ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S9032×

18 examples

TechniqueUsed byProcedure example
T1041
Exfiltration Over C2 Channel
MalwareMuddyViper

MuddyViper has uploaded files to the C2 server. Additionally, MuddyViper has the ability to upload the specified file in chunks with sleep time between each chunk.

T1053.005
Scheduled Task
MalwareMuddyViper

MuddyViper has the ability to establish persistence by creating a scheduled task named ManageOnDriveUpdater to launch itself during system startup.

T1056.002
GUI Input Capture
MalwareMuddyViper

MuddyViper has displayed a fake Windows Security dialog to gather credentials.

T1057
Process Discovery
MalwareMuddyViper

MuddyViper has the ability to collect running processes.

T1059
Command and Scripting Interpreter
MalwareMuddyViper

MuddyViper has launched a reverse shell using a provided command line.

T1059.001
PowerShell
MalwareMuddyViper

MuddyViper has used PowerShell.exe to launch a reverse shell.

T1059.003
Windows Command Shell
MalwareMuddyViper

MuddyViper has used cmd.exe to launch a reverse shell.

T1071.001
Web Protocols
MalwareMuddyViper

MuddyViper has used HTTP GET requests over port 443 and with the WINHTTP_FLAG_SECURE set to SSL/TLS via the WinHTTP API.

T1105
Ingress Tool Transfer
MalwareMuddyViper

MuddyViper has the ability to download files from the C2 server. Additionally, MuddyViper has the ability to download a file in chunks with sleep time between each chunk.

T1106
Native API
MalwareMuddyViper

MuddyViper has the ability to relaunch itself using the `CreateProcessW` API.

T1112
Modify Registry
MalwareMuddyViper

MuddyViper has the ability to clear the Registry values in the Windows Startup folder that were previously set for persistence.

T1140
Deobfuscate/Decode Files or Information
MalwareMuddyViper

MuddyViper has decrypted the embedded HackBrowserData tool prior to execution.

T1518.001
Security Software Discovery
MalwareMuddyViper

MuddyViper has the ability to check for a specified list of security tools in the compromised environment.

T1547.001
Registry Run Keys / Startup Folder
MalwareMuddyViper

MuddyViper has the ability to establish persistence by configuring its installation directory as a Windows Startup folder by setting the following Registry values to `%APPDATALOCAL%\Microsoft\Windows\PPBCompatCache\ManagerCache`:  `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup` and `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup`.

T1560
Archive Collected Data
MalwareMuddyViper

MuddyViper has archived collected web browser data into a file named CacheDump.zip.

T1573.001
Symmetric Cryptography
MalwareMuddyViper

MuddyViper has the ability to encrypt C2 communication using AES-CBC using the CNG API, the key `0608101047106453101617106423101013101012101083109710108585106969`, and the initialization vector `0`.

T1620
Reflective Code Loading
MalwareMuddyViper

MuddyViper has reflectively loaded the decrypted HackBrowserData tool in a new thread.

T1678
Delay Execution
MalwareMuddyViper

MuddyViper has the ability to sleep for a certain amount of time, with the default being one minute.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.