ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0239×

25 examples

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
MalwareBankshot

Bankshot generates a false TLS handshake using a public certificate to disguise C2 network communications.

T1005
Data from Local System
MalwareBankshot

Bankshot collects files from the local system.

T1012
Query Registry
MalwareBankshot

Bankshot searches for certain Registry keys to be configured before executing the payload.

T1041
Exfiltration Over C2 Channel
MalwareBankshot

Bankshot exfiltrates data over its C2 channel.

T1057
Process Discovery
MalwareBankshot

Bankshot identifies processes and collects the process ids.

T1059.003
Windows Command Shell
MalwareBankshot

Bankshot uses the command-line interface to execute arbitrary commands.

T1070
Indicator Removal
MalwareBankshot

Bankshot deletes all artifacts associated with the malware from the infected machine.

T1070.004
File Deletion
MalwareBankshot

Bankshot marks files to be deleted upon the next system reboot and uninstalls and removes itself from the system.

T1070.006
Timestomp
MalwareBankshot

Bankshot modifies the time of a file as specified by the control server.

T1071.001
Web Protocols
MalwareBankshot

Bankshot uses HTTP for command and control communication.

T1082
System Information Discovery
MalwareBankshot

Bankshot gathers system information, network addresses, and the operation system version.

T1083
File and Directory Discovery
MalwareBankshot

Bankshot searches for files on the victim's machine.

T1087.001
Local Account
MalwareBankshot

Bankshot gathers domain and account names/information through process monitoring.

T1087.002
Domain Account
MalwareBankshot

Bankshot gathers domain and account names/information through process monitoring.

T1105
Ingress Tool Transfer
MalwareBankshot

Bankshot uploads files and secondary payloads to the victim's machine.

T1106
Native API
MalwareBankshot

Bankshot creates processes using the Windows API calls: CreateProcessA() and CreateProcessAsUserA().

T1112
Modify Registry
MalwareBankshot

Bankshot writes data into the Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Pniumj.

T1119
Automated Collection
MalwareBankshot

Bankshot recursively generates a list of files within a directory and sends them back to the control server.

T1132.002
Non-Standard Encoding
MalwareBankshot

Bankshot encodes commands from the control server using a range of characters and gzip.

T1134.002
Create Process with Token
MalwareBankshot

Bankshot grabs a user token using WTSQueryUserToken and then creates a process by impersonating a logged-on user.

T1140
Deobfuscate/Decode Files or Information
MalwareBankshot

Bankshot decodes embedded XOR strings.

T1203
Exploitation for Client Execution
MalwareBankshot

Bankshot leverages a known zero-day vulnerability in Adobe Flash to execute the implant into the victims’ machines.

T1543.003
Windows Service
MalwareBankshot

Bankshot can terminate a specific process by its process id.

T1571
Non-Standard Port
MalwareBankshot

Bankshot binds and listens on port 1058 for HTTP traffic while also utilizing a FakeTLS method.

T1680
Local Storage Discovery
MalwareBankshot

Bankshot gathers disk type and disk free space.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.