ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1207×

28 examples

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareXLoader

XLoader uses various packers, including CyaX, to obfuscate malicious executables.

T1027.013
Encrypted/Encoded File
MalwareXLoader

XLoader features encrypted functions using the RC4 algorithm and bytecode operations.

T1033
System Owner/User Discovery
MalwareXLoader

XLoader can identify the username from a victim machine.

T1053.005
Scheduled Task
MalwareXLoader

XLoader can create scheduled tasks for persistence.

T1055.004
Asynchronous Procedure Call
MalwareXLoader

XLoader injects code into the APC queue using `NtQueueApcThread` API.

T1055.012
Process Hollowing
MalwareXLoader

XLoader uses process hollowing by injecting itself into the `explorer.exe` process and other files ithin the Windows `SysWOW64` directory.

T1056.001
Keylogging
MalwareXLoader

XLoader can capture keystrokes from the victim machine.

T1059.010
AutoHotKey & AutoIT
MalwareXLoader

XLoader can use an AutoIT script to decrypt a payload file, load it into victim memory, then execute it on the victim machine.

T1070.004
File Deletion
MalwareXLoader

XLoader can delete malicious executables from compromised machines.

T1071.001
Web Protocols
MalwareXLoader

XLoader uses HTTP and HTTPS for command and control communication.

T1082
System Information Discovery
MalwareXLoader

XLoader can collect system information and supported language information from the victim machine.

T1106
Native API
MalwareXLoader

XLoader uses the native Windows API for functionality, including defense evasion.

T1113
Screen Capture
MalwareXLoader

XLoader can capture screenshots on compromised hosts.

T1115
Clipboard Data
MalwareXLoader

XLoader can collect data stored in the victim's clipboard.

T1140
Deobfuscate/Decode Files or Information
MalwareXLoader

XLoader uses XOR and RC4 algorithms to decrypt payloads and functions. XLoader can be distributed as a self-extracting RAR archive that launches an AutoIT loader.

T1185
Browser Session Hijacking
MalwareXLoader

XLoader can conduct form grabbing, steal cookies, and extract data from HTTP sessions.

T1203
Exploitation for Client Execution
MalwareXLoader

XLoader has exploited Office vulnerabilities during local execution such as CVE-2017-11882 and CVE-2018-0798.

T1497
Virtualization/Sandbox Evasion
MalwareXLoader

XLoader can utilize decoy command and control domains within the malware configuration to circumvent sandbox analysis.

T1497.001
System Checks
MalwareXLoader

XLoader performs timing checks using the Read-Time Stamp Counter (RDTSC) instruction on the victim CPU.

T1529
System Shutdown/Reboot
MalwareXLoader

XLoader can initiate a system reboot or shutdown.

T1539
Steal Web Session Cookie
MalwareXLoader

XLoader can capture web session cookies and session information from victim browsers.

T1547.001
Registry Run Keys / Startup Folder
MalwareXLoader

XLoader establishes persistence by copying its executable in a subdirectory of `%APPDATA%` or `%PROGRAMFILES%`, and then modifies Windows Registry Run keys or policies keys to execute the executable on system start.

T1555
Credentials from Password Stores
MalwareXLoader

XLoader can collect credentials stored in email clients.

T1555.003
Credentials from Web Browsers
MalwareXLoader

XLoader can gather credentials from several web browsers.

T1566.001
Spearphishing Attachment
MalwareXLoader

XLoader has been delivered as a phishing attachment, including PDFs with embedded links, Word and Excel files, and various archive files (ZIP, RAR, ACE, and ISOs) containing EXE payloads.

T1583.001
Domains
MalwareXLoader

XLoader can utilize hardcoded command and control domain configurations created by the XLoader authors. These are designed to mimic domain registrars and hosting service providers such as Hostinger and Namecheap.

T1622
Debugger Evasion
MalwareXLoader

XLoader uses anti-debugging mechanisms such as calling `NtQueryInformationProcess` with `InfoClass=7`, referencing `ProcessDebugPort`, to determine if it is being analyzed.

T1685
Disable or Modify Tools
MalwareXLoader

XLoader loads a copy of NTDLL to evade hooks from security monitoring tools on this library. XLoader can add the path of its executable to the Microsoft Defender exclusion list.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.