ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1027.005×

9 examples

TechniqueUsed byProcedure example
T1027.005
Indicator Removal from Tools
MalwareGravityRAT

The author of GravityRAT submitted samples to VirusTotal for testing, showing that the author modified the code to try to hide the DDE object in a different part of the document.

T1027.005
Indicator Removal from Tools
MalwareInvisiMole

InvisiMole has undergone regular technical improvements in an attempt to evade detection.

T1027.005
Indicator Removal from Tools
MalwareCobalt Strike

Cobalt Strike includes a capability to modify the Beacon payload to eliminate known signatures or unpacking methods.

T1027.005
Indicator Removal from Tools
MalwareSUNBURST

SUNBURST source code used generic variable names and pre-obfuscated strings, and was likely sanitized of developer comments before being added to SUNSPOT.

T1027.005
Indicator Removal from Tools
MalwareDaserf

Analysis of Daserf has shown that it regularly undergoes technical improvements to evade anti-virus detection.

T1027.005
Indicator Removal from Tools
MalwarePenquin

Penquin can remove strings from binaries.

T1027.005
Indicator Removal from Tools
MalwareQakBot

QakBot can make small changes to itself in order to change its checksum and hash value.

T1027.005
Indicator Removal from Tools
MalwareWaterbear

Waterbear can scramble functions not to be executed again with random values.

T1027.005
Indicator Removal from Tools
ToolPowerSploit

PowerSploit's Find-AVSignature AntivirusBypass module can be used to locate single byte anti-virus signatures.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.