Real-world descriptions of how a group, tool or campaign used a technique.
35 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
MalwarePUBLOAD | PUBLOAD has modified HTTP POST requests to resemble legitimate communications. PUBLOAD used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. PUBLOAD has utilized FakeTLS headers with the bytes 17 03 03. |
| T1007 System Service Discovery |
MalwarePUBLOAD | PUBLOAD has leveraged `tasklist` to gather running services on victim host. |
| T1012 Query Registry |
MalwarePUBLOAD | PUBLOAD has queried Registry values to identify software using `reg query`. |
| T1016 System Network Configuration Discovery |
MalwarePUBLOAD | PUBLOAD has obtained information about local networks through the `ipconfig /all` command. |
| T1016.001 Internet Connection Discovery |
MalwarePUBLOAD | PUBLOAD has identified internet connectivity details through commands such as `tracert -h 5 -4 google.com` and `curl http://myip.ipip.net`. |
| T1016.002 Wi-Fi Discovery |
MalwarePUBLOAD | PUBLOAD has collected information on Wi-Fi networks from victim hosts leveraging `netsh wlan show profiles`, `netsh wlan show interface`, and `netsh wlan show`. |
| T1027 Obfuscated Files or Information |
MalwarePUBLOAD | PUBLOAD has obfuscated DLL names using the ror13AddHash32 algorithm. |
| T1027.015 Compression |
MalwarePUBLOAD | PUBLOAD has been delivered as compressed files within ZIP files to victims. |
| T1033 System Owner/User Discovery |
MalwarePUBLOAD | PUBLOAD has obtained the username from an infected host. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePUBLOAD | PUBLOAD has renamed malicious files to mimic legitimate file names such as adobe_wf.exe. |
| T1047 Windows Management Instrumentation |
MalwarePUBLOAD | PUBLOAD has used `wmic` to gather information from the victim device. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwarePUBLOAD | PUBLOAD has leveraged `curl` for data exfiltration over FTP by uploading RAR archives containing targeted files (.doc, .docx, .xls, .xlsx, .pdf, .ppt, .pptx) to an adversary-owned FTP site. |
| T1049 System Network Connections Discovery |
MalwarePUBLOAD | PUBLOAD has used several commands executed in sequence via `cmd` in a short interval to gather information on network connections. |
| T1053.005 Scheduled Task |
MalwarePUBLOAD | PUBLOAD has created scheduled tasks to maintain persistence with the command `schtasks.exe /F /Create /TN Microsoft_Licensing /sc minute /MO 1 /TR C:\\Users\\Public\\Libraries\...` |
| T1057 Process Discovery |
MalwarePUBLOAD | PUBLOAD has used `tasklist` to gather running processes on victim host. PUBLOAD has also leveraged the `OpenEventA` Windows API function to check whether the same process was already running. |
| T1059.003 Windows Command Shell |
MalwarePUBLOAD | PUBLOAD has used several commands executed in sequence via `cmd`. |
| T1071.001 Web Protocols |
MalwarePUBLOAD | PUBLOAD has communicated via `curl` over HTTP to identify device IP data. PUBLOAD has also utilized HTTP for a command-and-control protocol through HTTP POST. PUBLOAD has also leveraged HTTPS for C2. |
| T1071.002 File Transfer Protocols |
MalwarePUBLOAD | PUBLOAD has used `curl` for data exfiltration over FTP. |
| T1082 System Information Discovery |
MalwarePUBLOAD | PUBLOAD has collected and sent system information including volume serial number, computer name, and system uptime to designated C2. PUBLOAD has also used several commands executed in sequence via `cmd` in a short interval to gather system information about the infected host including `systeminfo`. PUBLOAD has decrypted shellcode that collects the computer name. |
| T1105 Ingress Tool Transfer |
MalwarePUBLOAD | PUBLOAD has acted as a stager that can download the next-stage payload from its C2 server. PUBLOAD has also delivered FDMTP as a secondary control tool and PTSOCKET for exfiltration to some infected systems. |
| T1106 Native API |
MalwarePUBLOAD | PUBLOAD has used various Windows API calls during execution, when establishing persistence and defense evasion. PUBLOAD stager leveraged Windows API functions with callback including `GrayStringW`, `EnumDateFormatsA`, and `LineDDA` to bypass anti-virus monitoring. PUBLOAD has also utilized other native windows API functions with callback functions such as `EnumChildWindows` and `EnumSystemLanguageGroupsA`. |
| T1124 System Time Discovery |
MalwarePUBLOAD | PUBLOAD has collected the machine’s tick count through the use of `GetTickCount`. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePUBLOAD | PUBLOAD has decoded its payload prior to execution. |
| T1205 Traffic Signaling |
MalwarePUBLOAD | PUBLOAD has utilized a magic value in C2 communications and only executes in memory when response packets match specific values of 17 03 03. PUBLOAD has also used magic bytes consisting of 46 77 4d. |
| T1480.001 Environmental Keying |
MalwarePUBLOAD | PUBLOAD has utilized environmental keying in the payload to include the victim volume serial number, computer name, username, and machine’s tick count. |
| T1518 Software Discovery |
MalwarePUBLOAD | PUBLOAD has used several commands executed in sequence via `cmd` in a short interval to gather software versions including querying Registry keys. |
| T1518.001 Security Software Discovery |
MalwarePUBLOAD | PUBLOAD has identified AV products on an infected host using the following command: `WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePUBLOAD | PUBLOAD has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1553.002 Code Signing |
MalwarePUBLOAD | PUBLOAD has used valid legitimate digital signatures and certificates to evade detection. |
| T1560.001 Archive via Utility |
MalwarePUBLOAD | PUBLOAD has used utilities such as `WinRAR` to archive data prior to exfiltration. |
| T1573.001 Symmetric Cryptography |
MalwarePUBLOAD | PUBLOAD has used RC4 encryption in C2 communications. |
| T1574.001 DLL |
MalwarePUBLOAD | PUBLOAD has abused legitimate executables to side-load malicious DLLs. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDACSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Networks, Unit 42PaloAlto MUSTANG PANDA PUBLOAD MARCH 2024 |
| T1614.001 System Language Discovery |
MalwarePUBLOAD | PUBLOAD has checked supported languages on the compromised system. |
| T1622 Debugger Evasion |
MalwarePUBLOAD | PUBLOAD has embedded debug strings with messages to distract analysts. PUBLOAD has leveraged `OutputDebugStringW` and `OutputDebugStringA` functions. |
| T1680 Local Storage Discovery |
MalwarePUBLOAD | PUBLOAD has leveraged `wmic logicaldisk get` to map local network drives. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.