Real-world descriptions of how a group, tool or campaign used a technique.
22 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has leveraged an encoded list of services that it designates for termination. |
| T1027.013 Encrypted/Encoded File |
MalwareMedusa Ransomware | Medusa Ransomware has utilized XOR encrypted strings. |
| T1057 Process Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has utilized an encoded list of the processes that it detects and terminates. |
| T1059.001 PowerShell |
MalwareMedusa Ransomware | Medusa Ransomware has launched PowerShell scripts for execution and defense evasion. |
| T1059.003 Windows Command Shell |
MalwareMedusa Ransomware | Medusa Ransomware has used `cmd.exe` to execute command on an infected host. |
| T1070.004 File Deletion |
MalwareMedusa Ransomware | Medusa Ransomware has the ability to delete itself after execution. Medusa Ransomware also has the ability to delete itself after execution through the command `cmd /c ping localhost -n 3 > nul & del`. |
| T1082 System Information Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has collected data from the SMBIOS firmware table using `GetSystemFirmwareTable`. |
| T1083 File and Directory Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has searched for files within the victim environment for encryption and exfiltration. Medusa Ransomware has also identified files associated with remote management services. |
| T1106 Native API |
MalwareMedusa Ransomware | Medusa Ransomware has leveraged Windows Native API functions to execute payloads. |
| T1124 System Time Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has discovered device uptime through `GetTickCount()`. |
| T1135 Network Share Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has identified networked drives. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMedusa Ransomware | Medusa Ransomware has decoded XOR encrypted strings prior to execution in memory. |
| T1486 Data Encrypted for Impact |
MalwareMedusa Ransomware | Medusa Ransomware has encrypted files using AES-256 encryption, which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.” |
| T1489 Service Stop |
MalwareMedusa Ransomware | Medusa Ransomware has the capability to terminate services related to backups, security, databases, communication, filesharing and websites. Medusa Ransomware has also utilized the `taskkill /F /IM <process> /T` command to stop targeted processes and `net stop <process>` command to stop designated services. |
| T1490 Inhibit System Recovery |
MalwareMedusa Ransomware | Medusa Ransomware has deleted recovery files such as shadow copies using `vssadmin.exe`. |
| T1518.001 Security Software Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has the capability to detect security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables. |
| T1543.003 Windows Service |
MalwareMedusa Ransomware | Medusa Ransomware has created a new PowerShell process using the `CreateProcessA` API. |
| T1559 Inter-Process Communication |
MalwareMedusa Ransomware | Medusa Ransomware has leveraged the `CreatePipe` API to enable inter-process communication. |
| T1564.003 Hidden Window |
MalwareMedusa Ransomware | Medusa Ransomware has utilized the `ShowWindow` function to hide current window. |
| T1679 Selective Exclusion |
MalwareMedusa Ransomware | Medusa Ransomware has avoided specified files, file extensions and folders to ensure successful execution of the payload and continued operations of the impacted device. |
| T1680 Local Storage Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has enumerated logical drives on infected hosts. |
| T1685 Disable or Modify Tools |
MalwareMedusa Ransomware | Medusa Ransomware has terminated antivirus services utilizing the gaze.exe executable. Medusa Ransomware has also terminated antivirus services utilizing PowerShell scripts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.