ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0414×

16 examples

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareBabyShark

BabyShark has executed the reg query command for HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default.

T1016
System Network Configuration Discovery
MalwareBabyShark

BabyShark has executed the ipconfig /all command.

T1033
System Owner/User Discovery
MalwareBabyShark

BabyShark has executed the whoami command.

T1053.005
Scheduled Task
MalwareBabyShark

BabyShark has used scheduled tasks to maintain persistence.

T1056.001
Keylogging
MalwareBabyShark

BabyShark has a PowerShell-based remote administration ability that can implement a PowerShell or C# based keylogger.

T1057
Process Discovery
MalwareBabyShark

BabyShark has executed the tasklist command.

T1059.003
Windows Command Shell
MalwareBabyShark

BabyShark has used cmd.exe to execute commands.

T1059.005
Visual Basic
MalwareBabyShark

BabyShark can execute additional VisualBasic content.

T1070.004
File Deletion
MalwareBabyShark

BabyShark has cleaned up all files associated with the secondary payload execution.

T1082
System Information Discovery
MalwareBabyShark

BabyShark has executed the ver command.

T1083
File and Directory Discovery
MalwareBabyShark

BabyShark has used dir to search for "programfiles" and "appdata".

T1105
Ingress Tool Transfer
MalwareBabyShark

BabyShark has downloaded additional files from the C2.

T1132.001
Standard Encoding
MalwareBabyShark

BabyShark has encoded data using certutil before exfiltration.

T1140
Deobfuscate/Decode Files or Information
MalwareBabyShark

BabyShark has the ability to decode downloaded files prior to execution.

T1218.005
Mshta
MalwareBabyShark

BabyShark has used mshta.exe to download and execute applications from a remote server.

T1547.001
Registry Run Keys / Startup Folder
MalwareBabyShark

BabyShark has added a Registry key to ensure all future macros are enabled for Microsoft Word and Excel as well as for additional persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.