ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1244×

22 examples

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareMedusa Ransomware

Medusa Ransomware has leveraged an encoded list of services that it designates for termination.

T1027.013
Encrypted/Encoded File
MalwareMedusa Ransomware

Medusa Ransomware has utilized XOR encrypted strings.

T1057
Process Discovery
MalwareMedusa Ransomware

Medusa Ransomware has utilized an encoded list of the processes that it detects and terminates.

T1059.001
PowerShell
MalwareMedusa Ransomware

Medusa Ransomware has launched PowerShell scripts for execution and defense evasion.

T1059.003
Windows Command Shell
MalwareMedusa Ransomware

Medusa Ransomware has used `cmd.exe` to execute command on an infected host.

T1070.004
File Deletion
MalwareMedusa Ransomware

Medusa Ransomware has the ability to delete itself after execution. Medusa Ransomware also has the ability to delete itself after execution through the command `cmd /c ping localhost -n 3 > nul & del`.

T1082
System Information Discovery
MalwareMedusa Ransomware

Medusa Ransomware has collected data from the SMBIOS firmware table using `GetSystemFirmwareTable`.

T1083
File and Directory Discovery
MalwareMedusa Ransomware

Medusa Ransomware has searched for files within the victim environment for encryption and exfiltration. Medusa Ransomware has also identified files associated with remote management services.

T1106
Native API
MalwareMedusa Ransomware

Medusa Ransomware has leveraged Windows Native API functions to execute payloads.

T1124
System Time Discovery
MalwareMedusa Ransomware

Medusa Ransomware has discovered device uptime through `GetTickCount()`.

T1135
Network Share Discovery
MalwareMedusa Ransomware

Medusa Ransomware has identified networked drives.

T1140
Deobfuscate/Decode Files or Information
MalwareMedusa Ransomware

Medusa Ransomware has decoded XOR encrypted strings prior to execution in memory.

T1486
Data Encrypted for Impact
MalwareMedusa Ransomware

Medusa Ransomware has encrypted files using AES-256 encryption, which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.”

T1489
Service Stop
MalwareMedusa Ransomware

Medusa Ransomware has the capability to terminate services related to backups, security, databases, communication, filesharing and websites. Medusa Ransomware has also utilized the `taskkill /F /IM <process> /T` command to stop targeted processes and `net stop <process>` command to stop designated services.

T1490
Inhibit System Recovery
MalwareMedusa Ransomware

Medusa Ransomware has deleted recovery files such as shadow copies using `vssadmin.exe`.

T1518.001
Security Software Discovery
MalwareMedusa Ransomware

Medusa Ransomware has the capability to detect security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables.

T1543.003
Windows Service
MalwareMedusa Ransomware

Medusa Ransomware has created a new PowerShell process using the `CreateProcessA` API.

T1559
Inter-Process Communication
MalwareMedusa Ransomware

Medusa Ransomware has leveraged the `CreatePipe` API to enable inter-process communication.

T1564.003
Hidden Window
MalwareMedusa Ransomware

Medusa Ransomware has utilized the `ShowWindow` function to hide current window.

T1679
Selective Exclusion
MalwareMedusa Ransomware

Medusa Ransomware has avoided specified files, file extensions and folders to ensure successful execution of the payload and continued operations of the impacted device.

T1680
Local Storage Discovery
MalwareMedusa Ransomware

Medusa Ransomware has enumerated logical drives on infected hosts.

T1685
Disable or Modify Tools
MalwareMedusa Ransomware

Medusa Ransomware has terminated antivirus services utilizing the gaze.exe executable. Medusa Ransomware has also terminated antivirus services utilizing PowerShell scripts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.