ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S9023×

25 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareHiddenFace

HiddenFace can upload files from the victim machine to C2 nodes.

T1008
Fallback Channels
MalwareHiddenFace

HiddenFace can use active and passive C2 modes that use different encryption algorithms and backdoor commands.

T1027.007
Dynamic API Resolution
MalwareHiddenFace

HiddenFace can dynamically resolve Windows APIs.

T1027.013
Encrypted/Encoded File
MalwareHiddenFace

HiddenFace has encrypted its payload with AES.

T1033
System Owner/User Discovery
MalwareHiddenFace

HiddenFace can collect the username associated with the compromised host.

T1053.005
Scheduled Task
MalwareHiddenFace

HiddenFace has used scheduled tasks for execution and persistence.

T1055
Process Injection
MalwareHiddenFace

HiddenFace can inject code directly into legitimate applications.

T1057
Process Discovery
MalwareHiddenFace

HiddenFace can check running processes against a list of blocklisted applications.

T1070.006
Timestomp
MalwareHiddenFace

HiddenFace can alter timestamps for directory content on targeted machines.

T1082
System Information Discovery
MalwareHiddenFace

HiddenFace can enumerate the hostname and username of the compromised system.

T1090.001
Internal Proxy
MalwareHiddenFace

HiddenFace can act as an internal HTTP proxy within the targeted environment.

T1095
Non-Application Layer Protocol
MalwareHiddenFace

HiddenFace can use a custom TCP protocol over Port 443 for C2.

T1105
Ingress Tool Transfer
MalwareHiddenFace

HiddenFace can download files from the C2 to victim systems.

T1112
Modify Registry
MalwareHiddenFace

HiddenFace can store its configuration file in the Registry.

T1140
Deobfuscate/Decode Files or Information
MalwareHiddenFace

HiddenFace has the ability to decrypt its payload prior to execution.

T1480
Execution Guardrails
MalwareHiddenFace

HiddenFace can check for the presence of specific analysis tools and will terminate itself if they are found.

T1480.002
Mutual Exclusion
MalwareHiddenFace

HiddenFace can create a mutex to ensure only one instance is running at a time.

T1497.003
Time Based Checks
MalwareHiddenFace

HiddenFace can sleep randomly between 30 and 60 seconds to avoid behavioral analysis.

T1518.001
Security Software Discovery
MalwareHiddenFace

HiddenFace can identify processes identified with security applications and tooling.

T1568.002
Domain Generation Algorithms
MalwareHiddenFace

HiddenFace has used dynamic domain generation algorithms in C2.

T1571
Non-Standard Port
MalwareHiddenFace

HiddenFace's passive mode listens on TCP 47000.

T1572
Protocol Tunneling
MalwareHiddenFace

HiddenFace can hide its IP lookup by using DNS over HTTPS (DoH) for C2.

T1573.001
Symmetric Cryptography
MalwareHiddenFace

HiddenFace can use a randomly selected symmetric encryption algorithm for C2.

T1573.002
Asymmetric Cryptography
MalwareHiddenFace

HiddenFace can use RSA-2048 in addition to symmetric algorithms in C2.

T1686.003
Windows Host Firewall
MalwareHiddenFace

HiddenFace can reconfigure Windows firewalls to enable communication by adding a rule named “Cortana” to allow inbound connection to TCP/47000.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.