Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1497.003 Time Based Checks |
MalwareEgregor | Egregor can perform a long sleep (greater than or equal to 3 minutes) to evade detection. |
| T1497.003 Time Based Checks |
MalwaremetaMain | metaMain has delayed execution for five to six minutes during its persistence establishment process. |
| T1497.003 Time Based Checks |
MalwareLunarWeb | LunarWeb can pause for a number of hours before entering its C2 communication loop. |
| T1497.003 Time Based Checks |
MalwareXCSSET | Using the machine's local time, XCSSET waits 43200 seconds (12 hours) from the initial creation timestamp of a specific file, |
| T1497.003 Time Based Checks |
MalwareAppleJeus | AppleJeus has waited a specified time before downloading a second stage payload. |
| T1497.003 Time Based Checks |
MalwareQakBot | The QakBot dropper can delay dropping the payload to evade detection. |
| T1497.003 Time Based Checks |
MalwareStrifeWater | StrifeWater can modify its sleep time responses from the default of 20-22 seconds. |
| T1497.003 Time Based Checks |
Toolevilginx2 | evilginx2 has the ability to hide phishing lures for a set time to avoid scanning by sandboxes. |
| T1497.003 Time Based Checks |
ToolBrute Ratel C4 | Brute Ratel C4 can call `NtDelayExecution` to pause execution. |
| T1497.003 Time Based Checks |
MalwareCanisterWorm | CanisterWorm has leveraged a Sleep setting of five minutes before executing tasks to evade sandbox environments. |
| T1497.003 Time Based Checks |
MalwareBADFLICK | BADFLICK has delayed communication to the actor-controlled IP address by 5 minutes. |
| T1498 Network Denial of Service |
MalwareLucifer | Lucifer can execute TCP, UDP, and HTTP denial of service (DoS) attacks. |
| T1498 Network Denial of Service |
MalwareNKAbuse | NKAbuse enables multiple types of network denial of service capabilities across several protocols post-installation. |
| T1499 Endpoint Denial of Service |
MalwareOnionDuke | OnionDuke has the capability to use a Denial of Service module. |
| T1499 Endpoint Denial of Service |
MalwareZxShell | ZxShell has a feature to perform SYN flood attack on a host. |
| T1499.004 Application or System Exploitation |
MalwareIndustroyer | Industroyer uses a custom DoS tool that leverages CVE-2015-5374 and targets hardcoded IP addresses of Siemens SIPROTEC devices. |
| T1505.001 SQL Stored Procedures |
MalwareStuxnet | Stuxnet used xp_cmdshell to store and execute SQL code. |
| T1505.002 Transport Agent |
MalwareLightNeuron | LightNeuron has used a malicious Microsoft Exchange transport agent for persistence. |
| T1505.003 Web Shell |
MalwareSEASHARPEE | SEASHARPEE is a Web shell. |
| T1505.003 Web Shell |
MalwarereGeorg | reGeorg is a web shell that has been installed on exposed web servers for access to victim environments. |
| T1505.003 Web Shell |
MalwareBUSHWALK | BUSHWALK is a web shell that has the ability to execute arbitrary commands or write files. |
| T1505.003 Web Shell |
MalwareP.A.S. Webshell | P.A.S. Webshell can gain remote access and execution on target web servers. |
| T1505.003 Web Shell |
MalwareGLASSTOKEN | GLASSTOKEN is a web shell capable of tunneling C2 connections and code execution on compromised Ivanti Secure Connect VPNs. |
| T1505.003 Web Shell |
MalwareASPXSpy | ASPXSpy is a Web shell. The ASPXTool version used by Threat Group-3390 has been deployed to accessible servers running Internet Information Services (IIS). |
| T1505.003 Web Shell |
MalwareChina Chopper | China Chopper's server component is a Web Shell payload. |
| T1505.003 Web Shell |
MalwareSnappyTCP | SnappyTCP is a reverse TCP shell with command and control capabilities used for persistence purposes. |
| T1505.003 Web Shell |
MalwareLIGHTWIRE | LIGHTWIRE is a web shell capable of command execution and establishing persistence on compromised Ivanti Secure Connect VPNs. |
| T1505.003 Web Shell |
MalwareLine Runner | Line Runner is a persistent Lua-based web shell. |
| T1505.003 Web Shell |
MalwareRAPIDPULSE | RAPIDPULSE is a web shell that is capable of arbitrary file read on targeted web servers to exfiltrate items of interest on the victim device. |
| T1505.003 Web Shell |
MalwarePHPsert | PHPsert can use the .php assert function to execute attacker-provided code and maintain persistence on targeted web servers. |
| T1505.003 Web Shell |
MalwarePULSECHECK | PULSECHECK is a web shell that can enable command execution on compromised servers. |
| T1505.003 Web Shell |
MalwareOwaAuth | OwaAuth is a Web shell that appears to be exclusively used by Threat Group-3390. It is installed as an ISAPI filter on Exchange servers and shares characteristics with the China Chopper Web shell. |
| T1505.003 Web Shell |
MalwareSUPERNOVA | SUPERNOVA is a Web shell. |
| T1505.003 Web Shell |
MalwareNeo-reGeorg | Neo-reGeorg can be installed on compromised web servers to tunnel C2 connections. |
| T1505.003 Web Shell |
MalwareFRAMESTING | FRAMESTING is a web shell capable of enabling arbitrary command execution on compromised Ivanti Connect Secure VPNs. |
| T1505.003 Web Shell |
MalwareWIREFIRE | WIREFIRE is a web shell that can download files to and execute arbitrary commands from compromised Ivanti Connect Secure VPNs. |
| T1505.003 Web Shell |
MalwareSTEADYPULSE | STEADYPULSE is a web shell that can enable the execution of arbitrary commands on compromised web servers. |
| T1505.003 Web Shell |
MalwarePHASEJAM | PHASEJAM has inserted Perl-based web shells into legitimate files that provided threat actors with remote access and code execution capabilities on the compromised network appliance. |
| T1505.003 Web Shell |
MalwareSLIGHTPULSE | SLIGHTPULSE is a web shell that can read, write, and execute files on compromised servers. |
| T1505.003 Web Shell |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has created web shells that facilitate actions on the victim host. |
| T1505.004 IIS Components |
MalwareOwaAuth | OwaAuth has been loaded onto Exchange servers and disguised as an ISAPI filter (owaauth.dll). The IIS w3wp.exe process then loads the malicious DLL. |
| T1505.004 IIS Components |
MalwareRGDoor | RGDoor establishes persistence on webservers as an IIS module. |
| T1505.004 IIS Components |
MalwareIceApple | IceApple is an IIS post-exploitation framework, consisting of 18 modules that provide several functionalities. |
| T1505.006 vSphere Installation Bundles |
MalwareVIRTUALPIE | VIRTUALPIE has been installed on VMware ESXi servers through malicious vSphere Installation Bundles (VIBs). |
| T1518 Software Discovery |
MalwareOrz | Orz can gather the victim's Internet Explorer version. |
| T1518 Software Discovery |
MalwareIronWind | IronWind can list installed software on targeted hosts. |
| T1518 Software Discovery |
MalwareInvisibleFerret | InvisibleFerret has gathered installed programs and running processes. |
| T1518 Software Discovery |
MalwarePUBLOAD | PUBLOAD has used several commands executed in sequence via `cmd` in a short interval to gather software versions including querying Registry keys. |
| T1518 Software Discovery |
MalwareWoody RAT | Woody RAT can collect .NET, PowerShell, and Python information from an infected host. |
| T1518 Software Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer has the ability to search systems for installed applications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.