ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0114×

59 examples

TechniqueUsed byProcedure example
T1003.003
NTDS
GroupChimera

Chimera has gathered the SYSTEM registry and ntds.dit files from target systems. Chimera specifically has used the NtdsAudit tool to dump the password hashes of domain users via msadcs.exe "NTDS.dit" -s "SYSTEM" -p RecordedTV_pdmp.txt --users-csv RecordedTV_users.csv and used ntdsutil to copy the Active Directory database.

T1007
System Service Discovery
GroupChimera

Chimera has used net start and net use for system service discovery.

T1012
Query Registry
GroupChimera

Chimera has queried Registry keys using reg query \\<host>\HKU\<SID>\SOFTWARE\Microsoft\Terminal Server Client\Servers and reg query \\<host>\HKU\<SID>\Software\Microsoft\Windows\CurrentVersion\Internet Settings.

T1016
System Network Configuration Discovery
GroupChimera

Chimera has used ipconfig, Ping, and tracert to enumerate the IP address and network environment and settings of the local host.

T1018
Remote System Discovery
GroupChimera

Chimera has utilized various scans and queries to find domain controllers and remote services in the target environment.

T1021.001
Remote Desktop Protocol
GroupChimera

Chimera has used RDP to access targeted systems.

T1021.002
SMB/Windows Admin Shares
GroupChimera

Chimera has used Windows admin shares to move laterally.

T1021.006
Windows Remote Management
GroupChimera

Chimera has used WinRM for lateral movement.

T1027.010
Command Obfuscation
GroupChimera

Chimera has encoded PowerShell commands.

T1033
System Owner/User Discovery
GroupChimera

Chimera has used the quser command to show currently logged on users.

T1036.005
Match Legitimate Resource Name or Location
GroupChimera

Chimera has renamed malware to GoogleUpdate.exe and WinRAR to jucheck.exe, RecordedTV.ms, teredo.tmp, update.exe, and msadcs1.exe.

T1039
Data from Network Shared Drive
GroupChimera

Chimera has collected data of interest from network shares.

T1041
Exfiltration Over C2 Channel
GroupChimera

Chimera has used Cobalt Strike C2 beacons for data exfiltration.

T1046
Network Service Discovery
GroupChimera

Chimera has used the get -b <start ip> -e <end ip> -p command for network scanning as well as a custom Python tool packed into a Windows executable named Get.exe to scan IP ranges for HTTP.

T1047
Windows Management Instrumentation
GroupChimera

Chimera has used WMIC to execute remote commands.

T1049
System Network Connections Discovery
GroupChimera

Chimera has used netstat -ano | findstr EST to discover network connections.

T1053.005
Scheduled Task
GroupChimera

Chimera has used scheduled tasks to invoke Cobalt Strike including through batch script schtasks /create /ru "SYSTEM" /tn "update" /tr "cmd /c c:\windows\temp\update.bat" /sc once /f /st and to maintain persistence.

T1057
Process Discovery
GroupChimera

Chimera has used tasklist to enumerate processes.

T1059.001
PowerShell
GroupChimera

Chimera has used PowerShell scripts to execute malicious payloads and the DSInternals PowerShell module to make use of Active Directory features.

T1059.003
Windows Command Shell
GroupChimera

Chimera has used the Windows Command Shell and batch scripts for execution on compromised hosts.

T1069.001
Local Groups
GroupChimera

Chimera has used net localgroup administrators to identify accounts with local administrative rights.

T1070.004
File Deletion
GroupChimera

Chimera has performed file deletion to evade detection.

T1070.006
Timestomp
GroupChimera

Chimera has used a Windows version of the Linux touch command to modify the date and time stamp on DLLs.

T1071.001
Web Protocols
GroupChimera

Chimera has used HTTPS for C2 communications.

T1071.004
DNS
GroupChimera

Chimera has used Cobalt Strike to encapsulate C2 in DNS traffic.

T1074.001
Local Data Staging
GroupChimera

Chimera has staged stolen data locally on compromised hosts.

T1074.002
Remote Data Staging
GroupChimera

Chimera has staged stolen data on designated servers in the target environment.

T1078
Valid Accounts
GroupChimera

Chimera has used a valid account to maintain persistence via scheduled task.

T1078.002
Domain Accounts
GroupChimera

Chimera has used compromised domain accounts to gain access to the target environment.

T1083
File and Directory Discovery
GroupChimera

Chimera has utilized multiple commands to identify data of interest in file and directory listings.

T1087.001
Local Account
GroupChimera

Chimera has used net user for account discovery.

T1087.002
Domain Account
GroupChimera

Chimera has has used net user /dom and net user Administrator to enumerate domain accounts including administrator accounts.

T1105
Ingress Tool Transfer
GroupChimera

Chimera has remotely copied tools and malware onto targeted systems.

T1106
Native API
GroupChimera

Chimera has used direct Windows system calls by leveraging Dumpert.

T1110.003
Password Spraying
GroupChimera

Chimera has used multiple password spraying attacks against victim's remote services to obtain valid user and administrator accounts.

T1110.004
Credential Stuffing
GroupChimera

Chimera has used credential stuffing against victim's remote services to obtain valid accounts.

T1111
Multi-Factor Authentication Interception
GroupChimera

Chimera has registered alternate phone numbers for compromised users to intercept 2FA codes sent via SMS.

T1114.001
Local Email Collection
GroupChimera

Chimera has harvested data from victim's e-mail including through execution of wmic /node:<ip> process call create "cmd /c copy c:\Users\<username>\<path>\backup.pst c:\windows\temp\backup.pst" copy "i:\<path>\<username>\My Documents\<filename>.pst"
copy
.

T1114.002
Remote Email Collection
GroupChimera

Chimera has harvested data from remote mailboxes including through execution of \\<hostname>\c$\Users\<username>\AppData\Local\Microsoft\Outlook*.ost.

T1119
Automated Collection
GroupChimera

Chimera has used custom DLLs for continuous retrieval of data from memory.

T1124
System Time Discovery
GroupChimera

Chimera has used time /t and net time \\ip/hostname for system time discovery.

T1133
External Remote Services
GroupChimera

Chimera has used legitimate credentials to login to an external VPN, Citrix, SSH, and other remote services.

T1135
Network Share Discovery
GroupChimera

Chimera has used net share and net view to identify network shares of interest.

T1201
Password Policy Discovery
GroupChimera

Chimera has used the NtdsAudit utility to collect information related to accounts and passwords.

T1213.002
Sharepoint
GroupChimera

Chimera has collected documents from the victim's SharePoint.

T1217
Browser Information Discovery
GroupChimera

Chimera has used type \\<hostname>\c$\Users\<username>\Favorites\Links\Bookmarks bar\Imported From IE\*citrix* for bookmark discovery.

T1482
Domain Trust Discovery
GroupChimera

Chimera has nltest /domain_trusts to identify domain trust relationships.

T1550.002
Pass the Hash
GroupChimera

Chimera has dumped password hashes for use in pass the hash authentication attacks.

T1556.001
Domain Controller Authentication
GroupChimera

Chimera's malware has altered the NTLM authentication program on domain controllers to allow Chimera to login without a valid credential.

T1560.001
Archive via Utility
GroupChimera

Chimera has used gzip for Linux OS and a modified RAR software to archive data on Windows hosts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.