ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1210×

18 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareSagerunex

Sagerunex will gather system information such as MAC and IP addresses.

T1027.002
Software Packing
MalwareSagerunex

Sagerunex has used VMProtect to pack and obscure itself.

T1027.013
Encrypted/Encoded File
MalwareSagerunex

Sagerunex can be passed a reference to an XOR-encrypted configuration file at runtime.

T1041
Exfiltration Over C2 Channel
MalwareSagerunex

Sagerunex encrypts collected system data then exfiltrates via existing command and control channels.

T1055.001
Dynamic-link Library Injection
MalwareSagerunex

Sagerunex is designed to be dynamic link library (DLL) injected into an infected endpoint and executed directly in memory.

T1057
Process Discovery
MalwareSagerunex

Sagerunex identifies the `explorer.exe` process on the executing system.

T1071.001
Web Protocols
MalwareSagerunex

Sagerunex communicates via HTTPS, at times using a hard-coded User Agent of `Mozilla/5.0 (compatible; MSIE 7.0; Win32)`.

T1074.001
Local Data Staging
MalwareSagerunex

Sagerunex gathers host information and stages it locally as a RAR file prior to exfiltration. Sagerunex stores logged data in an encrypted file located at `%TEMP%/TS_FB56.tmp` during execution.

T1082
System Information Discovery
MalwareSagerunex

Sagerunex gathers information from the infected system such as hostname.

T1090
Proxy
MalwareSagerunex

Sagerunex uses several proxy configuration settings to ensure connectivity.

T1102.002
Bidirectional Communication
MalwareSagerunex

Sagerunex has used virtual private servers (VPS) for command and control traffic as well as third-party cloud services in more recent variants.

T1102.003
One-Way Communication
MalwareSagerunex

Sagerunex has used web services such as Twitter for command and control purposes.

T1106
Native API
MalwareSagerunex

Sagerunex calls the `WaitForSingleObject` API function as part of time-check logic.

T1134
Access Token Manipulation
MalwareSagerunex

Sagerunex finds the `explorer.exe` process after execution and uses it to change the token of its executing thread.

T1140
Deobfuscate/Decode Files or Information
MalwareSagerunex

Sagerunex uses a custom decryption routine to unpack itself during installation.

T1480
Execution Guardrails
MalwareSagerunex

Sagerunex uses a "servicemain" function to verify its environment to ensure it can only be executed as a service, as well as the existence of a configuration file in a specified directory.

T1560.001
Archive via Utility
MalwareSagerunex

Sagerunex has archived collected materials in RAR format.

T1573.002
Asymmetric Cryptography
MalwareSagerunex

Sagerunex uses HTTPS for command and control communication.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.