ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1497.003
Time Based Checks
MalwareGoldMax

GoldMax has set an execution trigger date and time, stored as an ASCII Unix/Epoch time value.

T1497.003
Time Based Checks
MalwareDarkTortilla

DarkTortilla can implement the `kernel32.dll` Sleep function to delay execution for up to 300 seconds before implementing persistence or processing an addon package.

T1497.003
Time Based Checks
MalwareBisonal

Bisonal has checked if the malware is running in a virtual environment with the anti-debug function GetTickCount() to compare the timing.

T1497.003
Time Based Checks
MalwareClambling

Clambling can wait 30 minutes before initiating contact with C2.

T1497.003
Time Based Checks
MalwareSVCReady

SVCReady can enter a sleep stage for 30 minutes to evade detection.

T1497.003
Time Based Checks
MalwareThiefQuest

ThiefQuest invokes time call to check the system's time, executes a sleep command, invokes a second time call, and then compares the time difference between the two time calls and the amount of time the system slept to identify the sandbox.

T1497.003
Time Based Checks
MalwareSaint Bot

Saint Bot has used the command `timeout 20` to pause the execution of its initial loader.

T1497.003
Time Based Checks
MalwareP8RAT

P8RAT has the ability to "sleep" for a specified time to evade detection.

T1497.003
Time Based Checks
MalwareBendyBear

BendyBear can check for analysis environments and signs of debugging using the Windows API kernel32!GetTickCountKernel32 call.

T1497.003
Time Based Checks
MalwareSodaMaster

SodaMaster has the ability to put itself to "sleep" for a specified time.

T1497.003
Time Based Checks
MalwareLiteDuke

LiteDuke can wait 30 seconds before executing additional code if security software is detected.

T1497.003
Time Based Checks
MalwareBazar

Bazar can use a timer to delay execution of core functionality.

T1497.003
Time Based Checks
MalwareHiddenFace

HiddenFace can sleep randomly between 30 and 60 seconds to avoid behavioral analysis.

T1497.003
Time Based Checks
MalwareHermeticWiper

HermeticWiper has the ability to receive a command parameter to sleep prior to carrying out destructive actions on a targeted host.

T1497.003
Time Based Checks
MalwareSUNBURST

SUNBURST remained dormant after initial access for a period of up to two weeks.

T1497.003
Time Based Checks
MalwareEvilBunny

EvilBunny has used time measurements from 3 different APIs before and after performing sleep operations to check and abort if the malware is running in a sandbox.

T1497.003
Time Based Checks
MalwareIPsec Helper

IPsec Helper will sleep for a random number of seconds, iterating 200 times over sleeps between one to three seconds, before continuing execution flow.

T1497.003
Time Based Checks
MalwareGoldenSpy

GoldenSpy's installer has delayed installation of GoldenSpy for two hours after it reaches a victim system.

T1497.003
Time Based Checks
MalwareGrimAgent

GrimAgent can sleep for 195 - 205 seconds after payload execution and before deleting its task.

T1497.003
Time Based Checks
MalwareClop

Clop has used the sleep command to avoid sandbox detection.

T1497.003
Time Based Checks
MalwareLokibot

Lokibot has performed a time-based anti-debug check before downloading its third stage.

T1497.003
Time Based Checks
MalwareEgregor

Egregor can perform a long sleep (greater than or equal to 3 minutes) to evade detection.

T1497.003
Time Based Checks
MalwaremetaMain

metaMain has delayed execution for five to six minutes during its persistence establishment process.

T1497.003
Time Based Checks
MalwareLunarWeb

LunarWeb can pause for a number of hours before entering its C2 communication loop.

T1497.003
Time Based Checks
MalwareXCSSET

Using the machine's local time, XCSSET waits 43200 seconds (12 hours) from the initial creation timestamp of a specific file, .report. After the elapsed time, XCSSET executes additional modules.

T1497.003
Time Based Checks
MalwareAppleJeus

AppleJeus has waited a specified time before downloading a second stage payload.

T1497.003
Time Based Checks
MalwareQakBot

The QakBot dropper can delay dropping the payload to evade detection.

T1497.003
Time Based Checks
MalwareStrifeWater

StrifeWater can modify its sleep time responses from the default of 20-22 seconds.

T1497.003
Time Based Checks
Toolevilginx2

evilginx2 has the ability to hide phishing lures for a set time to avoid scanning by sandboxes.

T1497.003
Time Based Checks
ToolBrute Ratel C4

Brute Ratel C4 can call `NtDelayExecution` to pause execution.

T1497.003
Time Based Checks
MalwareCanisterWorm

CanisterWorm has leveraged a Sleep setting of five minutes before executing tasks to evade sandbox environments.

T1497.003
Time Based Checks
MalwareBADFLICK

BADFLICK has delayed communication to the actor-controlled IP address by 5 minutes.

T1498
Network Denial of Service
GroupAPT28

In 2016, APT28 conducted a distributed denial of service (DDoS) attack against the World Anti-Doping Agency.

T1498
Network Denial of Service
MalwareLucifer

Lucifer can execute TCP, UDP, and HTTP denial of service (DoS) attacks.

T1498
Network Denial of Service
MalwareNKAbuse

NKAbuse enables multiple types of network denial of service capabilities across several protocols post-installation.

T1499
Endpoint Denial of Service
GroupSandworm Team

Sandworm Team temporarily disrupted service to Georgian government, non-government, and private sector websites after compromising a Georgian web hosting provider in 2019.

T1499
Endpoint Denial of Service
MalwareOnionDuke

OnionDuke has the capability to use a Denial of Service module.

T1499
Endpoint Denial of Service
MalwareZxShell

ZxShell has a feature to perform SYN flood attack on a host.

T1499.004
Application or System Exploitation
MalwareIndustroyer

Industroyer uses a custom DoS tool that leverages CVE-2015-5374 and targets hardcoded IP addresses of Siemens SIPROTEC devices.

T1505.001
SQL Stored Procedures
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used various MS-SQL stored procedures.

T1505.001
SQL Stored Procedures
MalwareStuxnet

Stuxnet used xp_cmdshell to store and execute SQL code.

T1505.002
Transport Agent
MalwareLightNeuron

LightNeuron has used a malicious Microsoft Exchange transport agent for persistence.

T1505.003
Web Shell
CampaignFrostyGoop Incident

FrostyGoop Incident deployed a ReGeorg variant web shell to impacted systems following initial access for persistence.

T1505.003
Web Shell
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors followed exploitation of SharePoint servers with installation of a malicious .aspx web shell (spinstall0.aspx) that was written to the `_layouts/15/` directory, granting persistent HTTP-based access.

T1505.003
Web Shell
CampaignCutting Edge

During Cutting Edge, threat actors used multiple web shells to maintain presence on compromised Connect Secure appliances such as WIREFIRE, GLASSTOKEN, BUSHWALK, LIGHTWIRE, and FRAMESTING.

T1505.003
Web Shell
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors deployed a PHP-based webshell to maintain persistent access.

T1505.003
Web Shell
CampaignHomeLand Justice

For HomeLand Justice, threat actors used .aspx webshells named pickers.aspx, error4.aspx, and ClientBin.aspx, to maintain persistence.

T1505.003
Web Shell
CampaignC0032

During the C0032 campaign, TEMP.Veles planted Web shells on Outlook Exchange servers.

T1505.003
Web Shell
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors generated a web shell within a vulnerable Enterprise Resource Planning Web Application Server as a persistence mechanism.

T1505.003
Web Shell
CampaignAPT41 DUST

APT41 DUST involved use of web shells such as ANTSWORD and BLUEBEAM for persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.