Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1041 Exfiltration Over C2 Channel |
MalwareMuddyViper | MuddyViper has uploaded files to the C2 server. Additionally, MuddyViper has the ability to upload the specified file in chunks with sleep time between each chunk. |
| T1053.005 Scheduled Task |
MalwareMuddyViper | MuddyViper has the ability to establish persistence by creating a scheduled task named ManageOnDriveUpdater to launch itself during system startup. |
| T1056.002 GUI Input Capture |
MalwareMuddyViper | MuddyViper has displayed a fake Windows Security dialog to gather credentials. |
| T1057 Process Discovery |
MalwareMuddyViper | MuddyViper has the ability to collect running processes. |
| T1059 Command and Scripting Interpreter |
MalwareMuddyViper | MuddyViper has launched a reverse shell using a provided command line. |
| T1059.001 PowerShell |
MalwareMuddyViper | MuddyViper has used PowerShell.exe to launch a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareMuddyViper | MuddyViper has used cmd.exe to launch a reverse shell. |
| T1071.001 Web Protocols |
MalwareMuddyViper | MuddyViper has used HTTP GET requests over port 443 and with the WINHTTP_FLAG_SECURE set to SSL/TLS via the WinHTTP API. |
| T1105 Ingress Tool Transfer |
MalwareMuddyViper | MuddyViper has the ability to download files from the C2 server. Additionally, MuddyViper has the ability to download a file in chunks with sleep time between each chunk. |
| T1106 Native API |
MalwareMuddyViper | MuddyViper has the ability to relaunch itself using the `CreateProcessW` API. |
| T1112 Modify Registry |
MalwareMuddyViper | MuddyViper has the ability to clear the Registry values in the Windows Startup folder that were previously set for persistence. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMuddyViper | MuddyViper has decrypted the embedded HackBrowserData tool prior to execution. |
| T1518.001 Security Software Discovery |
MalwareMuddyViper | MuddyViper has the ability to check for a specified list of security tools in the compromised environment. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMuddyViper | MuddyViper has the ability to establish persistence by configuring its installation directory as a Windows Startup folder by setting the following Registry values to `%APPDATALOCAL%\Microsoft\Windows\PPBCompatCache\ManagerCache`: `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup` and `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup`. |
| T1560 Archive Collected Data |
MalwareMuddyViper | MuddyViper has archived collected web browser data into a file named CacheDump.zip. |
| T1573.001 Symmetric Cryptography |
MalwareMuddyViper | MuddyViper has the ability to encrypt C2 communication using AES-CBC using the CNG API, the key `0608101047106453101617106423101013101012101083109710108585106969`, and the initialization vector `0`. |
| T1620 Reflective Code Loading |
MalwareMuddyViper | MuddyViper has reflectively loaded the decrypted HackBrowserData tool in a new thread. |
| T1678 Delay Execution |
MalwareMuddyViper | MuddyViper has the ability to sleep for a certain amount of time, with the default being one minute. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.