ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1160×

43 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareLatrodectus

Latrodectus can collect data from a compromised host using a stealer module.

T1016
System Network Configuration Discovery
MalwareLatrodectus

Latrodectus can discover the IP and MAC address of a targeted host.

T1021.005
VNC
MalwareLatrodectus

Latrodectus has routed C2 traffic using Keyhole VNC.

T1027.001
Binary Padding
MalwareLatrodectus

Latrodectus has been obfuscated with a 129 byte sequence of junk data prepended to the file.

T1027.002
Software Packing
MalwareLatrodectus

The Latrodectus payload has been packed for obfuscation.

T1027.007
Dynamic API Resolution
MalwareLatrodectus

Latrodectus can resolve Windows APIs dynamically by hash.

T1027.013
Encrypted/Encoded File
MalwareLatrodectus

Latrodectus has used a pseudo random number generator (PRNG) algorithm and a rolling XOR key to obfuscate strings.

T1033
System Owner/User Discovery
MalwareLatrodectus

Latrodectus can discover the username of an infected host.

T1036.005
Match Legitimate Resource Name or Location
MalwareLatrodectus

Latrodectus has been packed to appear as a component to Bitdefender’s kernel-mode driver, TRUFOS.SYS.

T1041
Exfiltration Over C2 Channel
MalwareLatrodectus

Latrodectus can exfiltrate encrypted system information to the C2 server.

T1047
Windows Management Instrumentation
MalwareLatrodectus

Latrodectus has used WMI in malicious email infection chains to facilitate the installation of remotely-hosted files.

T1053.005
Scheduled Task
MalwareLatrodectus

Latrodectus can create scheduled tasks for persistence.

T1057
Process Discovery
MalwareLatrodectus

Latrodectus can enumerate running processes including process grandchildren on targeted hosts.

T1059.003
Windows Command Shell
MalwareLatrodectus

The Latrodectus command handler can use `cmdexe` to run multiple discovery commands.

T1059.007
JavaScript
MalwareLatrodectus

Latrodectus has used JavaScript files as part its infection chain during malicious spam
email campaigns.

T1069.002
Domain Groups
MalwareLatrodectus

Latrodectus can identify domain groups through `cmd.exe /c net group "Domain Admins" /domain`.

T1070.004
File Deletion
MalwareLatrodectus

Latrodectus has the ability to delete itself.

T1071.001
Web Protocols
MalwareLatrodectus

Latrodectus can send registration information to C2 via HTTP `POST`.

T1082
System Information Discovery
MalwareLatrodectus

Latrodectus can gather operating system information.

T1083
File and Directory Discovery
MalwareLatrodectus

Latrodectus can collect desktop filenames.

T1087.002
Domain Account
MalwareLatrodectus

Latrodectus can run `C:\Windows\System32\cmd.exe /c net group "Domain Admins" /domain` to identify domain administrator accounts.

T1102
Web Service
MalwareLatrodectus

Latrodectus has used Google Firebase to download malicious installation scripts.

T1104
Multi-Stage Channels
MalwareLatrodectus

Latrodectus has used a two-tiered C2 configuration with tier one nodes connecting to the victim and tier two nodes connecting to backend infrastructure.

T1105
Ingress Tool Transfer
MalwareLatrodectus

Latrodectus can download and execute PEs, DLLs, and shellcode from C2.

T1106
Native API
MalwareLatrodectus

Latrodectus has used multiple Windows API post exploitation including `GetAdaptersInfo`, `CreateToolhelp32Snapshot`, and `CreateProcessW`.

T1132.001
Standard Encoding
MalwareLatrodectus

Latrodectus has Base64-encoded the message body of a HTTP request sent to C2.

T1135
Network Share Discovery
MalwareLatrodectus

Latrodectus can run `C:\Windows\System32\cmd.exe /c net view /all` to discover network shares.

T1140
Deobfuscate/Decode Files or Information
MalwareLatrodectus

Latrodectus has the ability to deobfuscate encrypted strings.

T1204.001
Malicious Link
MalwareLatrodectus

Latrodectus has been executed through malicious links distributed in email campaigns.

T1204.002
Malicious File
MalwareLatrodectus

Latrodectus has lured users into opening malicious email attachments for execution.

T1218.007
Msiexec
MalwareLatrodectus

Latrodectus has called `msiexec` to install remotely-hosted MSI files.

T1218.011
Rundll32
MalwareLatrodectus

Latrodectus can use rundll32.exe to execute downloaded DLLs.

T1482
Domain Trust Discovery
MalwareLatrodectus

Latrodectus can run `C:\Windows\System32\cmd.exe /c nltest /domain_trusts` to discover domain trusts.

T1497.001
System Checks
MalwareLatrodectus

Latrodectus can determine if it is running in a virtualized environment by checking the OS version, checking the number of running processes, ensuring a 64-bit application is running on a 64-bit host, and checking if the host has a valid MAC address.

T1518.001
Security Software Discovery
MalwareLatrodectus

Latrodectus has the ability to identify installed antivirus products.

T1529
System Shutdown/Reboot
MalwareLatrodectus

Latrodectus has the ability to restart compromised hosts.

T1547.001
Registry Run Keys / Startup Folder
MalwareLatrodectus

Latrodectus can set an AutoRun key to establish persistence.

T1559.001
Component Object Model
MalwareLatrodectus

Latrodectus can use the Windows Component Object Model (COM) to set scheduled tasks.

T1564.004
NTFS File Attributes
MalwareLatrodectus

Latrodectus can delete itself while its process is still running through the use of an alternate data stream.

T1566.001
Spearphishing Attachment
MalwareLatrodectus

Latrodectus has been distributed through reply-chain phishing emails with malicious attachments.

T1566.002
Spearphishing Link
MalwareLatrodectus

Latrodectus has been distributed to victims through emails containing malicious links.

T1573.001
Symmetric Cryptography
MalwareLatrodectus

Latrodectus can send RC4 encrypted data over C2 channels.

T1622
Debugger Evasion
MalwareLatrodectus

Latrodectus has the ability to check for the presence of debuggers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.