Real-world descriptions of how a group, tool or campaign used a technique.
23 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareADVSTORESHELL | ADVSTORESHELL can enumerate registry keys. |
| T1027 Obfuscated Files or Information |
MalwareADVSTORESHELL | Most of the strings in ADVSTORESHELL are encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed. API function names are also reversed, presumably to avoid detection in memory. |
| T1029 Scheduled Transfer |
MalwareADVSTORESHELL | ADVSTORESHELL collects, compresses, encrypts, and exfiltrates data to the C2 server every 10 minutes. |
| T1041 Exfiltration Over C2 Channel |
MalwareADVSTORESHELL | ADVSTORESHELL exfiltrates data over the same channel used for C2. |
| T1056.001 Keylogging |
MalwareADVSTORESHELL | ADVSTORESHELL can perform keylogging. |
| T1057 Process Discovery |
MalwareADVSTORESHELL | ADVSTORESHELL can list running processes. |
| T1059.003 Windows Command Shell |
MalwareADVSTORESHELL | ADVSTORESHELL can create a remote shell and run a given command. |
| T1070.004 File Deletion |
MalwareADVSTORESHELL | ADVSTORESHELL can delete files and directories. |
| T1071.001 Web Protocols |
MalwareADVSTORESHELL | ADVSTORESHELL connects to port 80 of a C2 server using Wininet API. Data is exchanged via HTTP POSTs. |
| T1074.001 Local Data Staging |
MalwareADVSTORESHELL | ADVSTORESHELL stores output from command execution in a .dat file in the %TEMP% directory. |
| T1082 System Information Discovery |
MalwareADVSTORESHELL | ADVSTORESHELL can run Systeminfo to gather information about the victim. |
| T1083 File and Directory Discovery |
MalwareADVSTORESHELL | ADVSTORESHELL can list files and directories. |
| T1106 Native API |
MalwareADVSTORESHELL | ADVSTORESHELL is capable of starting a process using CreateProcess. |
| T1112 Modify Registry |
MalwareADVSTORESHELL | ADVSTORESHELL is capable of setting and deleting Registry values. |
| T1120 Peripheral Device Discovery |
MalwareADVSTORESHELL | ADVSTORESHELL can list connected devices. |
| T1132.001 Standard Encoding |
MalwareADVSTORESHELL | C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding. |
| T1218.011 Rundll32 |
MalwareADVSTORESHELL | ADVSTORESHELL has used rundll32.exe in a Registry value to establish persistence. |
| T1546.015 Component Object Model Hijacking |
MalwareADVSTORESHELL | Some variants of ADVSTORESHELL achieve persistence by registering the payload as a Shell Icon Overlay handler COM object. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareADVSTORESHELL | ADVSTORESHELL achieves persistence by adding itself to the |
| T1560 Archive Collected Data |
MalwareADVSTORESHELL | ADVSTORESHELL encrypts with the 3DES algorithm and a hardcoded key prior to exfiltration. |
| T1560.003 Archive via Custom Method |
MalwareADVSTORESHELL | ADVSTORESHELL compresses output data generated by command execution with a custom implementation of the Lempel–Ziv–Welch (LZW) algorithm. |
| T1573.001 Symmetric Cryptography |
MalwareADVSTORESHELL | A variant of ADVSTORESHELL encrypts some C2 with 3DES. |
| T1573.002 Asymmetric Cryptography |
MalwareADVSTORESHELL | A variant of ADVSTORESHELL encrypts some C2 with RSA. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.