Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareAshTag | The AshTag AshenOrchestrator component payload as been Base64 encoded and embedded with HTML content from the C2 server. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareAshTag | AshTag has masqueraded as a legitimate VisualServer utility. |
| T1041 Exfiltration Over C2 Channel |
MalwareAshTag | AshTag has exfiltrated reconnaissance data on targeted systems to C2 servers. |
| T1047 Windows Management Instrumentation |
MalwareAshTag | AshTag can use a .NET program to execute WMI queries and send unique victim IDs to C2. |
| T1053.005 Scheduled Task |
MalwareAshTag | AshTag can set persistence using scheduled tasks. |
| T1057 Process Discovery |
MalwareAshTag | The AshTag AshenOrchestrator component has process management functionality. |
| T1059.007 JavaScript |
MalwareAshTag | AshTag can use JSON files to deliver payloads and configuration files. |
| T1071.001 Web Protocols |
MalwareAshTag | AshTag can use HTTP to send and receive data from C2. |
| T1082 System Information Discovery |
MalwareAshTag | The AshTag loader and AshenOrchestrator components can collect reconnaissance data from victim machines. |
| T1083 File and Directory Discovery |
MalwareAshTag | The AshTag AshenOrchestrator component can enumerate files on victim hosts. |
| T1102 Web Service |
MalwareAshTag | AshTag can download malicious payloads from file sharing services. |
| T1105 Ingress Tool Transfer |
MalwareAshTag | The AshTag stager component can retrieve and execute the main payload. |
| T1113 Screen Capture |
MalwareAshTag | The AshTag AshenOrchestrator component has the ability to take screenshots. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAshTag | The AshTag stager compoment can decode and decrypt Base64 and XOR-encrypted payloads. |
| T1204.002 Malicious File |
MalwareAshTag | AshTag has been executed through victims downloading and opening malicious RAR archive files. |
| T1574.001 DLL |
MalwareAshTag | AshTag has enabled execution via DLL sideloading using a legitimate executable paired with a malicious DLL named wtsapi32. |
| T1614 System Location Discovery |
MalwareAshTag | AshTag can check geolocation on targeted systems. |
| T1678 Delay Execution |
MalwareAshTag | AshTag can use a set sleep time to delay C2 beaconing. |
| T1680 Local Storage Discovery |
MalwareAshTag | AshTag can use `volumeserialnumber` to enumerate volumes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.