ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S9037×

20 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareRustyWater

RustyWater has an obfuscated function (i.e. love_me__()) that dynamically reconstructs the string WScript.Shell using hard-coded ASCII values and the Chr() function.

T1027.013
Encrypted/Encoded File
MalwareRustyWater

RustyWater has encrypted all strings in the code using position independent XOR encryption.

T1033
System Owner/User Discovery
MalwareRustyWater

RustyWater has gathered the victim machine’s username.

T1036.005
Match Legitimate Resource Name or Location
MalwareRustyWater

RustyWater has used reddit.exe as its file name and a Cloudflare logo.

T1055.002
Portable Executable Injection
MalwareRustyWater

RustyWater has injected its shellcode into explorer.exe by allocating memory via `VirtualAllocEx`, then by writing the payload via `WriteProcessMemory`.

T1071.001
Web Protocols
MalwareRustyWater

RustyWater has used the Rust request library for HTTP C2 communication.

T1082
System Information Discovery
MalwareRustyWater

RustyWater has gathered the victim machine’s computer name.

T1087.002
Domain Account
MalwareRustyWater

RustyWater has gathered the domain membership of the victim machine’s user.

T1106
Native API
MalwareRustyWater

RustyWater has used `CreateObject` to instantiate a WScript.Shell Component Object Model (COM) object.  Additionally, RustyWater has used `VirtualAllocEx` and `WriteProcessMemory` to inject shellcode into explorer.exe.

T1132.001
Standard Encoding
MalwareRustyWater

RustyWater has encoded collected data with Base64.

T1140
Deobfuscate/Decode Files or Information
MalwareRustyWater

RustyWater has used the WriteHexToFile function to transform an embedded hex string to the payload CertificationKit.ini.

T1204.002
Malicious File
MalwareRustyWater

RustyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed.

T1518.001
Security Software Discovery
MalwareRustyWater

RustyWater has attempted to detect more than 25 antivirus and EDR tools.

T1547.001
Registry Run Keys / Startup Folder
MalwareRustyWater

RustyWater has established persistence by adding `C:\ProgramData\CertificationKit.ini` to a Windows startup Registry key or to a Run or RunOnce Registry key.

T1559.001
Component Object Model
MalwareRustyWater

RustyWater has used a WScript.Shell COM object to execute the CertificationKit.ini file.

T1566.001
Spearphishing Attachment
MalwareRustyWater

RustyWater has sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primary payload for the next stage.

T1573.001
Symmetric Cryptography
MalwareRustyWater

RustyWater has encrypted encoded data with XOR before sending it to the C2 server.

T1622
Debugger Evasion
MalwareRustyWater

RustyWater has registered a Vectored Exception Handler (VEH) to catch debugging efforts.

T1678
Delay Execution
MalwareRustyWater

RustyWater has generated random sleep intervals between C2 communication.

T1684.001
Impersonation
MalwareRustyWater

RustyWater has impersonated TMCell (Altyn Asyr CJSC), the primary mobile operator in Turkmenistan, sending phishing emails with the email domain `info@tmcell`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.