ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1239×

43 examples

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
MalwareTONESHELL

TONESHELL used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. TONESHELL variants have utilized FakeTLS headers with the bytes `0x17 0x03 0x03` to represent TLSv1.2 and `0x17 0x03 0x04` for TLSv1.3.

T1010
Application Window Discovery
MalwareTONESHELL

TONESHELL has used `GetForegroundWindow` to detect virtualization or sandboxes by calling the API twice and comparing each window handle.

T1027.001
Binary Padding
MalwareTONESHELL

TONESHELL has used randomized padding to obfuscate payloads.

T1027.007
Dynamic API Resolution
MalwareTONESHELL

TONESHELL has utilized a modified DJB2 algorithm to resolve APIs.

T1027.012
LNK Icon Smuggling
MalwareTONESHELL

TONESHELL has been initiated using LNK files that were programmed to display a PDF icon to entice the victim to click on the file to execute an office.exe binary.

T1033
System Owner/User Discovery
MalwareTONESHELL

TONESHELL has obtained the username from an infected host.

T1036.004
Masquerade Task or Service
MalwareTONESHELL

TONESHELL has masqueraded as the legitimate Windows utility service DISMsrv (Dism Images Servicing Utility Service).

T1036.005
Match Legitimate Resource Name or Location
MalwareTONESHELL

TONESHELL has renamed malicious files to mimic legitimate file names and file extensions. TONESHELL has also masqueraded as legitimate file names to include LogMeIn.dll.

T1047
Windows Management Instrumentation
MalwareTONESHELL

TONESHELL has used WMI queries to gather information from the system.

T1053.005
Scheduled Task
MalwareTONESHELL

TONESHELL has created scheduled tasks to maintain persistence.

T1055.001
Dynamic-link Library Injection
MalwareTONESHELL

TONESHELL has used DLL injection to execute payloads received from the C2 server.

T1056.001
Keylogging
MalwareTONESHELL

TONESHELL has capabilities to conduct keylogging.

T1057
Process Discovery
MalwareTONESHELL

TONESHELL has checked the process name and process path to ensure it matches the expected one prior to triggering a custom exception handler. TONESHELL has also searched for running antivirus processes to include ESET’s antivirus associated executables ekrn.exe and egui.exe.

T1059.003
Windows Command Shell
MalwareTONESHELL

TONESHELL has created a reverse shell using `cmd.exe`.

T1070.004
File Deletion
MalwareTONESHELL

TONESHELL has deleted payload files received from the C2 server.

T1071.001
Web Protocols
MalwareTONESHELL

TONESHELL has utilized HTTP for a C2 protocol through HTTP POST. TONESHELL has also utilized HTTPS for C2.

T1082
System Information Discovery
MalwareTONESHELL

TONESHELL has the ability to retrieve the name of the infected machine.

T1087
Account Discovery
MalwareTONESHELL

TONESHELL included functionality to retrieve a list of user accounts.

T1095
Non-Application Layer Protocol
MalwareTONESHELL

TONESHELL has utilized TCP-based reverse shells.

T1105
Ingress Tool Transfer
MalwareTONESHELL

TONESHELL has the ability to download additional files to the victim device.

T1106
Native API
MalwareTONESHELL

TONESHELL has utilized Native Windows API functions such as `WriteProcessMemory` and `CreateRemoteThreadEx`. TONESHELL has also utilized Windows API functions for creating seed values including `CoCreateGuid` and `GetTickCount`. TONESHELL has leveraged the legitimate API function `EnumSystemLocalesA` to run its shellcode through the callback function.

T1113
Screen Capture
MalwareTONESHELL

TONESHELL has conducted screen capturing.

T1132.002
Non-Standard Encoding
MalwareTONESHELL

TONESHELL has encoded a payload with a random 32-byte key using XOR. TONESHELL has also encoded payloads with a 256-byte key using XOR.

T1134.002
Create Process with Token
MalwareTONESHELL

TONESHELL included functionality to create sub-processes with a specific user’s token.

T1140
Deobfuscate/Decode Files or Information
MalwareTONESHELL

TONESHELL has decoded its payload prior to execution.

T1205
Traffic Signaling
MalwareTONESHELL

TONESHELL has utilized a magic value in C2 communications and only executes in memory when response packets match specific values.

T1218.010
Regsvr32
MalwareTONESHELL

TONESHELL has used regsvr32.exe to execute the windows `DLLRegisterServer` function.

T1218.013
Mavinject
MalwareTONESHELL

TONESHELL has injected its malicious payload into a running process through Windows utility Microsoft Application Virtualization Injector `MAVInject.exe`.

T1480
Execution Guardrails
MalwareTONESHELL

TONESHELL has an exception handler that executes when ESET antivirus applications `ekrn.exe` and `egui.exe` are not found and directly injects its code into waitfor.exe using Native Windows API including `WriteProcessMemory` and `CreateRemoteThreadEx`.

T1480.001
Environmental Keying
MalwareTONESHELL

TONESHELL has generated unique GUIDs to identify victim devices. TONESHELL has leveraged environmental keying in payload delivery using the victim computer name and other configuration values. TONESHELL has also tracked IDs associated with reverse shell subprocesses to manage interactions and terminations from C2.

T1480.002
Mutual Exclusion
MalwareTONESHELL

TONESHELL has created a mutex to avoid duplicate execution.

T1497.002
User Activity Based Checks
MalwareTONESHELL

TONESHELL has leveraged `GetForegroundWindow` to detect virtualization or sandboxes by calling the API twice and comparing each window handle.

T1518.001
Security Software Discovery
MalwareTONESHELL

TONESHELL has checked for the presence of ESET antivirus applications `ekrn.exe` and `egui.exe`.

T1543.003
Windows Service
MalwareTONESHELL

TONESHELL has created a malicious service DISMsrv to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareTONESHELL

TONESHELL has added Registry Run keys to achieve persistence.

T1553.002
Code Signing
MalwareTONESHELL

TONESHELL has used valid legitimate digital signatures and certificates to evade detection.

T1559
Inter-Process Communication
MalwareTONESHELL

TONESHELL has facilitated inter-process communication between DLL components via the use of pipes. TONESHELL has also created a reverse shell using two anonymous pipes to write data to stdin and read data from stdout and stderr.

T1560.001
Archive via Utility
MalwareTONESHELL

TONESHELL used WinRAR rar.exe to archive files for exfiltration. TONESHELL has also utilized a unique 13-character password consisting of upper lower case and digits to protect RAR archives.

T1573.001
Symmetric Cryptography
MalwareTONESHELL

TONESHELL has used RC4 encryption in C2 communications. TONESHELL variants used a randomly generated variable length (0x20 - 0x200 bytes) rolling XOR key to encrypt and decrypt network packets.

T1574.001
DLL
MalwareTONESHELL

TONESHELL has abused legitimate executables to side-load malicious DLLs. TONESHELL has also been loaded via DLL side-loading, using legitimate, signed executables to include: FastVD.exe, Bandizip.exe and gpgconf.exe.

T1622
Debugger Evasion
MalwareTONESHELL

TONESHELL has leveraged custom exception handlers to hide code flow and stop execution of a debugger.

T1678
Delay Execution
MalwareTONESHELL

TONESHELL has the ability to pause operations for a specified duration prior to follow-on execution of activities.

T1680
Local Storage Discovery
MalwareTONESHELL

TONESHELL has retrieved the disk serial number of the device using WMI query `SELECT volumeserialnumber FROM win32_logicaldisk where Name =’C:` to identify the victim machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.