CHIMNEYSWEEP installer has been padded with null bytes to inflate its size.

T1027.007
Dynamic API Resolution
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use `LoadLibrary` and `GetProcAddress` to resolve Windows API function strings at run time.

T1027.009
Embedded Payloads
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can extract RC4 encrypted embedded payloads for privilege escalation.

T1033
System Owner/User Discovery
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has included the victim's computer name and username in C2 messages sent to actor-owned infrastructure.

T1041
Exfiltration Over C2 Channel
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can upload collected files to the command-and-control server.

T1053.005
Scheduled Task
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use the Windows `SilentCleanup` scheduled task to enable payload execution.

T1056.001
Keylogging
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has the ability to support keylogging.

T1057
Process Discovery
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can check if a process name contains “creensaver.”

T1059.001
PowerShell
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can invoke the PowerShell command `[Reflection.Assembly]::LoadFile(\"%s\")\n$i=\"\"\n$r=[%s]::%s(\"%s\",[ref] $i)\necho $r,$i\n` to execute secondary payloads.

T1059.005
Visual Basic
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has executed a script named cln.vbs on compromised hosts.

T1070.006
Timestomp
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can time stomp its executable, previously dating it between 2010 to 2021.

T1071.001
Web Protocols
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can send `HTTP GET` requests to  C2.

T1074.001
Local Data Staging
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can store captured screenshots to disk including to a covert store named `APPX.%x%x%x%x%x.tmp` where `%x` is a random value.

T1083
File and Directory Discovery
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has the ability to enumerate directories for files that match a set list.

T1102
Web Service
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has the ability to use use Telegram channels to return a list of commands to be executed, to download additional payloads, or to create a reverse shell.

T1105
Ingress Tool Transfer
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can download additional files from C2.

T1106
Native API
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use Windows APIs including `LoadLibrary` and `GetProcAddress`.

T1112
Modify Registry
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use the Windows Registry Environment key to change the `%windir%` variable to point to `c:\Windows` to enable payload execution.

T1113
Screen Capture
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can capture screenshots on targeted systems using a timer and either upload them or store them to disk.

T1115
Clipboard Data
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can capture content from the clipboard.

T1120
Peripheral Device Discovery
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can monitor for removable drives.

T1132.002
Non-Standard Encoding
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use a custom Base64 alphabet for encoding C2.

T1140
Deobfuscate/Decode Files or Information
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use an embedded RC4 key to decrypt Windows API function strings.

T1218.003
CMSTP
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use CMSTP.exe to install a malicious Microsoft Connection Manager Profile.

T1480
Execution Guardrails
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can execute a task which leads to execution if it finds a process name containing “creensaver.”

T1518.001
Security Software Discovery
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP is capable of checking whether a compromised device is running DeepFreeze by Faronics.

T1529
System Shutdown/Reboot
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can reboot or shutdown the targeted system or logoff the current user.

T1548.002
Bypass User Account Control
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can make use of the Windows `SilentCleanup` scheduled task to execute its payload with elevated privileges.

T1553.002
Code Signing
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has been dropped by a self-extracting archive signed with a valid digital certificate.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.