ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0260×

73 examples

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
MalwareInvisiMole

InvisiMole can mimic HTTP protocol with custom HTTP “verbs” HIDE, ZVVP, and NOP.

T1005
Data from Local System
MalwareInvisiMole

InvisiMole can collect data from the system, and can monitor changes in specified directories.

T1007
System Service Discovery
MalwareInvisiMole

InvisiMole can obtain running services on the victim.

T1008
Fallback Channels
MalwareInvisiMole

InvisiMole has been configured with several servers available for alternate C2 communications.

T1010
Application Window Discovery
MalwareInvisiMole

InvisiMole can enumerate windows and child windows on a compromised host.

T1012
Query Registry
MalwareInvisiMole

InvisiMole can enumerate Registry values, keys, and data.

T1016
System Network Configuration Discovery
MalwareInvisiMole

InvisiMole gathers information on the IP forwarding table, MAC address, configured proxy, and network SSID.

T1025
Data from Removable Media
MalwareInvisiMole

InvisiMole can collect jpeg files from connected MTP devices.

T1027
Obfuscated Files or Information
MalwareInvisiMole

InvisiMole avoids analysis by encrypting all strings, internal files, configuration data and by using a custom executable format.

T1027.005
Indicator Removal from Tools
MalwareInvisiMole

InvisiMole has undergone regular technical improvements in an attempt to evade detection.

T1033
System Owner/User Discovery
MalwareInvisiMole

InvisiMole lists local users and session information.

T1036.004
Masquerade Task or Service
MalwareInvisiMole

InvisiMole has attempted to disguise itself by registering under a seemingly legitimate service name.

T1036.005
Match Legitimate Resource Name or Location
MalwareInvisiMole

InvisiMole has disguised its droppers as legitimate software or documents, matching their original names and locations, and saved its files as mpr.dll in the Windows folder.

T1046
Network Service Discovery
MalwareInvisiMole

InvisiMole can scan the network for open ports and vulnerable instances of RDP and SMB protocols.

T1053.005
Scheduled Task
MalwareInvisiMole

InvisiMole has used scheduled tasks named MSST and \Microsoft\Windows\Autochk\Scheduled to establish persistence.

T1055
Process Injection
MalwareInvisiMole

InvisiMole can inject itself into another process to avoid detection including use of a technique called ListPlanting that customizes the sorting algorithm in a ListView structure.

T1055.002
Portable Executable Injection
MalwareInvisiMole

InvisiMole can inject its backdoor as a portable executable into a target process.

T1055.004
Asynchronous Procedure Call
MalwareInvisiMole

InvisiMole can inject its code into a trusted process via the APC queue.

T1055.015
ListPlanting
MalwareInvisiMole

InvisiMole has used ListPlanting to inject code into a trusted process.

T1056.001
Keylogging
MalwareInvisiMole

InvisiMole can capture keystrokes on a compromised host.

T1057
Process Discovery
MalwareInvisiMole

InvisiMole can obtain a list of running processes.

T1059.003
Windows Command Shell
MalwareInvisiMole

InvisiMole can launch a remote shell to execute commands.

T1059.007
JavaScript
MalwareInvisiMole

InvisiMole can use a JavaScript file as part of its execution chain.

T1068
Exploitation for Privilege Escalation
MalwareInvisiMole

InvisiMole has exploited CVE-2007-5633 vulnerability in the speedfan.sys driver to obtain kernel mode privileges.

T1070.004
File Deletion
MalwareInvisiMole

InvisiMole has deleted files and directories including XML and files successfully uploaded to C2 servers.

T1070.005
Network Share Connection Removal
MalwareInvisiMole

InvisiMole can disconnect previously connected remote drives.

T1070.006
Timestomp
MalwareInvisiMole

InvisiMole samples were timestomped by the authors by setting the PE timestamps to all zero values. InvisiMole also has a built-in command to modify file times.

T1071.001
Web Protocols
MalwareInvisiMole

InvisiMole uses HTTP for C2 communications.

T1071.004
DNS
MalwareInvisiMole

InvisiMole has used a custom implementation of DNS tunneling to embed C2 communications in DNS requests and replies.

T1074.001
Local Data Staging
MalwareInvisiMole

InvisiMole determines a working directory where it stores all the gathered data about the compromised machine.

T1080
Taint Shared Content
MalwareInvisiMole

InvisiMole can replace legitimate software or documents in the compromised network with their trojanized versions, in an attempt to propagate itself within the network.

T1082
System Information Discovery
MalwareInvisiMole

InvisiMole can gather information on the OS version, computer name, DEP policy, and memory size.

T1083
File and Directory Discovery
MalwareInvisiMole

InvisiMole can list information about files in a directory and recently opened or used documents. InvisiMole can also search for specific files by supplied file mask.

T1087.001
Local Account
MalwareInvisiMole

InvisiMole has a command to list account information on the victim’s machine.

T1090.001
Internal Proxy
MalwareInvisiMole

InvisiMole can function as a proxy to create a server that relays communication between the client and C&C server, or between two clients.

T1090.002
External Proxy
MalwareInvisiMole

InvisiMole InvisiMole can identify proxy servers used by the victim and use them for C2 communication.

T1095
Non-Application Layer Protocol
MalwareInvisiMole

InvisiMole has used TCP to download additional modules.

T1105
Ingress Tool Transfer
MalwareInvisiMole

InvisiMole can upload files to the victim's machine for operations.

T1106
Native API
MalwareInvisiMole

InvisiMole can use winapiexec tool for indirect execution of ShellExecuteW and CreateProcessA.

T1112
Modify Registry
MalwareInvisiMole

InvisiMole has a command to create, set, copy, or delete a specified Registry key or value.

T1113
Screen Capture
MalwareInvisiMole

InvisiMole can capture screenshots of not only the entire screen, but of each separate window open, in case they are overlapping.

T1119
Automated Collection
MalwareInvisiMole

InvisiMole can sort and collect specific documents as well as generate a list of all files on a newly inserted drive and store them in an encrypted file.

T1123
Audio Capture
MalwareInvisiMole

InvisiMole can record sound using input audio devices.

T1124
System Time Discovery
MalwareInvisiMole

InvisiMole gathers the local system time from the victim’s machine.

T1125
Video Capture
MalwareInvisiMole

InvisiMole can remotely activate the victim’s webcam to capture content.

T1132.002
Non-Standard Encoding
MalwareInvisiMole

InvisiMole can use a modified base32 encoding to encode data within the subdomain of C2 requests.

T1135
Network Share Discovery
MalwareInvisiMole

InvisiMole can gather network share information.

T1140
Deobfuscate/Decode Files or Information
MalwareInvisiMole

InvisiMole can decrypt, unpack and load a DLL from its resources, or from blobs encrypted with Data Protection API, two-key triple DES, and variations of the XOR cipher.

T1203
Exploitation for Client Execution
MalwareInvisiMole

InvisiMole has installed legitimate but vulnerable Total Video Player software and wdigest.dll library drivers on compromised hosts to exploit stack overflow and input validation vulnerabilities for code execution.

T1204.002
Malicious File
MalwareInvisiMole

InvisiMole can deliver trojanized versions of software and documents, relying on user execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.