Real-world descriptions of how a group, tool or campaign used a technique.
32 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.001 Junk Data |
MalwareLODEINFO | LODEINFO can append C2 communication with randomly generated junk data. |
| T1005 Data from Local System |
MalwareLODEINFO | LODEINFO can upload files from infected hosts to the C2. |
| T1016 System Network Configuration Discovery |
MalwareLODEINFO | LODEINFO can enumerate the MAC address of the compromised host. |
| T1018 Remote System Discovery |
MalwareLODEINFO | LODEINFO can run `net view` and `net view /domain` for network discovery. |
| T1027 Obfuscated Files or Information |
MalwareLODEINFO | LODEINFO has used control flow flattening to obfuscate code. |
| T1027.007 Dynamic API Resolution |
MalwareLODEINFO | LODEINFO can use a hashing algorithm to dynamically resolve API function addresses. |
| T1027.013 Encrypted/Encoded File |
MalwareLODEINFO | The LODEINFO loader module contains XOR-encrypted shellcode. |
| T1027.015 Compression |
MalwareLODEINFO | LODEINFO components have been compressed with zip for delivery. |
| T1027.016 Junk Code Insertion |
MalwareLODEINFO | LODEINFO has inserted junk code to obstruct code analysis. |
| T1033 System Owner/User Discovery |
MalwareLODEINFO | LODEINFO can identify the associated username on targeted machines. |
| T1041 Exfiltration Over C2 Channel |
MalwareLODEINFO | LODEINFO can exfiltrate collected credentials and browser cookies to the C2 server. |
| T1047 Windows Management Instrumentation |
MalwareLODEINFO | LODEINFO can execute commands with WMI. |
| T1055 Process Injection |
MalwareLODEINFO | LODEINFO can inject shellcode into the memory of compromised hosts. |
| T1056.001 Keylogging |
MalwareLODEINFO | LODEINFO can capture keystrokes on targeted systems. |
| T1057 Process Discovery |
MalwareLODEINFO | LODEINFO can kill a process using specific process ID. |
| T1070.004 File Deletion |
MalwareLODEINFO | LODEINFO can delete files to remove traces of activity from victim systems. |
| T1074.001 Local Data Staging |
MalwareLODEINFO | LODEINFO has collected stolen web cookies locally in the `%TEMP%` folder. |
| T1082 System Information Discovery |
MalwareLODEINFO | LODEINFO can disover machine information including OS architecture, the ANSI code page (ACP) identifier, and hostname. |
| T1083 File and Directory Discovery |
MalwareLODEINFO | LODEINFO has the ability to designate specific files and folders to encryption. |
| T1105 Ingress Tool Transfer |
MalwareLODEINFO | LODEINFO has the ability to download additional files from the C2. |
| T1106 Native API |
MalwareLODEINFO | LODEINFO can use Windows APIs such as `VirtualAllocEx()`, `WriteProcessMemory()`, `CreateRemoteThread()`, `NtAllocateVirtualMemory()`, `NtWriteVirtualMemory()`, and `RtlCreateUserThread()` to enable memory injection of shellcode. |
| T1113 Screen Capture |
MalwareLODEINFO | LODEINFO has the ability to take screenshots. |
| T1124 System Time Discovery |
MalwareLODEINFO | LODEINFO can capture system time to send to the C2. |
| T1204.002 Malicious File |
MalwareLODEINFO | LODEINFO has been executed via victims opening malicious email attachments. |
| T1480 Execution Guardrails |
MalwareLODEINFO | LODEINFO can halt execution if the “en_US” locale is identified on a victim's machine. |
| T1486 Data Encrypted for Impact |
MalwareLODEINFO | LODEINFO can incorporate a ransom command to encrypt specified files and folders. |
| T1539 Steal Web Session Cookie |
MalwareLODEINFO | LODEINFO can list the contents of `%LocalAppData%\Google\Chrome\User Data\` and `%LocalAppData%\Microsoft\Edge\User Data\` to obtain cookies. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLODEINFO | LODEINFO has used Registry run keys to set persistence. |
| T1566.001 Spearphishing Attachment |
MalwareLODEINFO | LODEINFO has been distributed to targeted victims via malicious email attachments. |
| T1573.001 Symmetric Cryptography |
MalwareLODEINFO | LODEINFO can encrypt C2 communication with a hardcoded (NV4HDOeOVyL) Vigenere cipher key. |
| T1574.001 DLL |
MalwareLODEINFO | LODEINFO can use legitimate EXE files to sideload malicious DLLs. |
| T1614.001 System Language Discovery |
MalwareLODEINFO | LODEINFO can looks for the “en_US” locale on the victim’s machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.