ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1001×

13 examples

TechniqueUsed byProcedure example
T1001
Data Obfuscation
MalwareNinja

Ninja has the ability to modify headers and URL paths to hide malicious traffic in HTTP requests.

T1001
Data Obfuscation
MalwareSystemBC

SystemBC has encoded with XOR and encrypted with RC4 its beacon.

T1001
Data Obfuscation
MalwareFlawedAmmyy

FlawedAmmyy may obfuscate portions of the initial C2 handshake.

T1001
Data Obfuscation
MalwareRDAT

RDAT has used encoded data within subdomains as AES ciphertext to communicate from the host to the C2.

T1001
Data Obfuscation
MalwareOkrum

Okrum leverages the HTTP protocol for C2 communication, while hiding the actual messages in the Cookie and Set-Cookie headers of the HTTP requests.

T1001
Data Obfuscation
MalwareDarkGate

DarkGate will retrieved encrypted commands from its command and control server for follow-on actions such as cryptocurrency mining.

T1001
Data Obfuscation
MalwareStrelaStealer

StrelaStealer encrypts the payload of HTTP POST communications using the same XOR key used for the malware's DLL payload.

T1001
Data Obfuscation
MalwareFRAMESTING

FRAMESTING can send and receive zlib compressed data within `POST` requests.

T1001
Data Obfuscation
MalwareTrailBlazer

TrailBlazer can masquerade its C2 traffic as legitimate Google Notifications HTTP requests.

T1001
Data Obfuscation
MalwareFunnyDream

FunnyDream can send compressed and obfuscated packets to C2.

T1001
Data Obfuscation
MalwareSideTwist

SideTwist can embed C2 responses in the source code of a fake Flickr webpage.

T1001
Data Obfuscation
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has hashed a string containing system information prior to exfiltration via POST requests.

T1001
Data Obfuscation
Toolevilginx2

evilginx2 can modify the Origin and Referrer fields in HTTPS headers it relays between intended victims and legitimate websites to comply with cross-origin resource sharing (CORS) restrictions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.