ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S9020×

32 examples

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwareLODEINFO

LODEINFO can append C2 communication with randomly generated junk data.

T1005
Data from Local System
MalwareLODEINFO

LODEINFO can upload files from infected hosts to the C2.

T1016
System Network Configuration Discovery
MalwareLODEINFO

LODEINFO can enumerate the MAC address of the compromised host.

T1018
Remote System Discovery
MalwareLODEINFO

LODEINFO can run `net view` and `net view /domain` for network discovery.

T1027
Obfuscated Files or Information
MalwareLODEINFO

LODEINFO has used control flow flattening to obfuscate code.

T1027.007
Dynamic API Resolution
MalwareLODEINFO

LODEINFO can use a hashing algorithm to dynamically resolve API function addresses.

T1027.013
Encrypted/Encoded File
MalwareLODEINFO

The LODEINFO loader module contains XOR-encrypted shellcode.

T1027.015
Compression
MalwareLODEINFO

LODEINFO components have been compressed with zip for delivery.

T1027.016
Junk Code Insertion
MalwareLODEINFO

LODEINFO has inserted junk code to obstruct code analysis.

T1033
System Owner/User Discovery
MalwareLODEINFO

LODEINFO can identify the associated username on targeted machines.

T1041
Exfiltration Over C2 Channel
MalwareLODEINFO

LODEINFO can exfiltrate collected credentials and browser cookies to the C2 server.

T1047
Windows Management Instrumentation
MalwareLODEINFO

LODEINFO can execute commands with WMI.

T1055
Process Injection
MalwareLODEINFO

LODEINFO can inject shellcode into the memory of compromised hosts.

T1056.001
Keylogging
MalwareLODEINFO

LODEINFO can capture keystrokes on targeted systems.

T1057
Process Discovery
MalwareLODEINFO

LODEINFO can kill a process using specific process ID.

T1070.004
File Deletion
MalwareLODEINFO

LODEINFO can delete files to remove traces of activity from victim systems.

T1074.001
Local Data Staging
MalwareLODEINFO

LODEINFO has collected stolen web cookies locally in the `%TEMP%` folder.

T1082
System Information Discovery
MalwareLODEINFO

LODEINFO can disover machine information including OS architecture, the ANSI code page (ACP) identifier, and hostname.

T1083
File and Directory Discovery
MalwareLODEINFO

LODEINFO has the ability to designate specific files and folders to encryption.

T1105
Ingress Tool Transfer
MalwareLODEINFO

LODEINFO has the ability to download additional files from the C2.

T1106
Native API
MalwareLODEINFO

LODEINFO can use Windows APIs such as `VirtualAllocEx()`, `WriteProcessMemory()`, `CreateRemoteThread()`, `NtAllocateVirtualMemory()`, `NtWriteVirtualMemory()`, and `RtlCreateUserThread()` to enable memory injection of shellcode.

T1113
Screen Capture
MalwareLODEINFO

LODEINFO has the ability to take screenshots.

T1124
System Time Discovery
MalwareLODEINFO

LODEINFO can capture system time to send to the C2.

T1204.002
Malicious File
MalwareLODEINFO

LODEINFO has been executed via victims opening malicious email attachments.

T1480
Execution Guardrails
MalwareLODEINFO

LODEINFO can halt execution if the “en_US” locale is identified on a victim's machine.

T1486
Data Encrypted for Impact
MalwareLODEINFO

LODEINFO can incorporate a ransom command to encrypt specified files and folders.

T1539
Steal Web Session Cookie
MalwareLODEINFO

LODEINFO can list the contents of `%LocalAppData%\Google\Chrome\User Data\` and `%LocalAppData%\Microsoft\Edge\User Data\` to obtain cookies.

T1547.001
Registry Run Keys / Startup Folder
MalwareLODEINFO

LODEINFO has used Registry run keys to set persistence.

T1566.001
Spearphishing Attachment
MalwareLODEINFO

LODEINFO has been distributed to targeted victims via malicious email attachments.

T1573.001
Symmetric Cryptography
MalwareLODEINFO

LODEINFO can encrypt C2 communication with a hardcoded (NV4HDOeOVyL) Vigenere cipher key.

T1574.001
DLL
MalwareLODEINFO

LODEINFO can use legitimate EXE files to sideload malicious DLLs.

T1614.001
System Language Discovery
MalwareLODEINFO

LODEINFO can looks for the “en_US” locale on the victim’s machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.