ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1183×

34 examples

TechniqueUsed byProcedure example
T1001
Data Obfuscation
MalwareStrelaStealer

StrelaStealer encrypts the payload of HTTP POST communications using the same XOR key used for the malware's DLL payload.

T1020
Automated Exfiltration
MalwareStrelaStealer

StrelaStealer automatically sends gathered email credentials following collection to command and control servers via HTTP POST.

T1027
Obfuscated Files or Information
MalwareStrelaStealer

StrelaStealer has been distributed in ISO archives. StrelaStealer has been delivered in encrypted, password-protected ZIP archives.

T1027.002
Software Packing
MalwareStrelaStealer

StrelaStealer variants have used packers to obfuscate payloads and make analysis more difficult.

T1027.013
Encrypted/Encoded File
MalwareStrelaStealer

StrelaStealer uses XOR-encoded strings to obfuscate items.

T1027.015
Compression
MalwareStrelaStealer

StrelaStealer has been delivered via JScript files in a ZIP archive.

T1027.016
Junk Code Insertion
MalwareStrelaStealer

StrelaStealer variants have included excessive mathematical functions padding the binary and slowing execution for anti-analysis and sandbox evasion purposes.

T1036
Masquerading
MalwareStrelaStealer

StrelaStealer PE executable payloads have used uncommon but legitimate extensions such as `.com` instead of `.exe`.

T1036.003
Rename Legitimate Utilities
MalwareStrelaStealer

StrelaStealer has used a renamed, legitimate `msinfo32.exe` executable to sideload the StrelaStealer payload during initial installation.

T1036.005
Match Legitimate Resource Name or Location
MalwareStrelaStealer

StrelaStealer payloads have tailored filenames to include names identical to the name of the targeted organization or company.

T1036.008
Masquerade File Type
MalwareStrelaStealer

StrelaStealer has been distributed as a DLL/HTML polyglot file.

T1041
Exfiltration Over C2 Channel
MalwareStrelaStealer

StrelaStealer exfiltrates collected email credentials via HTTP POST to command and control servers.

T1059.001
PowerShell
MalwareStrelaStealer

StrelaStealer variants have used PowerShell scripts to download or drop payloads, including obfuscated variants to connect to a WebDAV server to download and executed an encrypted DLL for installation.

T1059.003
Windows Command Shell
MalwareStrelaStealer

StrelaStealer has included BAT files in some instances for installation.

T1059.007
JavaScript
MalwareStrelaStealer

StrelaStealer has been distributed as a malicious JavaScript object.

T1071.001
Web Protocols
MalwareStrelaStealer

StrelaStealer communicates externally via HTTP POST with encrypted content.

T1082
System Information Discovery
MalwareStrelaStealer

StrelaStealer variants collect victim system information for exfiltration.

T1105
Ingress Tool Transfer
MalwareStrelaStealer

StrelaStealer installers have used obfuscated PowerShell scripts to retrieve follow-on payloads from WebDAV servers.

T1119
Automated Collection
MalwareStrelaStealer

StrelaStealer attempts to identify and collect mail login data from Thunderbird and Outlook following execution.

T1132.001
Standard Encoding
MalwareStrelaStealer

StrelaStealer utilizes a hard-coded XOR key to encrypt the content of HTTP POST requests to command and control infrastructure.

T1140
Deobfuscate/Decode Files or Information
MalwareStrelaStealer

StrelaStealer payloads have included strings encrypted via XOR. StrelaStealer JavaScript payloads utilize Base64-encoded payloads that are decoded via certutil to create a malicious DLL file.

T1204.002
Malicious File
MalwareStrelaStealer

StrelaStealer relies on user execution of a malicious file for installation.

T1218.011
Rundll32
MalwareStrelaStealer

StrelaStealer DLL payloads have been executed via `rundll32.exe`.

T1480
Execution Guardrails
MalwareStrelaStealer

StrelaStealer variants only execute if the keyboard layout or language matches a set list of variables.

T1480.002
Mutual Exclusion
MalwareStrelaStealer

StrelaStealer variants include the use of mutex values based on the victim system name to prevent reinfection.

T1497
Virtualization/Sandbox Evasion
MalwareStrelaStealer

StrelaStealer payloads have used control flow obfuscation techniques such as excessively long code blocks of mathematical instructions to defeat sandboxing and related analysis methods.

T1518
Software Discovery
MalwareStrelaStealer

StrelaStealer variants use COM objects to enumerate installed applications from the "AppsFolder" on victim machines.

T1552.001
Credentials In Files
MalwareStrelaStealer

StrelaStealer searches for and if found collects the contents of files such as `logins.json` and `key4.db` in the `$APPDATA%\Thunderbird\Profiles\` directory, associated with the Thunderbird email application.

T1552.002
Credentials in Registry
MalwareStrelaStealer

StrelaStealer enumerates the registry key `HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\` to identify the values for "IMAP User," "IMAP Server," and "IMAP Password" associated with the Outlook email application.

T1553.002
Code Signing
MalwareStrelaStealer

StrelaStealer variants have used valid code signing certificates.

T1566.001
Spearphishing Attachment
MalwareStrelaStealer

StrelaStealer has been distributed as a spearphishing attachment.

T1574.001
DLL
MalwareStrelaStealer

StrelaStealer has sideloaded a DLL payload using a renamed, legitimate `msinfo32.exe` executable.

T1614.001
System Language Discovery
MalwareStrelaStealer

StrelaStealer variants check system language settings via keyboard layout or similar mechanisms.

T1622
Debugger Evasion
MalwareStrelaStealer

StrelaStealer variants include functionality to identify and evade debuggers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.