ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S9019×

26 examples

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwarePureCrypter

PureCrypter has used SmartAssembly and NET-Reactor for string encryption and control flow obfuscation.

T1027.016
Junk Code Insertion
MalwarePureCrypter

PureCrypter can insert junk code to avoid detection.

T1033
System Owner/User Discovery
MalwarePureCrypter

PureCrypter can retrieve the username from targeted machines.

T1036.005
Match Legitimate Resource Name or Location
MalwarePureCrypter

PureCrypter has used multiple file names to appear legitimate such as firefox\firefox.exe, Google\chrome.exe, and Taskmgr.exe.

T1036.008
Masquerade File Type
MalwarePureCrypter

PureCrypter has used a .NET downloader named 63342221.BAT and has used .jpg, .png, and .log as false extensions for malicious files.

T1053.005
Scheduled Task
MalwarePureCrypter

PureCrypter can maintain persistence with scheduled tasks.

T1055
Process Injection
MalwarePureCrypter

PureCrypter can inject its final stage into another process on the targeted system.

T1057
Process Discovery
MalwarePureCrypter

PureCrypter can enumerate processes on compromised hosts.

T1059.001
PowerShell
MalwarePureCrypter

PureCrypter can execute PowerShell commands to exclude files from EDR and to self-delete.

T1070.004
File Deletion
MalwarePureCrypter

PureCrypter can execute a PowerShell command to self-delete.

T1082
System Information Discovery
MalwarePureCrypter

PureCrypter can enumerate a targeted system's SerialNumber and Version.

T1102
Web Service
MalwarePureCrypter

PureCrypter can use Telegram or Discord to send infection status messages.

T1105
Ingress Tool Transfer
MalwarePureCrypter

PureCrypter can download additional payloads for execution on the compromised host.

T1140
Deobfuscate/Decode Files or Information
MalwarePureCrypter

PureCrypter can decrypt downloaded resources and parse internal files to determine its settings.

T1480
Execution Guardrails
MalwarePureCrypter

PureCrypter code contains an ExclusionRegionNames option where it can compare the results of `kernel32!GetGeoInfo` with a list of regions.

T1480.002
Mutual Exclusion
MalwarePureCrypter

PureCrypter code contains a global mutex.

T1518.001
Security Software Discovery
MalwarePureCrypter

PureCrypter can identify installed antivirus solutions.

T1547.001
Registry Run Keys / Startup Folder
MalwarePureCrypter

PureCrypter can set multiple Registry Run keys to establish persistence.

T1564.003
Hidden Window
MalwarePureCrypter

PureCrypter can set `ProcessWindowStyle.Hidden` to hide windows on victim machines.

T1573.001
Symmetric Cryptography
MalwarePureCrypter

PureCrypter can use AES to encrypt system information sent to the C2.

T1573.002
Asymmetric Cryptography
MalwarePureCrypter

PureCrypter can send a TLS 1.2 encrypted infection message via Discord webhook.

T1614
System Location Discovery
MalwarePureCrypter

PureCrypter can use `kernel32!GetGeoInfo` to determine system location.

T1622
Debugger Evasion
MalwarePureCrypter

PureCrypter has the ability to call `CheckRemoteDebuggerPresent`.

T1673
Virtual Machine Discovery
MalwarePureCrypter

PureCrypter can identify virtual machines by querying the WMI object Win32_ComputerSystem for manufacturer and model and check it against the regular expression Microsoft|VMWare|Virtual.

T1678
Delay Execution
MalwarePureCrypter

PureCrypter has the ability to delay for a specified number of seconds before execution.

T1685
Disable or Modify Tools
MalwarePureCrypter

PureCrypter has executed `Set-MpPreference -ExclusionPath` to exclude files or folders from Windows Defender scans.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.