Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareSagerunex | Sagerunex will gather system information such as MAC and IP addresses. |
| T1027.002 Software Packing |
MalwareSagerunex | Sagerunex has used VMProtect to pack and obscure itself. |
| T1027.013 Encrypted/Encoded File |
MalwareSagerunex | Sagerunex can be passed a reference to an XOR-encrypted configuration file at runtime. |
| T1041 Exfiltration Over C2 Channel |
MalwareSagerunex | Sagerunex encrypts collected system data then exfiltrates via existing command and control channels. |
| T1055.001 Dynamic-link Library Injection |
MalwareSagerunex | Sagerunex is designed to be dynamic link library (DLL) injected into an infected endpoint and executed directly in memory. |
| T1057 Process Discovery |
MalwareSagerunex | Sagerunex identifies the `explorer.exe` process on the executing system. |
| T1071.001 Web Protocols |
MalwareSagerunex | Sagerunex communicates via HTTPS, at times using a hard-coded User Agent of `Mozilla/5.0 (compatible; MSIE 7.0; Win32)`. |
| T1074.001 Local Data Staging |
MalwareSagerunex | Sagerunex gathers host information and stages it locally as a RAR file prior to exfiltration. Sagerunex stores logged data in an encrypted file located at `%TEMP%/TS_FB56.tmp` during execution. |
| T1082 System Information Discovery |
MalwareSagerunex | Sagerunex gathers information from the infected system such as hostname. |
| T1090 Proxy |
MalwareSagerunex | Sagerunex uses several proxy configuration settings to ensure connectivity. |
| T1102.002 Bidirectional Communication |
MalwareSagerunex | Sagerunex has used virtual private servers (VPS) for command and control traffic as well as third-party cloud services in more recent variants. |
| T1102.003 One-Way Communication |
MalwareSagerunex | Sagerunex has used web services such as Twitter for command and control purposes. |
| T1106 Native API |
MalwareSagerunex | Sagerunex calls the `WaitForSingleObject` API function as part of time-check logic. |
| T1134 Access Token Manipulation |
MalwareSagerunex | Sagerunex finds the `explorer.exe` process after execution and uses it to change the token of its executing thread. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSagerunex | Sagerunex uses a custom decryption routine to unpack itself during installation. |
| T1480 Execution Guardrails |
MalwareSagerunex | Sagerunex uses a "servicemain" function to verify its environment to ensure it can only be executed as a service, as well as the existence of a configuration file in a specified directory. |
| T1560.001 Archive via Utility |
MalwareSagerunex | Sagerunex has archived collected materials in RAR format. |
| T1573.002 Asymmetric Cryptography |
MalwareSagerunex | Sagerunex uses HTTPS for command and control communication. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.