ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0045×

23 examples

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareADVSTORESHELL

ADVSTORESHELL can enumerate registry keys.

T1027
Obfuscated Files or Information
MalwareADVSTORESHELL

Most of the strings in ADVSTORESHELL are encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed. API function names are also reversed, presumably to avoid detection in memory.

T1029
Scheduled Transfer
MalwareADVSTORESHELL

ADVSTORESHELL collects, compresses, encrypts, and exfiltrates data to the C2 server every 10 minutes.

T1041
Exfiltration Over C2 Channel
MalwareADVSTORESHELL

ADVSTORESHELL exfiltrates data over the same channel used for C2.

T1056.001
Keylogging
MalwareADVSTORESHELL

ADVSTORESHELL can perform keylogging.

T1057
Process Discovery
MalwareADVSTORESHELL

ADVSTORESHELL can list running processes.

T1059.003
Windows Command Shell
MalwareADVSTORESHELL

ADVSTORESHELL can create a remote shell and run a given command.

T1070.004
File Deletion
MalwareADVSTORESHELL

ADVSTORESHELL can delete files and directories.

T1071.001
Web Protocols
MalwareADVSTORESHELL

ADVSTORESHELL connects to port 80 of a C2 server using Wininet API. Data is exchanged via HTTP POSTs.

T1074.001
Local Data Staging
MalwareADVSTORESHELL

ADVSTORESHELL stores output from command execution in a .dat file in the %TEMP% directory.

T1082
System Information Discovery
MalwareADVSTORESHELL

ADVSTORESHELL can run Systeminfo to gather information about the victim.

T1083
File and Directory Discovery
MalwareADVSTORESHELL

ADVSTORESHELL can list files and directories.

T1106
Native API
MalwareADVSTORESHELL

ADVSTORESHELL is capable of starting a process using CreateProcess.

T1112
Modify Registry
MalwareADVSTORESHELL

ADVSTORESHELL is capable of setting and deleting Registry values.

T1120
Peripheral Device Discovery
MalwareADVSTORESHELL

ADVSTORESHELL can list connected devices.

T1132.001
Standard Encoding
MalwareADVSTORESHELL

C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding.

T1218.011
Rundll32
MalwareADVSTORESHELL

ADVSTORESHELL has used rundll32.exe in a Registry value to establish persistence.

T1546.015
Component Object Model Hijacking
MalwareADVSTORESHELL

Some variants of ADVSTORESHELL achieve persistence by registering the payload as a Shell Icon Overlay handler COM object.

T1547.001
Registry Run Keys / Startup Folder
MalwareADVSTORESHELL

ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key.

T1560
Archive Collected Data
MalwareADVSTORESHELL

ADVSTORESHELL encrypts with the 3DES algorithm and a hardcoded key prior to exfiltration.

T1560.003
Archive via Custom Method
MalwareADVSTORESHELL

ADVSTORESHELL compresses output data generated by command execution with a custom implementation of the Lempel–Ziv–Welch (LZW) algorithm.

T1573.001
Symmetric Cryptography
MalwareADVSTORESHELL

A variant of ADVSTORESHELL encrypts some C2 with 3DES.

T1573.002
Asymmetric Cryptography
MalwareADVSTORESHELL

A variant of ADVSTORESHELL encrypts some C2 with RSA.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.