Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
MalwareBOOKWORM | BOOKWORM has modified HTTP POST requests to resemble legitimate communications. |
| T1027 Obfuscated Files or Information |
MalwareBOOKWORM | BOOKWORM has been delivered using self-extracting RAR archives. |
| T1027.013 Encrypted/Encoded File |
MalwareBOOKWORM | BOOKWORM has utilized Base64 encoding to obfuscate its payload. |
| T1033 System Owner/User Discovery |
MalwareBOOKWORM | BOOKWORM has obtained the username from an infected host. |
| T1036.004 Masquerade Task or Service |
MalwareBOOKWORM | BOOKWORM has created services that attempt to resemble legitimate services to include a service named `Microsoft Windows DeviceSync Service`. |
| T1056.001 Keylogging |
MalwareBOOKWORM | BOOKWORM has used its KBLogger.dll module to capture keystrokes and stored them in a folder. |
| T1070.006 Timestomp |
MalwareBOOKWORM | BOOKWORM has modified file timestamps from the export address table (EAT) to make it difficult to discern when the module was created. |
| T1071.001 Web Protocols |
MalwareBOOKWORM | BOOKWORM has communicated with its C2 via HTTP POST requests. |
| T1106 Native API |
MalwareBOOKWORM | BOOKWORM has used various Windows API calls during execution and defense evasion. BOOKWORM has created a buffer on the heap using `HeapCreate` and `HeapAlloc` which allows for copying of shell code and then execution on the heap is initiated through callback function of legitimate API functions such as `EnumChildWindows` or `EnumSystemLanguageGroupsA`. |
| T1112 Modify Registry |
MalwareBOOKWORM | BOOKWORM has modified Registry key values as part of its created service `DeviceSync`. |
| T1115 Clipboard Data |
MalwareBOOKWORM | BOOKWORM has used its KBLogger.dll module to steal data saved to the clipboard. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBOOKWORM | BOOKWORM has decoded its Base64 encoded payload prior to execution. BOOKWORM has also encrypted files with RC4 and has decrypted its payload prior to execution. |
| T1543.003 Windows Service |
MalwareBOOKWORM | BOOKWORM has created a service named `Microsoft Windows DeviceSync Service` at `HKLM\SYSTEM\CurrentControlSet\Services\DeviceSync\` to trigger execution when the system starts and to maintain persistence. |
| T1553.002 Code Signing |
MalwareBOOKWORM | BOOKWORM has used valid legitimate digital signatures and certificates to evade detection. |
| T1564.003 Hidden Window |
MalwareBOOKWORM | BOOKWORM has created a hidden window when conducting key logging and clipboard theft through its KBLogger.dll module. |
| T1573.001 Symmetric Cryptography |
MalwareBOOKWORM | BOOKWORM has used encryption and compression algorithms to obfuscate the traffic between the system and C2 server, methods observed included RC4, AES, XOR with 0x5a, and LZO. |
| T1574.001 DLL |
MalwareBOOKWORM | BOOKWORM has used DLL side-loading to execute the malicious payload. BOOKWORM has also side-loaded DLL components into a legitimate process, including Microsoft Malware Protection `MsMpEng.exe` and Kaspersky Anti-Virus `ushata.exe`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.