ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1226×

17 examples

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
MalwareBOOKWORM

BOOKWORM has modified HTTP POST requests to resemble legitimate communications.

T1027
Obfuscated Files or Information
MalwareBOOKWORM

BOOKWORM has been delivered using self-extracting RAR archives.

T1027.013
Encrypted/Encoded File
MalwareBOOKWORM

BOOKWORM has utilized Base64 encoding to obfuscate its payload.

T1033
System Owner/User Discovery
MalwareBOOKWORM

BOOKWORM has obtained the username from an infected host.

T1036.004
Masquerade Task or Service
MalwareBOOKWORM

BOOKWORM has created services that attempt to resemble legitimate services to include a service named `Microsoft Windows DeviceSync Service`.

T1056.001
Keylogging
MalwareBOOKWORM

BOOKWORM has used its KBLogger.dll module to capture keystrokes and stored them in a folder.

T1070.006
Timestomp
MalwareBOOKWORM

BOOKWORM has modified file timestamps from the export address table (EAT) to make it difficult to discern when the module was created.

T1071.001
Web Protocols
MalwareBOOKWORM

BOOKWORM has communicated with its C2 via HTTP POST requests.

T1106
Native API
MalwareBOOKWORM

BOOKWORM has used various Windows API calls during execution and defense evasion. BOOKWORM has created a buffer on the heap using `HeapCreate` and `HeapAlloc` which allows for copying of shell code and then execution on the heap is initiated through callback function of legitimate API functions such as `EnumChildWindows` or `EnumSystemLanguageGroupsA`.

T1112
Modify Registry
MalwareBOOKWORM

BOOKWORM has modified Registry key values as part of its created service `DeviceSync`.

T1115
Clipboard Data
MalwareBOOKWORM

BOOKWORM has used its KBLogger.dll module to steal data saved to the clipboard.

T1140
Deobfuscate/Decode Files or Information
MalwareBOOKWORM

BOOKWORM has decoded its Base64 encoded payload prior to execution. BOOKWORM has also encrypted files with RC4 and has decrypted its payload prior to execution.

T1543.003
Windows Service
MalwareBOOKWORM

BOOKWORM has created a service named `Microsoft Windows DeviceSync Service` at `HKLM\SYSTEM\CurrentControlSet\Services\DeviceSync\` to trigger execution when the system starts and to maintain persistence.

T1553.002
Code Signing
MalwareBOOKWORM

BOOKWORM has used valid legitimate digital signatures and certificates to evade detection.

T1564.003
Hidden Window
MalwareBOOKWORM

BOOKWORM has created a hidden window when conducting key logging and clipboard theft through its KBLogger.dll module.

T1573.001
Symmetric Cryptography
MalwareBOOKWORM

BOOKWORM has used encryption and compression algorithms to obfuscate the traffic between the system and C2 server, methods observed included RC4, AES, XOR with 0x5a, and LZO.

T1574.001
DLL
MalwareBOOKWORM

BOOKWORM has used DLL side-loading to execute the malicious payload. BOOKWORM has also side-loaded DLL components into a legitimate process, including Microsoft Malware Protection `MsMpEng.exe` and Kaspersky Anti-Virus `ushata.exe`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.