ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1497.003
Time Based Checks
MalwareEgregor

Egregor can perform a long sleep (greater than or equal to 3 minutes) to evade detection.

T1497.003
Time Based Checks
MalwaremetaMain

metaMain has delayed execution for five to six minutes during its persistence establishment process.

T1497.003
Time Based Checks
MalwareLunarWeb

LunarWeb can pause for a number of hours before entering its C2 communication loop.

T1497.003
Time Based Checks
MalwareXCSSET

Using the machine's local time, XCSSET waits 43200 seconds (12 hours) from the initial creation timestamp of a specific file, .report. After the elapsed time, XCSSET executes additional modules.

T1497.003
Time Based Checks
MalwareAppleJeus

AppleJeus has waited a specified time before downloading a second stage payload.

T1497.003
Time Based Checks
MalwareQakBot

The QakBot dropper can delay dropping the payload to evade detection.

T1497.003
Time Based Checks
MalwareStrifeWater

StrifeWater can modify its sleep time responses from the default of 20-22 seconds.

T1497.003
Time Based Checks
Toolevilginx2

evilginx2 has the ability to hide phishing lures for a set time to avoid scanning by sandboxes.

T1497.003
Time Based Checks
ToolBrute Ratel C4

Brute Ratel C4 can call `NtDelayExecution` to pause execution.

T1497.003
Time Based Checks
MalwareCanisterWorm

CanisterWorm has leveraged a Sleep setting of five minutes before executing tasks to evade sandbox environments.

T1497.003
Time Based Checks
MalwareBADFLICK

BADFLICK has delayed communication to the actor-controlled IP address by 5 minutes.

T1498
Network Denial of Service
MalwareLucifer

Lucifer can execute TCP, UDP, and HTTP denial of service (DoS) attacks.

T1498
Network Denial of Service
MalwareNKAbuse

NKAbuse enables multiple types of network denial of service capabilities across several protocols post-installation.

T1499
Endpoint Denial of Service
MalwareOnionDuke

OnionDuke has the capability to use a Denial of Service module.

T1499
Endpoint Denial of Service
MalwareZxShell

ZxShell has a feature to perform SYN flood attack on a host.

T1499.004
Application or System Exploitation
MalwareIndustroyer

Industroyer uses a custom DoS tool that leverages CVE-2015-5374 and targets hardcoded IP addresses of Siemens SIPROTEC devices.

T1505.001
SQL Stored Procedures
MalwareStuxnet

Stuxnet used xp_cmdshell to store and execute SQL code.

T1505.002
Transport Agent
MalwareLightNeuron

LightNeuron has used a malicious Microsoft Exchange transport agent for persistence.

T1505.003
Web Shell
MalwareSEASHARPEE

SEASHARPEE is a Web shell.

T1505.003
Web Shell
MalwarereGeorg

reGeorg is a web shell that has been installed on exposed web servers for access to victim environments.

T1505.003
Web Shell
MalwareBUSHWALK

BUSHWALK is a web shell that has the ability to execute arbitrary commands or write files.

T1505.003
Web Shell
MalwareP.A.S. Webshell

P.A.S. Webshell can gain remote access and execution on target web servers.

T1505.003
Web Shell
MalwareGLASSTOKEN

GLASSTOKEN is a web shell capable of tunneling C2 connections and code execution on compromised Ivanti Secure Connect VPNs.

T1505.003
Web Shell
MalwareASPXSpy

ASPXSpy is a Web shell. The ASPXTool version used by Threat Group-3390 has been deployed to accessible servers running Internet Information Services (IIS).

T1505.003
Web Shell
MalwareChina Chopper

China Chopper's server component is a Web Shell payload.

T1505.003
Web Shell
MalwareSnappyTCP

SnappyTCP is a reverse TCP shell with command and control capabilities used for persistence purposes.

T1505.003
Web Shell
MalwareLIGHTWIRE

LIGHTWIRE is a web shell capable of command execution and establishing persistence on compromised Ivanti Secure Connect VPNs.

T1505.003
Web Shell
MalwareLine Runner

Line Runner is a persistent Lua-based web shell.

T1505.003
Web Shell
MalwareRAPIDPULSE

RAPIDPULSE is a web shell that is capable of arbitrary file read on targeted web servers to exfiltrate items of interest on the victim device.

T1505.003
Web Shell
MalwarePHPsert

PHPsert can use the .php assert function to execute attacker-provided code and maintain persistence on targeted web servers.

T1505.003
Web Shell
MalwarePULSECHECK

PULSECHECK is a web shell that can enable command execution on compromised servers.

T1505.003
Web Shell
MalwareOwaAuth

OwaAuth is a Web shell that appears to be exclusively used by Threat Group-3390. It is installed as an ISAPI filter on Exchange servers and shares characteristics with the China Chopper Web shell.

T1505.003
Web Shell
MalwareSUPERNOVA

SUPERNOVA is a Web shell.

T1505.003
Web Shell
MalwareNeo-reGeorg

Neo-reGeorg can be installed on compromised web servers to tunnel C2 connections.

T1505.003
Web Shell
MalwareFRAMESTING

FRAMESTING is a web shell capable of enabling arbitrary command execution on compromised Ivanti Connect Secure VPNs.

T1505.003
Web Shell
MalwareWIREFIRE

WIREFIRE is a web shell that can download files to and execute arbitrary commands from compromised Ivanti Connect Secure VPNs.

T1505.003
Web Shell
MalwareSTEADYPULSE

STEADYPULSE is a web shell that can enable the execution of arbitrary commands on compromised web servers.

T1505.003
Web Shell
MalwarePHASEJAM

PHASEJAM has inserted Perl-based web shells into legitimate files that provided threat actors with remote access and code execution capabilities on the compromised network appliance.

T1505.003
Web Shell
MalwareSLIGHTPULSE

SLIGHTPULSE is a web shell that can read, write, and execute files on compromised servers.

T1505.003
Web Shell
MalwareSPAWNCHIMERA

SPAWNCHIMERA has created web shells that facilitate actions on the victim host.

T1505.004
IIS Components
MalwareOwaAuth

OwaAuth has been loaded onto Exchange servers and disguised as an ISAPI filter (owaauth.dll). The IIS w3wp.exe process then loads the malicious DLL.

T1505.004
IIS Components
MalwareRGDoor

RGDoor establishes persistence on webservers as an IIS module.

T1505.004
IIS Components
MalwareIceApple

IceApple is an IIS post-exploitation framework, consisting of 18 modules that provide several functionalities.

T1505.006
vSphere Installation Bundles
MalwareVIRTUALPIE

VIRTUALPIE has been installed on VMware ESXi servers through malicious vSphere Installation Bundles (VIBs).

T1518
Software Discovery
MalwareOrz

Orz can gather the victim's Internet Explorer version.

T1518
Software Discovery
MalwareIronWind

IronWind can list installed software on targeted hosts.

T1518
Software Discovery
MalwareInvisibleFerret

InvisibleFerret has gathered installed programs and running processes.

T1518
Software Discovery
MalwarePUBLOAD

PUBLOAD has used several commands executed in sequence via `cmd` in a short interval to gather software versions including querying Registry keys.

T1518
Software Discovery
MalwareWoody RAT

Woody RAT can collect .NET, PowerShell, and Python information from an infected host.

T1518
Software Discovery
MalwareCuckoo Stealer

Cuckoo Stealer has the ability to search systems for installed applications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.