ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0650×

71 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareQakBot

QakBot can use a variety of commands, including esentutl.exe to steal sensitive data from Internet Explorer and Microsoft Edge, to acquire information that is subsequently exfiltrated.

T1010
Application Window Discovery
MalwareQakBot

QakBot has the ability to enumerate windows on a compromised host.

T1016
System Network Configuration Discovery
MalwareQakBot

QakBot can use net config workstation, arp -a, `nslookup`, and ipconfig /all to gather network configuration information.

T1016.001
Internet Connection Discovery
MalwareQakBot

QakBot can measure the download speed on a targeted host.

T1018
Remote System Discovery
MalwareQakBot

QakBot can identify remote systems through the net view command.

T1027
Obfuscated Files or Information
MalwareQakBot

QakBot has hidden code within Excel spreadsheets by turning the font color to white and splitting it across multiple cells.

T1027.001
Binary Padding
MalwareQakBot

QakBot can use large file sizes to evade detection.

T1027.002
Software Packing
MalwareQakBot

QakBot can encrypt and pack malicious payloads.

T1027.005
Indicator Removal from Tools
MalwareQakBot

QakBot can make small changes to itself in order to change its checksum and hash value.

T1027.006
HTML Smuggling
MalwareQakBot

QakBot has been delivered in ZIP files via HTML smuggling.

T1027.010
Command Obfuscation
MalwareQakBot

QakBot can use obfuscated and encoded scripts.

T1027.011
Fileless Storage
MalwareQakBot

QakBot can store its configuration information in a randomly named subkey under HKCU\Software\Microsoft.

T1033
System Owner/User Discovery
MalwareQakBot

QakBot can identify the user name on a compromised system.

T1036.008
Masquerade File Type
MalwareQakBot

The QakBot payload has been disguised as a PNG file and hidden within LNK files using a Microsoft File Explorer icon.

T1041
Exfiltration Over C2 Channel
MalwareQakBot

QakBot can send stolen information to C2 nodes including passwords, accounts, and emails.

T1047
Windows Management Instrumentation
MalwareQakBot

QakBot can execute WMI queries to gather information.

T1049
System Network Connections Discovery
MalwareQakBot

QakBot can use netstat to enumerate current network connections.

T1053.005
Scheduled Task
MalwareQakBot

QakBot has the ability to create scheduled tasks for persistence.

T1055
Process Injection
MalwareQakBot

QakBot can inject itself into processes including explore.exe, Iexplore.exe, Mobsync.exe., and wermgr.exe.

T1055.012
Process Hollowing
MalwareQakBot

QakBot can use process hollowing to execute its main payload.

T1056.001
Keylogging
MalwareQakBot

QakBot can capture keystrokes on a compromised host.

T1057
Process Discovery
MalwareQakBot

QakBot has the ability to check running processes.

T1059.001
PowerShell
MalwareQakBot

QakBot can use PowerShell to download and execute payloads.

T1059.003
Windows Command Shell
MalwareQakBot

QakBot can use cmd.exe to launch itself and to execute multiple C2 commands.

T1059.005
Visual Basic
MalwareQakBot

QakBot can use VBS to download and execute malicious files.

T1059.007
JavaScript
MalwareQakBot

The QakBot web inject module can inject Java Script into web banking pages visited by the victim.

T1069.001
Local Groups
MalwareQakBot

QakBot can use net localgroup to enable discovery of local groups.

T1070.004
File Deletion
MalwareQakBot

QakBot can delete folders and files including overwriting its executable with legitimate programs.

T1071.001
Web Protocols
MalwareQakBot

QakBot has the ability to use HTTP and HTTPS in communication with C2 servers.

T1074.001
Local Data Staging
MalwareQakBot

QakBot has stored stolen emails and other data into new folders prior to exfiltration.

T1082
System Information Discovery
MalwareQakBot

QakBot can collect system information including the OS version and domain on a compromised host.

T1083
File and Directory Discovery
MalwareQakBot

QakBot can identify whether it has been run previously on a host by checking for a specified folder.

T1090.002
External Proxy
MalwareQakBot

QakBot has a module that can proxy C2 communications.

T1091
Replication Through Removable Media
MalwareQakBot

QakBot has the ability to use removable drives to spread through compromised networks.

T1095
Non-Application Layer Protocol
MalwareQakBot

QakBot has the ability use TCP to send or receive C2 packets.

T1105
Ingress Tool Transfer
MalwareQakBot

QakBot has the ability to download additional components and malware.

T1106
Native API
MalwareQakBot

QakBot can use GetProcAddress to help delete malicious strings from memory.

T1110
Brute Force
MalwareQakBot

QakBot can conduct brute force attacks to capture credentials.

T1112
Modify Registry
MalwareQakBot

QakBot can modify the Registry to store its configuration information in a randomly named subkey under HKCU\Software\Microsoft.

T1114.001
Local Email Collection
MalwareQakBot

QakBot can target and steal locally stored emails to support thread hijacking phishing campaigns.

T1120
Peripheral Device Discovery
MalwareQakBot

QakBot can identify peripheral devices on targeted systems.

T1124
System Time Discovery
MalwareQakBot

QakBot can identify the system time on a targeted host.

T1132.001
Standard Encoding
MalwareQakBot

QakBot can Base64 encode system information sent to C2.

T1135
Network Share Discovery
MalwareQakBot

QakBot can use net share to identify network shares for use in lateral movement.

T1140
Deobfuscate/Decode Files or Information
MalwareQakBot

QakBot can deobfuscate and re-assemble code strings for execution.

T1185
Browser Session Hijacking
MalwareQakBot

QakBot can use advanced web injects to steal web banking credentials.

T1204.001
Malicious Link
MalwareQakBot

QakBot has gained execution through users opening malicious links.

T1204.002
Malicious File
MalwareQakBot

QakBot has gained execution through users opening malicious attachments.

T1210
Exploitation of Remote Services
MalwareQakBot

QakBot can move laterally using worm-like functionality through exploitation of SMB.

T1218.007
Msiexec
MalwareQakBot

QakBot can use MSIExec to spawn multiple cmd.exe processes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.