ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0060×

40 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupBRONZE BUTLER

BRONZE BUTLER has used various tools (such as Mimikatz and WCE) to perform credential dumping.

T1005
Data from Local System
GroupBRONZE BUTLER

BRONZE BUTLER has exfiltrated files stolen from local systems.

T1007
System Service Discovery
GroupBRONZE BUTLER

BRONZE BUTLER has used TROJ_GETVERSION to discover system services.

T1018
Remote System Discovery
GroupBRONZE BUTLER

BRONZE BUTLER typically use ping and Net to enumerate systems.

T1027.001
Binary Padding
GroupBRONZE BUTLER

BRONZE BUTLER downloader code has included "0" characters at the end of the file to inflate the file size in a likely attempt to evade anti-virus detection.

T1027.003
Steganography
GroupBRONZE BUTLER

BRONZE BUTLER has used steganography in multiple operations to conceal malicious payloads.

T1036
Masquerading
GroupBRONZE BUTLER

BRONZE BUTLER has masked executables with document file icons including Word and Adobe PDF.

T1036.002
Right-to-Left Override
GroupBRONZE BUTLER

BRONZE BUTLER has used Right-to-Left Override to deceive victims into executing several strains of malware.

T1036.005
Match Legitimate Resource Name or Location
GroupBRONZE BUTLER

BRONZE BUTLER has given malware the same name as an existing file on the file share server to cause users to unwittingly launch and install the malware on additional systems.

T1039
Data from Network Shared Drive
GroupBRONZE BUTLER

BRONZE BUTLER has exfiltrated files stolen from file shares.

T1053.002
At
GroupBRONZE BUTLER

BRONZE BUTLER has used at to register a scheduled task to execute malware during lateral movement.

T1053.005
Scheduled Task
GroupBRONZE BUTLER

BRONZE BUTLER has used schtasks to register a scheduled task to execute malware during lateral movement.

T1059.001
PowerShell
GroupBRONZE BUTLER

BRONZE BUTLER has used PowerShell for execution.

T1059.003
Windows Command Shell
GroupBRONZE BUTLER

BRONZE BUTLER has used batch scripts and the command-line interface for execution.

T1059.005
Visual Basic
GroupBRONZE BUTLER

BRONZE BUTLER has used VBS and VBE scripts for execution.

T1059.006
Python
GroupBRONZE BUTLER

BRONZE BUTLER has made use of Python-based remote access tools.

T1070.004
File Deletion
GroupBRONZE BUTLER

The BRONZE BUTLER uploader or malware the uploader uses command to delete the RAR archives after they have been exfiltrated.

T1071.001
Web Protocols
GroupBRONZE BUTLER

BRONZE BUTLER malware has used HTTP for C2.

T1080
Taint Shared Content
GroupBRONZE BUTLER

BRONZE BUTLER has placed malware on file shares and given it the same name as legitimate documents on the share.

T1083
File and Directory Discovery
GroupBRONZE BUTLER

BRONZE BUTLER has collected a list of files from the victim and uploaded it to its C2 server, and then created a new list of specific files to steal.

T1087.002
Domain Account
GroupBRONZE BUTLER

BRONZE BUTLER has used net user /domain to identify account information.

T1102.001
Dead Drop Resolver
GroupBRONZE BUTLER

BRONZE BUTLER's MSGET downloader uses a dead drop resolver to access malicious payloads.

T1105
Ingress Tool Transfer
GroupBRONZE BUTLER

BRONZE BUTLER has used various tools to download files, including DGet (a similar tool to wget).

T1113
Screen Capture
GroupBRONZE BUTLER

BRONZE BUTLER has used a tool to capture screenshots.

T1124
System Time Discovery
GroupBRONZE BUTLER

BRONZE BUTLER has used net time to check the local time on a target system.

T1132.001
Standard Encoding
GroupBRONZE BUTLER

Several BRONZE BUTLER tools encode data with base64 when posting it to a C2 server.

T1140
Deobfuscate/Decode Files or Information
GroupBRONZE BUTLER

BRONZE BUTLER downloads encoded payloads and decodes them on the victim.

T1189
Drive-by Compromise
GroupBRONZE BUTLER

BRONZE BUTLER compromised three Japanese websites using a Flash exploit to perform watering hole attacks.

T1203
Exploitation for Client Execution
GroupBRONZE BUTLER

BRONZE BUTLER has exploited Microsoft Office vulnerabilities CVE-2014-4114, CVE-2018-0802, and CVE-2018-0798 for execution.

T1204.002
Malicious File
GroupBRONZE BUTLER

BRONZE BUTLER has attempted to get users to launch malicious Microsoft Word attachments delivered via spearphishing emails.

T1518
Software Discovery
GroupBRONZE BUTLER

BRONZE BUTLER has used tools to enumerate software installed on an infected host.

T1547.001
Registry Run Keys / Startup Folder
GroupBRONZE BUTLER

BRONZE BUTLER has used a batch script that adds a Registry Run key to establish malware persistence.

T1548.002
Bypass User Account Control
GroupBRONZE BUTLER

BRONZE BUTLER has used a Windows 10 specific tool and xxmm to bypass UAC for privilege escalation.

T1550.003
Pass the Ticket
GroupBRONZE BUTLER

BRONZE BUTLER has created forged Kerberos Ticket Granting Ticket (TGT) and Ticket Granting Service (TGS) tickets to maintain administrative access.

T1560.001
Archive via Utility
GroupBRONZE BUTLER

BRONZE BUTLER has compressed data into password-protected RAR archives prior to exfiltration.

T1566.001
Spearphishing Attachment
GroupBRONZE BUTLER

BRONZE BUTLER used spearphishing emails with malicious Microsoft Word attachments to infect victims.

T1573.001
Symmetric Cryptography
GroupBRONZE BUTLER

BRONZE BUTLER has used RC4 encryption (for Datper malware) and AES (for xxmm malware) to obfuscate HTTP traffic. BRONZE BUTLER has also used a tool called RarStar that encodes data with a custom XOR algorithm when posting it to a C2 server.

T1574.001
DLL
GroupBRONZE BUTLER

BRONZE BUTLER has used legitimate applications to side-load malicious DLLs.

T1588.002
Tool
GroupBRONZE BUTLER

BRONZE BUTLER has obtained and used open-source tools such as Mimikatz, gsecdump, and Windows Credential Editor.

T1685
Disable or Modify Tools
GroupBRONZE BUTLER

BRONZE BUTLER has incorporated code into several tools that attempts to terminate anti-virus processes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.