ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1245×

35 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareInvisibleFerret

InvisibleFerret has collected data utilizing a script that contained a list of excluded files and directory names and naming patterns of interest such as environment and configuration files, documents, spreadsheets, and other files that contained the words secret, wallet, private, and password.

T1016
System Network Configuration Discovery
MalwareInvisibleFerret

InvisibleFerret has collected the local IP address, and external IP.

T1027.013
Encrypted/Encoded File
MalwareInvisibleFerret

InvisibleFerret has utilized the XOR and Base64 encoding for each of its modules. InvisibleFerret has also obfuscated files with a combination of zlib, Base64 and reverse string order. InvisibleFerret has also utilized the XOR and Base64 encoding some of its Python scripts.

T1033
System Owner/User Discovery
MalwareInvisibleFerret

InvisibleFerret has identified the user’s UUID and username through the "pay" module.

T1041
Exfiltration Over C2 Channel
MalwareInvisibleFerret

InvisibleFerret has used HTTP communications to the “/Uploads” URI for file exfiltration.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareInvisibleFerret

InvisibleFerret has used FTP to exfiltrate files and directories using the command `ssh_upload` which contains with six subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr` and `sfind` that had varying functions. InvisibleFerret has exfiltrated stolen files and data to the C2 servers over ports 1224, 2245 and 8637.

T1056
Input Capture
MalwareInvisibleFerret

InvisibleFerret has collected mouse and keyboard events using “pyWinhook”.

T1056.001
Keylogging
MalwareInvisibleFerret

InvisibleFerret has conducted keylogging using the Python project “pyWinHook” and "Pyhook". InvisibleFerret has also captured keylogging thread checks for changes in an active window and key presses.

T1057
Process Discovery
MalwareInvisibleFerret

InvisibleFerret has the capability to query installed programs and running processes. InvisibleFerret has also identified running processes using the Python project “psutil”.

T1059.001
PowerShell
MalwareInvisibleFerret

InvisibleFerret has utilized a PowerShell script created in the victim’s home directory named “conf.ps1” that is used to modify configuration files for AnyDesk remote services.

T1059.006
Python
MalwareInvisibleFerret

InvisibleFerret is written in Python and has used Python scripts for execution.

T1071.001
Web Protocols
MalwareInvisibleFerret

InvisibleFerret has used HTTP for C2 communications.

T1074.001
Local Data Staging
MalwareInvisibleFerret

InvisibleFerret has staged data in consolidated folders prior to exfiltration.

T1082
System Information Discovery
MalwareInvisibleFerret

InvisibleFerret has collected OS type, hostname and system version through the "pay" module. InvisibleFerret has also queried the victim device using Python scripts to obtain the User and Hostname.

T1083
File and Directory Discovery
MalwareInvisibleFerret

InvisibleFerret has identified specific directories and files for exfiltration using the `ssh_upload` command which contains subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr`, `sfind`. InvisibleFerret also has the capability to scan and upload files of interest from multiple OS systems through the use of scripts that check file names, file extensions, and avoids certain path names. InvisibleFerret has utilized the `findstr` on Windows or the macOS `find` commands to search for files of interest.

T1087.001
Local Account
MalwareInvisibleFerret

InvisibleFerret has queried the victim device using Python scripts to obtain the User and Hostname.

T1095
Non-Application Layer Protocol
MalwareInvisibleFerret

InvisibleFerret has established a connection with the C2 server over TCP traffic. InvisibleFerret has also created a TCP reverse shell communicating via a socket connection over ports 1245, 80, 2245, 3001, and 5000.

T1105
Ingress Tool Transfer
MalwareInvisibleFerret

InvisibleFerret has downloaded “AnyDesk.exe” into the user’s home directory from the C2 server when checks for the service fail to identify its presence in the victim environment. InvisibleFerret has also been configured to download additional payloads using a command which calls to the /bow URI.

T1115
Clipboard Data
MalwareInvisibleFerret

InvisibleFerret has stolen data from the clipboard using the Python project “pyperclip”. InvisibleFerret has also captured clipboard contents during copy and paste operations.

T1140
Deobfuscate/Decode Files or Information
MalwareInvisibleFerret

InvisibleFerret has decoded XOR-encrypted and Base-64-encoded payloads prior to execution.

T1219
Remote Access Tools
MalwareInvisibleFerret

InvisibleFerret has utilized remote access software including AnyDesk client through the “adc” module. InvisibleFerret has also downloaded the AnyDesk client should it not already exist on the compromised host by searching for `C:/Program Files(x86)/AnyDesk/AnyDesk.exe`.

T1489
Service Stop
MalwareInvisibleFerret

InvisibleFerret has terminated Chrome and Brave browsers using the `taskkill` command on Windows and the `killall` command on other systems such as Linux and macOS. InvisibleFerret has also utilized it’s `ssh_kill` command to terminate Chrome and Brave browser processes.

T1518
Software Discovery
MalwareInvisibleFerret

InvisibleFerret has gathered installed programs and running processes.

T1543.001
Launch Agent
MalwareInvisibleFerret

InvisibleFerret has established persistence using LaunchAgents on macOS that run on Startup using a file named “com.avatar.update.wake.plist”.

T1547.001
Registry Run Keys / Startup Folder
MalwareInvisibleFerret

InvisibleFerret has established persistence within Windows devices by creating a .bat file “queue.bat” within the Startup folder to run a Python script.

T1547.013
XDG Autostart Entries
MalwareInvisibleFerret

InvisibleFerret has established persistence within GNOME-based Linux environments by placing entries within `.desktop` that run on Startup.

T1555.003
Credentials from Web Browsers
MalwareInvisibleFerret

InvisibleFerret has stolen login data, autofill data, cryptocurrency wallets, and payment information saved in web browsers such as Chrome, Brave, Opera, Yandex and Edge, to include versions affiliated with major operating systems on Windows, Linux, and macOS. InvisibleFerret has also leveraged the command `ssh_zcp` to copy browser data to include extensions and cryptocurrency wallet data.

T1555.005
Password Managers
MalwareInvisibleFerret

InvisibleFerret has utilized the command `ssh_zcp` to exfiltrate data from browser extensions and password managers via Telegram and FTP.

T1560.001
Archive via Utility
MalwareInvisibleFerret

InvisibleFerret has used 7zip, RAR and zip files to archive collected data for exfiltration.

T1564.003
Hidden Window
MalwareInvisibleFerret

InvisibleFerret has executed Python instances of the browser module “.n2/bow” utilizing the `CREATE_NO_WINDOW` process creation flag.

T1567
Exfiltration Over Web Service
MalwareInvisibleFerret

InvisibleFerret has leveraged Telegram chat to upload stolen data using the Telegram API with a bot token.

T1571
Non-Standard Port
MalwareInvisibleFerret

InvisibleFerret has been observed utilizing HTTP communications to the C2 server over ports 1224, 2245 and 8637.

T1614
System Location Discovery
MalwareInvisibleFerret

InvisibleFerret has collected the internal IP address, IP geolocation information of the infected host and sends the data to a C2 server. InvisibleFerret has also leveraged the “pay” module to obtain region name, country, city, zip code, ISP, latitude and longitude using “http://ip-api.com/json”.

T1657
Financial Theft
MalwareInvisibleFerret

InvisibleFerret has searched the victim device credentials and files commonly associated with cryptocurrency wallets.

T1679
Selective Exclusion
MalwareInvisibleFerret

InvisibleFerret has the capability to scan for file names, file extensions, and avoids pre-designated path names and file types.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.