ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.003×

295 examples

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
MalwareTrickBot

TrickBot has used macros in Excel documents to download and deploy the malware on the user’s machine.

T1059.003
Windows Command Shell
MalwarePowerDuke

PowerDuke runs cmd.exe /c and sends the output to its C2.

T1059.003
Windows Command Shell
MalwareBLINDINGCAN

BLINDINGCAN has executed commands via cmd.exe.

T1059.003
Windows Command Shell
MalwarePikabot

Pikabot can execute Windows shell commands via cmd.exe.

T1059.003
Windows Command Shell
MalwareWiarp

Wiarp creates a backdoor through which remote attackers can open a command line interface.

T1059.003
Windows Command Shell
MalwareRCSession

RCSession can use `cmd.exe` for execution on compromised hosts.

T1059.003
Windows Command Shell
MalwareSpark

Spark can use cmd.exe to run commands.

T1059.003
Windows Command Shell
MalwareBumblebee

Bumblebee can use `cmd.exe` to drop and run files.

T1059.003
Windows Command Shell
MalwareMURKYTOP

MURKYTOP uses the command-line interface.

T1059.003
Windows Command Shell
MalwareExaramel for Windows

Exaramel for Windows has a command to launch a remote shell and executes commands on the victim’s machine.

T1059.003
Windows Command Shell
MalwareProxysvc

Proxysvc executes a binary on the system and logs the results into a temp file by using: cmd.exe /c "<file_path> > %temp%\PM* .tmp 2>&1".

T1059.003
Windows Command Shell
MalwareOrz

Orz can execute shell commands. Orz can execute commands with JavaScript.

T1059.003
Windows Command Shell
MalwareIronWind

IronWind has used the Windows command shell to execute malicious files.

T1059.003
Windows Command Shell
MalwareSEASHARPEE

SEASHARPEE can execute commands on victims.

T1059.003
Windows Command Shell
MalwarePOWRUNER

POWRUNER can execute commands from its C2 server.

T1059.003
Windows Command Shell
MalwareRobbinHood

RobbinHood uses cmd.exe on the victim's computer.

T1059.003
Windows Command Shell
MalwareTDTESS

TDTESS provides a reverse shell on the victim.

T1059.003
Windows Command Shell
MalwareSharpStage

SharpStage can execute arbitrary commands with the command line.

T1059.003
Windows Command Shell
MalwareSardonic

Sardonic has the ability to run `cmd.exe` or other interactive processes on a compromised computer.

T1059.003
Windows Command Shell
MalwareMisdat

Misdat is capable of providing shell functionality to the attacker to execute commands.

T1059.003
Windows Command Shell
Malwareadbupd

adbupd can run a copy of cmd.exe.

T1059.003
Windows Command Shell
MalwareEmissary

Emissary has the capability to create a remote shell and execute specified commands.

T1059.003
Windows Command Shell
MalwareKEYMARBLE

KEYMARBLE can execute shell commands using cmd.exe.

T1059.003
Windows Command Shell
MalwareHAWKBALL

HAWKBALL has created a cmd.exe reverse shell, executed commands, and uploaded output via the command line.

T1059.003
Windows Command Shell
MalwareTAMECAT

TAMECAT has used `cmd.exe` to run the `curl` command.

T1059.003
Windows Command Shell
MalwareHeartCrypt

HeartCrypt can use the `reg add` command via `cmd.exe` for Registry modification.

T1059.003
Windows Command Shell
MalwareRansomHub

RansomHub can use `cmd.exe` to execute multiple commands on infected hosts.

T1059.003
Windows Command Shell
MalwareZLib

ZLib has the ability to execute shell commands.

T1059.003
Windows Command Shell
MalwareRedLeaves

RedLeaves can receive and execute commands with cmd.exe. It can also provide a reverse shell.

T1059.003
Windows Command Shell
MalwareFelismus

Felismus uses command line for execution.

T1059.003
Windows Command Shell
MalwareZeus Panda

Zeus Panda can launch an interface where it can execute several commands on the victim’s PC.

T1059.003
Windows Command Shell
MalwareHavoc

Havoc can execute commands via `cmd.exe`.

T1059.003
Windows Command Shell
MalwareCARROTBAT

CARROTBAT has the ability to execute command line arguments on a compromised host.

T1059.003
Windows Command Shell
MalwareGravityRAT

GravityRAT executes commands remotely on the infected host.

T1059.003
Windows Command Shell
MalwareWEBC2

WEBC2 can open an interactive command shell.

T1059.003
Windows Command Shell
MalwareBankshot

Bankshot uses the command-line interface to execute arbitrary commands.

T1059.003
Windows Command Shell
MalwareSharpDisco

SharpDisco can use `cmd.exe` to execute plugins and to send command output to specified SMB shares.

T1059.003
Windows Command Shell
MalwarexCaon

xCaon has a command to start an interactive shell.

T1059.003
Windows Command Shell
MalwarePLAINTEE

PLAINTEE uses cmd.exe to execute commands on the victim’s machine.

T1059.003
Windows Command Shell
MalwarePony

Pony has used batch scripts to delete itself after execution.

T1059.003
Windows Command Shell
MalwareNebulae

Nebulae can use CMD to execute a process.

T1059.003
Windows Command Shell
MalwareAuditCred

AuditCred can open a reverse shell on the system to execute commands.

T1059.003
Windows Command Shell
MalwareTONESHELL

TONESHELL has created a reverse shell using `cmd.exe`.

T1059.003
Windows Command Shell
MalwareKasidet

Kasidet can execute commands using cmd.exe.

T1059.003
Windows Command Shell
MalwareHannotog

Hannotog can execute various `cmd.exe /c %s` commands.

T1059.003
Windows Command Shell
MalwareOceanSalt

OceanSalt can create a reverse shell on the infected endpoint using cmd.exe. OceanSalt has been executed via malicious macros.

T1059.003
Windows Command Shell
MalwareMedusa Ransomware

Medusa Ransomware has used `cmd.exe` to execute command on an infected host.

T1059.003
Windows Command Shell
MalwareRainyDay

RainyDay can use the Windows Command Shell for execution.

T1059.003
Windows Command Shell
MalwareNETWIRE

NETWIRE can issue commands using cmd.exe.

T1059.003
Windows Command Shell
MalwareTinyTurla

TinyTurla has been installed using a .bat file.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.