Real-world descriptions of how a group, tool or campaign used a technique.
29 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareHavoc | Havoc can download files from the victim's computer. |
| T1016 System Network Configuration Discovery |
MalwareHavoc | Havoc has a module for network enumeration including determining IP addresses. |
| T1016.001 Internet Connection Discovery |
MalwareHavoc | The Havoc demon can check for a connection to the C2 server from the target machine. |
| T1018 Remote System Discovery |
MalwareHavoc | Havoc features a module capable of host enumeration. |
| T1027.010 Command Obfuscation |
MalwareHavoc | Havoc has utilized XOR encryption with the key “01-01-1900” to obfuscate command strings. |
| T1033 System Owner/User Discovery |
MalwareHavoc | Havoc can trigger exection of `whoami` on the target host to display the current user. |
| T1055.001 Dynamic-link Library Injection |
MalwareHavoc | Havoc has DLL spawn and injection modules. |
| T1055.002 Portable Executable Injection |
MalwareHavoc | Havoc has itself injected into `C:\\Windows\\System32\\Werfault.exe` on targeted systems. |
| T1057 Process Discovery |
MalwareHavoc | Havoc can enumerate processes on targeted hosts. |
| T1059.001 PowerShell |
MalwareHavoc | Havoc can facilitate the execution of PowerShell commands. |
| T1059.003 Windows Command Shell |
MalwareHavoc | Havoc can execute commands via `cmd.exe`. |
| T1071.001 Web Protocols |
MalwareHavoc | Havoc can use HTTP/S listeners to establish and maintain C2 communications. |
| T1071.002 File Transfer Protocols |
MalwareHavoc | Havoc can use an SMB listener for C2 communication. |
| T1082 System Information Discovery |
MalwareHavoc | Havoc can gather system information including hostname, domain, and OS details. |
| T1083 File and Directory Discovery |
MalwareHavoc | The Havoc interface can display a file explorer view of the compromised host. |
| T1087 Account Discovery |
MalwareHavoc | Havoc can identify privileged user accounts on infected systems. |
| T1090 Proxy |
MalwareHavoc | Havoc has the ability to route HTTP/S communications through designated proxies. |
| T1105 Ingress Tool Transfer |
MalwareHavoc | Havoc has the ability to upload files to infected systems. |
| T1106 Native API |
MalwareHavoc | Havoc can use `NtAllocateVirtualMemory` and `NtCreateThreadEx` to aid process injection. |
| T1113 Screen Capture |
MalwareHavoc | Havoc can capture screenshots. |
| T1134.001 Token Impersonation/Theft |
MalwareHavoc | Havoc has a module capable of token impersonation. |
| T1204.002 Malicious File |
MalwareHavoc | Havoc has been executed by victims through the use of targeted lures and crafted decoy documents. |
| T1204.004 Malicious Copy and Paste |
MalwareHavoc | The Havoc infection chain has been initiated via ClickFix lures in phishing emails. |
| T1497.003 Time Based Checks |
MalwareHavoc | The Havoc demon agent can be set to sleep for a specified time. |
| T1559 Inter-Process Communication |
MalwareHavoc | The Havoc SMB demon can use named pipes for communication through a parent demon. |
| T1566.002 Spearphishing Link |
MalwareHavoc | Havoc has been distributed through ClickFix phishing campaigns. |
| T1570 Lateral Tool Transfer |
MalwareHavoc | Havoc has the ability to copy files from one location to another. |
| T1573.001 Symmetric Cryptography |
MalwareHavoc | Havoc can send an AES encrypted check-in request to the C2 server. |
| T1574.001 DLL |
MalwareHavoc | Havoc has leveraged legitimate executables to side-load malicious payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.