T1047 Windows Management Instrumentation in real malware
ATT&CK technique T1047 Windows Management Instrumentation appears in 1 publicly analyzed sample on MalwareAnalyzer by Cyble, 0.0% of the analyzed corpus. Seven-day prevalence is rising (1 recent vs 0 prior). Most associated families: Maener.
Tactics: execution
Prevalence in the corpus
- Samples exhibiting T1047: 1
- Share of analyzed corpus: 0.0%
- Last 7 days: 1 · prior 7 days: 0 (rising)
Malware families using T1047
- Maener - 1 sample
Example samples
Canonical technique definition: MITRE ATT&CK T1047 (ATT&CK v19.1, CC BY 4.0).
Frequently asked about T1047
- How common is ATT&CK T1047 (Windows Management Instrumentation) in real malware?
- ATT&CK technique T1047 Windows Management Instrumentation appears in 1 publicly analyzed sample on MalwareAnalyzer by Cyble, 0.0% of the analyzed corpus. Seven-day prevalence is rising (1 recent vs 0 prior). Most associated families: Maener.
- Is T1047 becoming more common?
- Prevalence is rising: 1 sample in the last seven days against 0 in the seven days before. This measures submissions to MalwareAnalyzer by Cyble, so it reflects what is being submitted here rather than global attacker behaviour.
- Which malware families use T1047?
- In this corpus T1047 is most associated with Maener (1). Counts are analyzed samples per family in which the technique was observed.
- What share of analyzed samples use T1047?
- 0.0% of the publicly analyzed corpus (1 of 100981 samples) exhibits T1047. Technique attribution comes from behavior captured during real sandbox detonation and from static analysis, not from a vendor label.
All ATT&CK techniques in the corpus · Latest analyzed threats