ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S9031×

19 examples

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareAshTag

The AshTag AshenOrchestrator component payload as been Base64 encoded and embedded with HTML content from the C2 server.

T1036.005
Match Legitimate Resource Name or Location
MalwareAshTag

AshTag has masqueraded as a legitimate VisualServer utility.

T1041
Exfiltration Over C2 Channel
MalwareAshTag

AshTag has exfiltrated reconnaissance data on targeted systems to C2 servers.

T1047
Windows Management Instrumentation
MalwareAshTag

AshTag can use a .NET program to execute WMI queries and send unique victim IDs to C2.

T1053.005
Scheduled Task
MalwareAshTag

AshTag can set persistence using scheduled tasks.

T1057
Process Discovery
MalwareAshTag

The AshTag AshenOrchestrator component has process management functionality.

T1059.007
JavaScript
MalwareAshTag

AshTag can use JSON files to deliver payloads and configuration files.

T1071.001
Web Protocols
MalwareAshTag

AshTag can use HTTP to send and receive data from C2.

T1082
System Information Discovery
MalwareAshTag

The AshTag loader and AshenOrchestrator components can collect reconnaissance data from victim machines.

T1083
File and Directory Discovery
MalwareAshTag

The AshTag AshenOrchestrator component can enumerate files on victim hosts.

T1102
Web Service
MalwareAshTag

AshTag can download malicious payloads from file sharing services.

T1105
Ingress Tool Transfer
MalwareAshTag

The AshTag stager component can retrieve and execute the main payload.

T1113
Screen Capture
MalwareAshTag

The AshTag AshenOrchestrator component has the ability to take screenshots.

T1140
Deobfuscate/Decode Files or Information
MalwareAshTag

The AshTag stager compoment can decode and decrypt Base64 and XOR-encrypted payloads.

T1204.002
Malicious File
MalwareAshTag

AshTag has been executed through victims downloading and opening malicious RAR archive files.

T1574.001
DLL
MalwareAshTag

AshTag has enabled execution via DLL sideloading using a legitimate executable paired with a malicious DLL named wtsapi32.

T1614
System Location Discovery
MalwareAshTag

AshTag can check geolocation on targeted systems.

T1678
Delay Execution
MalwareAshTag

AshTag can use a set sleep time to delay C2 beaconing.

T1680
Local Storage Discovery
MalwareAshTag

AshTag can use `volumeserialnumber` to enumerate volumes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.