Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareAmadey | Amadey can collect information from a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareAmadey | Amadey can identify the IP address of a victim machine. |
| T1027 Obfuscated Files or Information |
MalwareAmadey | Amadey has obfuscated strings such as antivirus vendor names, domains, files, and others. |
| T1033 System Owner/User Discovery |
MalwareAmadey | Amadey has collected the user name from a compromised host using `GetUserNameA`. |
| T1041 Exfiltration Over C2 Channel |
MalwareAmadey | Amadey has sent victim data to its C2 servers. |
| T1071.001 Web Protocols |
MalwareAmadey | Amadey has used HTTP for C2 communications. |
| T1082 System Information Discovery |
MalwareAmadey | Amadey has collected the computer name and OS version from a compromised machine. |
| T1083 File and Directory Discovery |
MalwareAmadey | Amadey has searched for folders associated with antivirus software. |
| T1105 Ingress Tool Transfer |
MalwareAmadey | Amadey can download and execute files to further infect a host machine with additional malware. |
| T1106 Native API |
MalwareAmadey | Amadey has used a variety of Windows API calls, including `GetComputerNameA`, `GetUserNameA`, and `CreateProcessA`. |
| T1112 Modify Registry |
MalwareAmadey | Amadey has overwritten registry keys for persistence. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAmadey | Amadey has decoded antivirus name strings. |
| T1518.001 Security Software Discovery |
MalwareAmadey | Amadey has checked for a variety of antivirus products. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAmadey | Amadey has changed the Startup folder to the one containing its executable by overwriting the registry keys. |
| T1553.005 Mark-of-the-Web Bypass |
MalwareAmadey | Amadey has modified the `:Zone.Identifier` in the ADS area to zero. |
| T1568.001 Fast Flux DNS |
MalwareAmadey | Amadey has used fast flux DNS for its C2. |
| T1614 System Location Discovery |
MalwareAmadey | Amadey does not run any tasks or install additional malware if the victim machine is based in Russia. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.