ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S9001×

21 examples

TechniqueUsed byProcedure example
T1001
Data Obfuscation
MalwareSystemBC

SystemBC has encoded with XOR and encrypted with RC4 its beacon.

T1053.005
Scheduled Task
MalwareSystemBC

SystemBC has executed a copy of itself as a scheduled task with the `start` command. The copy of SystemBC has random file and directory names within the ProgramData directory.

T1057
Process Discovery
MalwareSystemBC

SystemBC has the ability to enumerate running processes.

T1059.001
PowerShell
MalwareSystemBC

SystemBC has used hidden scheduled tasks to execute PowerShell commands by adding the following: `-WindowStyle Hidden -ep bypass -file `.

T1059.003
Windows Command Shell
MalwareSystemBC

SystemBC has used `cmd.exe` to execute VBS scripts, BAT scripts and CMD scripts.

T1059.005
Visual Basic
MalwareSystemBC

SystemBC has leveraged VBScript to execute malicious code.

T1071.004
DNS
MalwareSystemBC

SystemBC has used DNS servers to resolve .bit domains to C2 infrastructure.

T1082
System Information Discovery
MalwareSystemBC

SystemBC has collected username , build number and serial number, then sent the information to the C2 server. SystemBC has also gathered device name, operating system, and processor type.

T1087.001
Local Account
MalwareSystemBC

SystemBC has collected the Windows account username on the victim machine.

T1090.003
Multi-hop Proxy
MalwareSystemBC

SystemBC has used multiple proxy layers, such as SOCKS5 and Tor, for C2 communication. SystemBC has also leveraged Tor for encrypting and concealing C2 traffic. The server component of SystemBC has used SOCKS5 for C2 communication.

T1095
Non-Application Layer Protocol
MalwareSystemBC

SystemBC has used raw TCP on non-standard ports, such as 4044, for C2 communications and for HTTP communications, which include downloading binaries.

T1105
Ingress Tool Transfer
MalwareSystemBC

SystemBC has downloaded additional files for execution on the victim’s machine. The server component of SystemBC has the ability to send additional files to victim machines.

T1106
Native API
MalwareSystemBC

SystemBC has utilized native Windows API functions such as `EnumWindows`and `GetVolumeInformationA` during discovery activities.

T1124
System Time Discovery
MalwareSystemBC

SystemBC has leveraged the time of the device to create a text file with a filename that uses the function of `uniqid(time()).‘.txt`, consisting of the 10 character UNIX timestamp and 13 hexadecimal characters.

T1140
Deobfuscate/Decode Files or Information
MalwareSystemBC

SystemBC has the ability to decrypt RC4 encrypted packets and to decode obfuscated data before C2 communication. Additionally, SystemBC has decrypted its config file that was encoded with XOR and a hardcoded 40-byte key.

T1480
Execution Guardrails
MalwareSystemBC

SystemBC has checked if the last characters of DNS server names end in .bit before initializing C2 communication. SystemBC has identified running processes associated with anti-virus solutions to include `a2guard.exe` to determine whether it executes or not.

T1564.003
Hidden Window
MalwareSystemBC

SystemBC has utilized the `-WindowStyle Hidden -ep bypass -file `to conceal PowerShell windows.

T1571
Non-Standard Port
MalwareSystemBC

The server component of SystemBC has used various TCP ports for C2 communication.

T1573.001
Symmetric Cryptography
MalwareSystemBC

SystemBC has encrypted its C2 traffic with RC4.

T1620
Reflective Code Loading
MalwareSystemBC

SystemBC has downloaded a text file into memory and set the area of memory via the VirtualProtect call. Then, SystemBC has executed the file via the CreateThread call.

T1678
Delay Execution
MalwareSystemBC

SystemBC has leveraged the Sleep functions before and after commands to ensure execution using the hexadecimal values within commands to include `Sleep(0x2710u)` that waits 10 seconds, and `Sleep(0xEA60u)` for 60 seconds.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.