ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Campaign: C0018×

19 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
CampaignC0018

During C0018, the threat actors ran `nslookup` and Advanced IP Scanner on the target network.

T1021.001
Remote Desktop Protocol
CampaignC0018

During C0018, the threat actors opened a variety of ports to establish RDP connections, including ports 28035, 32467, 41578, and 46892.

T1027.010
Command Obfuscation
CampaignC0018

During C0018, the threat actors used Base64 to encode their PowerShell scripts.

T1033
System Owner/User Discovery
CampaignC0018

During C0018, the threat actors collected `whoami` information via PowerShell scripts.

T1036
Masquerading
CampaignC0018

During C0018, AvosLocker was disguised using the victim company name as the filename.

T1036.005
Match Legitimate Resource Name or Location
CampaignC0018

For C0018, the threat actors renamed a Sliver payload to `vmware_kb.exe`.

T1046
Network Service Discovery
CampaignC0018

During C0018, the threat actors used the SoftPerfect Network Scanner for network scanning.

T1047
Windows Management Instrumentation
CampaignC0018

During C0018, the threat actors used WMIC to modify administrative settings on both a local and a remote host, likely as part of the first stages for their lateral movement; they also used WMI Provider Host (`wmiprvse.exe`) to execute a variety of encoded PowerShell scripts using the `DownloadString` method.

T1059.001
PowerShell
CampaignC0018

During C0018, the threat actors used encoded PowerShell scripts for execution.

T1071.001
Web Protocols
CampaignC0018

During C0018, the threat actors used HTTP for C2 communications.

T1072
Software Deployment Tools
CampaignC0018

During C0018, the threat actors used PDQ Deploy to move AvosLocker and tools across the network.

T1105
Ingress Tool Transfer
CampaignC0018

During C0018, the threat actors downloaded additional tools, such as Mimikatz and Sliver, as well as Cobalt Strike and AvosLocker ransomware onto the victim network.

T1190
Exploit Public-Facing Application
CampaignC0018

During C0018, the threat actors exploited VMWare Horizon Unified Access Gateways that were vulnerable to several Log4Shell vulnerabilities, including CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832.

T1218.011
Rundll32
CampaignC0018

During C0018, the threat actors used `rundll32` to run Mimikatz.

T1219.002
Remote Desktop Software
CampaignC0018

During C0018, the threat actors used AnyDesk to transfer tools between systems.

T1486
Data Encrypted for Impact
CampaignC0018

During C0018, the threat actors used AvosLocker ransomware to encrypt files on the compromised network.

T1570
Lateral Tool Transfer
CampaignC0018

During C0018, the threat actors transferred the SoftPerfect Network Scanner and other tools to machines in the network using AnyDesk and PDQ Deploy.

T1571
Non-Standard Port
CampaignC0018

During C0018, the threat actors opened a variety of ports, including ports 28035, 32467, 41578, and 46892, to establish RDP connections.

T1588.002
Tool
CampaignC0018

For C0018, the threat actors acquired a variety of open source tools, including Mimikatz, Sliver, SoftPerfect Network Scanner, AnyDesk, and PDQ Deploy.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.