ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0534×

51 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareBazar

Bazar can retrieve information from the infected machine.

T1008
Fallback Channels
MalwareBazar

Bazar has the ability to use an alternative C2 server if the primary server fails.

T1012
Query Registry
MalwareBazar

Bazar can query Windows\CurrentVersion\Uninstall for installed applications.

T1016
System Network Configuration Discovery
MalwareBazar

Bazar can collect the IP address and NetBIOS name of an infected machine.

T1018
Remote System Discovery
MalwareBazar

Bazar can enumerate remote systems using Net View.

T1027.002
Software Packing
MalwareBazar

Bazar has a variant with a packed payload.

T1027.007
Dynamic API Resolution
MalwareBazar

Bazar can hash then resolve API calls at runtime.

T1027.013
Encrypted/Encoded File
MalwareBazar

Bazar has used XOR, RSA2, and RC4 encrypted files.

T1033
System Owner/User Discovery
MalwareBazar

Bazar can identify the username of the infected user.

T1036.004
Masquerade Task or Service
MalwareBazar

Bazar can create a task named to appear benign.

T1036.005
Match Legitimate Resource Name or Location
MalwareBazar

The Bazar loader has named malicious shortcuts "adobe" and mimicked communications software.

T1036.007
Double File Extension
MalwareBazar

The Bazar loader has used dual-extension executable files such as PreviewReport.DOC.exe.

T1047
Windows Management Instrumentation
MalwareBazar

Bazar can execute a WMI query to gather information about the installed antivirus engine.

T1053.005
Scheduled Task
MalwareBazar

Bazar can create a scheduled task for persistence.

T1055
Process Injection
MalwareBazar

Bazar can inject code through calling VirtualAllocExNuma.

T1055.012
Process Hollowing
MalwareBazar

Bazar can inject into a target process including Svchost, Explorer, and cmd using process hollowing.

T1055.013
Process Doppelgänging
MalwareBazar

Bazar can inject into a target process using process doppelgänging.

T1057
Process Discovery
MalwareBazar

Bazar can identity the current process on a compromised host.

T1059.001
PowerShell
MalwareBazar

Bazar can execute a PowerShell script received from C2.

T1059.003
Windows Command Shell
MalwareBazar

Bazar can launch cmd.exe to perform reconnaissance commands.

T1070.004
File Deletion
MalwareBazar

Bazar can delete its loader using a batch file in the Windows temporary folder.

T1070.009
Clear Persistence
MalwareBazar

Bazar's loader can delete scheduled tasks created by a previous instance of the malware.

T1071.001
Web Protocols
MalwareBazar

Bazar can use HTTP and HTTPS over ports 80 and 443 in C2 communications.

T1082
System Information Discovery
MalwareBazar

Bazar can fingerprint architecture, computer name, and OS version on the compromised host. Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found.

T1083
File and Directory Discovery
MalwareBazar

Bazar can enumerate the victim's desktop.

T1087.001
Local Account
MalwareBazar

Bazar can identify administrator accounts on an infected host.

T1087.002
Domain Account
MalwareBazar

Bazar has the ability to identify domain administrator accounts.

T1102
Web Service
MalwareBazar

Bazar downloads have been hosted on Google Docs.

T1104
Multi-Stage Channels
MalwareBazar

The Bazar loader is used to download and execute the Bazar backdoor.

T1105
Ingress Tool Transfer
MalwareBazar

Bazar can download and deploy additional payloads, including ransomware and post-exploitation frameworks such as Cobalt Strike.

T1106
Native API
MalwareBazar

Bazar can use various APIs to allocate memory and facilitate code execution/injection.

T1124
System Time Discovery
MalwareBazar

Bazar can collect the time on the compromised host.

T1135
Network Share Discovery
MalwareBazar

Bazar can enumerate shared drives on the domain.

T1140
Deobfuscate/Decode Files or Information
MalwareBazar

Bazar can decrypt downloaded payloads. Bazar also resolves strings and other artifacts at runtime.

T1197
BITS Jobs
MalwareBazar

Bazar has been downloaded via Windows BITS functionality.

T1204.001
Malicious Link
MalwareBazar

Bazar can gain execution after a user clicks on a malicious link to decoy landing pages hosted on Google Docs.

T1482
Domain Trust Discovery
MalwareBazar

Bazar can use Nltest tools to obtain information about the domain.

T1497
Virtualization/Sandbox Evasion
MalwareBazar

Bazar can attempt to overload sandbox analysis by sending 1550 calls to printf.

T1497.003
Time Based Checks
MalwareBazar

Bazar can use a timer to delay execution of core functionality.

T1518
Software Discovery
MalwareBazar

Bazar can query the Registry for installed applications.

T1518.001
Security Software Discovery
MalwareBazar

Bazar can identify the installed antivirus engine.

T1547.001
Registry Run Keys / Startup Folder
MalwareBazar

Bazar can create or add files to Registry Run Keys to establish persistence.

T1547.004
Winlogon Helper DLL
MalwareBazar

Bazar can use Winlogon Helper DLL to establish persistence.

T1547.009
Shortcut Modification
MalwareBazar

Bazar can establish persistence by writing shortcuts to the Windows Startup folder.

T1553.002
Code Signing
MalwareBazar

Bazar has been signed with fake certificates including those appearing to be from VB CORPORATE PTY. LTD.

T1566.002
Spearphishing Link
MalwareBazar

Bazar has been spread via emails with embedded malicious links.

T1568.002
Domain Generation Algorithms
MalwareBazar

Bazar can implement DGA using the current date as a seed variable.

T1573.001
Symmetric Cryptography
MalwareBazar

Bazar can send C2 communications with XOR encryption.

T1573.002
Asymmetric Cryptography
MalwareBazar

Bazar can use TLS in C2 communications.

T1614.001
System Language Discovery
MalwareBazar

Bazar can perform a check to ensure that the operating system's keyboard and language settings are not set to Russian.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.