Real-world descriptions of how a group, tool or campaign used a technique.
26 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwarePureCrypter | PureCrypter has used SmartAssembly and NET-Reactor for string encryption and control flow obfuscation. |
| T1027.016 Junk Code Insertion |
MalwarePureCrypter | PureCrypter can insert junk code to avoid detection. |
| T1033 System Owner/User Discovery |
MalwarePureCrypter | PureCrypter can retrieve the username from targeted machines. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePureCrypter | PureCrypter has used multiple file names to appear legitimate such as firefox\firefox.exe, Google\chrome.exe, and Taskmgr.exe. |
| T1036.008 Masquerade File Type |
MalwarePureCrypter | PureCrypter has used a .NET downloader named 63342221.BAT and has used .jpg, .png, and .log as false extensions for malicious files. |
| T1053.005 Scheduled Task |
MalwarePureCrypter | PureCrypter can maintain persistence with scheduled tasks. |
| T1055 Process Injection |
MalwarePureCrypter | PureCrypter can inject its final stage into another process on the targeted system. |
| T1057 Process Discovery |
MalwarePureCrypter | PureCrypter can enumerate processes on compromised hosts. |
| T1059.001 PowerShell |
MalwarePureCrypter | PureCrypter can execute PowerShell commands to exclude files from EDR and to self-delete. |
| T1070.004 File Deletion |
MalwarePureCrypter | PureCrypter can execute a PowerShell command to self-delete. |
| T1082 System Information Discovery |
MalwarePureCrypter | PureCrypter can enumerate a targeted system's SerialNumber and Version. |
| T1102 Web Service |
MalwarePureCrypter | PureCrypter can use Telegram or Discord to send infection status messages. |
| T1105 Ingress Tool Transfer |
MalwarePureCrypter | PureCrypter can download additional payloads for execution on the compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePureCrypter | PureCrypter can decrypt downloaded resources and parse internal files to determine its settings. |
| T1480 Execution Guardrails |
MalwarePureCrypter | PureCrypter code contains an ExclusionRegionNames option where it can compare the results of `kernel32!GetGeoInfo` with a list of regions. |
| T1480.002 Mutual Exclusion |
MalwarePureCrypter | PureCrypter code contains a global mutex. |
| T1518.001 Security Software Discovery |
MalwarePureCrypter | PureCrypter can identify installed antivirus solutions. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePureCrypter | PureCrypter can set multiple Registry Run keys to establish persistence. |
| T1564.003 Hidden Window |
MalwarePureCrypter | PureCrypter can set `ProcessWindowStyle.Hidden` to hide windows on victim machines. |
| T1573.001 Symmetric Cryptography |
MalwarePureCrypter | PureCrypter can use AES to encrypt system information sent to the C2. |
| T1573.002 Asymmetric Cryptography |
MalwarePureCrypter | PureCrypter can send a TLS 1.2 encrypted infection message via Discord webhook. |
| T1614 System Location Discovery |
MalwarePureCrypter | PureCrypter can use `kernel32!GetGeoInfo` to determine system location. |
| T1622 Debugger Evasion |
MalwarePureCrypter | PureCrypter has the ability to call `CheckRemoteDebuggerPresent`. |
| T1673 Virtual Machine Discovery |
MalwarePureCrypter | PureCrypter can identify virtual machines by querying the WMI object Win32_ComputerSystem for manufacturer and model and check it against the regular expression Microsoft|VMWare|Virtual. |
| T1678 Delay Execution |
MalwarePureCrypter | PureCrypter has the ability to delay for a specified number of seconds before execution. |
| T1685 Disable or Modify Tools |
MalwarePureCrypter | PureCrypter has executed `Set-MpPreference -ExclusionPath` to exclude files or folders from Windows Defender scans. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.