ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0331×

37 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareAgent Tesla

Agent Tesla can collect the IP address of the victim machine and spawn instances of netsh.exe to enumerate wireless settings.

T1016.002
Wi-Fi Discovery
MalwareAgent Tesla

Agent Tesla can collect names and passwords of all Wi-Fi networks to which a device has previously connected.

T1027
Obfuscated Files or Information
MalwareAgent Tesla

Agent Tesla has had its code obfuscated in an apparent attempt to make analysis difficult. Agent Tesla has used the Rijndael symmetric encryption algorithm to encrypt strings.

T1033
System Owner/User Discovery
MalwareAgent Tesla

Agent Tesla can collect the username from the victim’s machine.

T1047
Windows Management Instrumentation
MalwareAgent Tesla

Agent Tesla has used wmi queries to gather information from the system.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareAgent Tesla

Agent Tesla has routines for exfiltration over SMTP, FTP, and HTTP.

T1053.005
Scheduled Task
MalwareAgent Tesla

Agent Tesla has achieved persistence via scheduled tasks.

T1055
Process Injection
MalwareAgent Tesla

Agent Tesla can inject into known, vulnerable binaries on targeted hosts.

T1055.012
Process Hollowing
MalwareAgent Tesla

Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code.

T1056.001
Keylogging
MalwareAgent Tesla

Agent Tesla can log keystrokes on the victim’s machine.

T1057
Process Discovery
MalwareAgent Tesla

Agent Tesla can list the current running processes on the system.

T1071.001
Web Protocols
MalwareAgent Tesla

Agent Tesla has used HTTP for C2 communications.

T1071.003
Mail Protocols
MalwareAgent Tesla

Agent Tesla has used SMTP for C2 communications.

T1082
System Information Discovery
MalwareAgent Tesla

Agent Tesla can collect the system's computer name and also has the capability to collect information on the processor, memory, OS, and video card from the system.

T1087.001
Local Account
MalwareAgent Tesla

Agent Tesla can collect account information from the victim’s machine.

T1105
Ingress Tool Transfer
MalwareAgent Tesla

Agent Tesla can download additional files for execution on the victim’s machine.

T1112
Modify Registry
MalwareAgent Tesla

Agent Tesla can achieve persistence by modifying Registry key entries.

T1113
Screen Capture
MalwareAgent Tesla

Agent Tesla can capture screenshots of the victim’s desktop.

T1115
Clipboard Data
MalwareAgent Tesla

Agent Tesla can steal data from the victim’s clipboard.

T1124
System Time Discovery
MalwareAgent Tesla

Agent Tesla can collect the timestamp from the victim’s machine.

T1125
Video Capture
MalwareAgent Tesla

Agent Tesla can access the victim’s webcam and record video.

T1140
Deobfuscate/Decode Files or Information
MalwareAgent Tesla

Agent Tesla has the ability to decrypt strings encrypted with the Rijndael symmetric encryption algorithm.

T1185
Browser Session Hijacking
MalwareAgent Tesla

Agent Tesla has the ability to use form-grabbing to extract data from web data forms.

T1203
Exploitation for Client Execution
MalwareAgent Tesla

Agent Tesla has exploited Office vulnerabilities such as CVE-2017-11882 and CVE-2017-8570 for execution during delivery.

T1204.002
Malicious File
MalwareAgent Tesla

Agent Tesla has been executed through malicious e-mail attachments

T1218.009
Regsvcs/Regasm
MalwareAgent Tesla

Agent Tesla has dropped RegAsm.exe onto systems for performing malicious activity.

T1497
Virtualization/Sandbox Evasion
MalwareAgent Tesla

Agent Tesla has the ability to perform anti-sandboxing and anti-virtualization checks.

T1547.001
Registry Run Keys / Startup Folder
MalwareAgent Tesla

Agent Tesla can add itself to the Registry as a startup program to establish persistence.

T1552.001
Credentials In Files
MalwareAgent Tesla

Agent Tesla has the ability to extract credentials from configuration or support files.

T1552.002
Credentials in Registry
MalwareAgent Tesla

Agent Tesla has the ability to extract credentials from the Registry.

T1555
Credentials from Password Stores
MalwareAgent Tesla

Agent Tesla has the ability to steal credentials from FTP clients and wireless profiles.

T1555.003
Credentials from Web Browsers
MalwareAgent Tesla

Agent Tesla can gather credentials from a number of browsers.

T1560
Archive Collected Data
MalwareAgent Tesla

Agent Tesla can encrypt data with 3DES before sending it over to a C2 server.

T1564.001
Hidden Files and Directories
MalwareAgent Tesla

Agent Tesla has created hidden folders.

T1564.003
Hidden Window
MalwareAgent Tesla

Agent Tesla has used ProcessWindowStyle.Hidden to hide windows.

T1566.001
Spearphishing Attachment
MalwareAgent Tesla

The primary delivered mechanism for Agent Tesla is through email phishing messages.

T1685
Disable or Modify Tools
MalwareAgent Tesla

Agent Tesla has the capability to kill any running analysis processes and AV software.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.