ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1047×

93 examples

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
MalwareEKANS

EKANS can use Windows Mangement Instrumentation (WMI) calls to execute operations.

T1047
Windows Management Instrumentation
MalwareBumblebee

Bumblebee can use WMI to gather system information and to spawn processes for code injection.

T1047
Windows Management Instrumentation
MalwareStuxnet

Stuxnet used WMI with an explorer.exe token to execute on a remote share.

T1047
Windows Management Instrumentation
MalwarePOWRUNER

POWRUNER may use WMI when collecting information about a victim.

T1047
Windows Management Instrumentation
MalwareSharpStage

SharpStage can use WMI for execution.

T1047
Windows Management Instrumentation
MalwareSardonic

Sardonic can use WMI to execute PowerShell commands on a compromised machine.

T1047
Windows Management Instrumentation
MalwareHALFBAKED

HALFBAKED can use WMI queries to gather system information.

T1047
Windows Management Instrumentation
MalwareTAMECAT

TAMECAT has used Windows Management Instrumentation (WMI) to query anti-virus products.

T1047
Windows Management Instrumentation
MalwareUrsnif

Ursnif droppers have used WMI classes to execute PowerShell commands.

T1047
Windows Management Instrumentation
MalwareGravityRAT

GravityRAT collects various information via WMI requests, including CPU information in the Win32_Processor entry (Processor ID, Name, Manufacturer and the clock speed).

T1047
Windows Management Instrumentation
MalwareROAMINGHOUSE

ROAMINGHOUSE can use WMI to launch a legitimate executable later used to enable DLL sideloading.

T1047
Windows Management Instrumentation
MalwareTONESHELL

TONESHELL has used WMI queries to gather information from the system.

T1047
Windows Management Instrumentation
MalwarePyDCrypt

PyDCrypt has attempted to execute with WMIC.

T1047
Windows Management Instrumentation
MalwareIMAPLoader

IMAPLoader uses WMI queries to query system information on victim hosts.

T1047
Windows Management Instrumentation
MalwareEmotet

Emotet has used WMI to execute powershell.exe.

T1047
Windows Management Instrumentation
MalwareOlympic Destroyer

Olympic Destroyer uses WMI to help propagate itself across a network.

T1047
Windows Management Instrumentation
MalwareBADHATCH

BADHATCH can utilize WMI to collect system information, create new processes, and run malicious PowerShell scripts on a compromised machine.

T1047
Windows Management Instrumentation
MalwareAction RAT

Action RAT can use WMI to gather AV products installed on an infected host.

T1047
Windows Management Instrumentation
MalwarePUBLOAD

PUBLOAD has used `wmic` to gather information from the victim device.

T1047
Windows Management Instrumentation
MalwareShrinkLocker

ShrinkLocker uses WMI to query information about the victim operating system.

T1047
Windows Management Instrumentation
MalwareFlawedAmmyy

FlawedAmmyy leverages WMI to enumerate anti-virus on the victim.

T1047
Windows Management Instrumentation
MalwareSnip3

Snip3 can query the WMI class `Win32_ComputerSystem` to gather information.

T1047
Windows Management Instrumentation
MalwareHOPLIGHT

HOPLIGHT has used WMI to recompile the Managed Object Format (MOF) files in the WMI repository.

T1047
Windows Management Instrumentation
MalwareProLock

ProLock can use WMIC to execute scripts on targeted hosts.

T1047
Windows Management Instrumentation
MalwareRaspberry Robin

Raspberry Robin can execute via LNK containing a command to run a legitimate executable, such as wmic.exe, to download a malicious Windows Installer (MSI) package.

T1047
Windows Management Instrumentation
MalwareBlackCat

BlackCat can use `wmic.exe` to delete shadow copies on compromised networks.

T1047
Windows Management Instrumentation
MalwareIcedID

IcedID has used WMI to execute binaries.

T1047
Windows Management Instrumentation
MalwareKazuar

Kazuar obtains a list of running processes through WMI querying.

T1047
Windows Management Instrumentation
MalwareLucifer

Lucifer can use WMI to log into remote machines for propagation.

T1047
Windows Management Instrumentation
MalwareBlackEnergy

A BlackEnergy 2 plug-in uses WMI to gather victim host details.

T1047
Windows Management Instrumentation
MalwareNotPetya

NotPetya can use wmic to help propagate itself across a network.

T1047
Windows Management Instrumentation
MalwareAvaddon

Avaddon uses wmic.exe to delete shadow copies.

T1047
Windows Management Instrumentation
MalwareSocGholish

SocGholish has used WMI calls for script execution and system profiling.

T1047
Windows Management Instrumentation
MalwareHELLOKITTY

HELLOKITTY can use WMI to delete volume shadow copies.

T1047
Windows Management Instrumentation
MalwareDarkTortilla

DarkTortilla can use WMI queries to obtain system information.

T1047
Windows Management Instrumentation
MalwareDarkWatchman

DarkWatchman can use WMI to execute commands.

T1047
Windows Management Instrumentation
MalwareDustySky

The DustySky dropper uses Windows Management Instrumentation to extract information about the operating system and whether an anti-virus is active.

T1047
Windows Management Instrumentation
MalwareDEATHRANSOM

DEATHRANSOM has the ability to use WMI to delete volume shadow copies.

T1047
Windows Management Instrumentation
MalwareAkira

Akira will leverage COM objects accessed through WMI during execution to evade detection.

T1047
Windows Management Instrumentation
MalwareDarkGate

DarkGate has used WMI to execute files over the network and to obtain information about the domain.

T1047
Windows Management Instrumentation
MalwareSVCReady

SVCReady can use `WMI` queries to detect the presence of a virtual machine environment.

T1047
Windows Management Instrumentation
MalwareNetwalker

Netwalker can use WMI to delete Shadow Volumes.

T1047
Windows Management Instrumentation
MalwareWannaCry

WannaCry utilizes wmic to delete shadow copies.

T1047
Windows Management Instrumentation
MalwareLatrodectus

Latrodectus has used WMI in malicious email infection chains to facilitate the installation of remotely-hosted files.

T1047
Windows Management Instrumentation
MalwareLODEINFO

LODEINFO can execute commands with WMI.

T1047
Windows Management Instrumentation
MalwareCharmPower

CharmPower can use `wmic` to gather information from a system.

T1047
Windows Management Instrumentation
MalwareEVILNUM

EVILNUM has used the Windows Management Instrumentation (WMI) tool to enumerate infected machines.

T1047
Windows Management Instrumentation
MalwareKOMPROGO

KOMPROGO is capable of running WMI queries.

T1047
Windows Management Instrumentation
MalwareMoleNet

MoleNet can perform WMI commands on the system.

T1047
Windows Management Instrumentation
MalwareMicropsia

Micropsia searches for anti-virus software and firewall products installed on the victim’s machine using WMI.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.