Real-world descriptions of how a group, tool or campaign used a technique.
251 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1070.004 File Deletion |
MalwarePowerDuke | PowerDuke has a command to write random data across a file and delete it. |
| T1070.004 File Deletion |
MalwareBLINDINGCAN | BLINDINGCAN has deleted itself and associated artifacts from victim machines. |
| T1070.004 File Deletion |
MalwareRCSession | RCSession can remove files from a targeted system. |
| T1070.004 File Deletion |
MalwareBumblebee | Bumblebee can uninstall its loader through the use of a `Sdl` command. |
| T1070.004 File Deletion |
MalwareBRICKSTORM | BRICKSTORM has the ability to delete files and directories. BRICKSTORM also has deleted installer files after execution to reduce detection. |
| T1070.004 File Deletion |
MalwareMURKYTOP | MURKYTOP has the capability to delete local files. |
| T1070.004 File Deletion |
MalwareRDFSNIFFER | RDFSNIFFER has the capability of deleting local files. |
| T1070.004 File Deletion |
MalwareNICECURL | NICECURL has a function to remove artifacts. |
| T1070.004 File Deletion |
MalwareProxysvc | Proxysvc can delete files indicated by the attacker and remove itself from disk using a batch file. |
| T1070.004 File Deletion |
MalwareNOKKI | NOKKI can delete files to cover tracks. |
| T1070.004 File Deletion |
MalwareBackdoor.Oldrea | Backdoor.Oldrea contains a cleanup module that removes traces of itself from the victim. |
| T1070.004 File Deletion |
MalwareStuxnet | Stuxnet uses an RPC server that contains a routine for file deletion and also removes itself from the system through a DLL export by deleting specific files. |
| T1070.004 File Deletion |
MalwareVersaMem | VersaMem deleted files related to initial installation such as temporary files related to the PID of the main web process. |
| T1070.004 File Deletion |
MalwareTDTESS | TDTESS creates then deletes log files during installation of itself as a service. |
| T1070.004 File Deletion |
MalwareCOATHANGER | COATHANGER removes files from victim environments following use in multiple instances. |
| T1070.004 File Deletion |
MalwareHALFBAKED | HALFBAKED can delete a specified file. |
| T1070.004 File Deletion |
MalwareWindTail | WindTail has the ability to receive and execute a self-delete command. |
| T1070.004 File Deletion |
MalwareMisdat | Misdat is capable of deleting the backdoor file. |
| T1070.004 File Deletion |
MalwareExaramel for Linux | Exaramel for Linux can uninstall its persistence mechanism and delete its configuration file. |
| T1070.004 File Deletion |
MalwareKEYMARBLE | KEYMARBLE has the capability to delete files off the victim’s machine. |
| T1070.004 File Deletion |
MalwareHAWKBALL | HAWKBALL has the ability to delete files. |
| T1070.004 File Deletion |
MalwareUrsnif | Ursnif has deleted data staged in tmp files after exfiltration. |
| T1070.004 File Deletion |
MalwareRansomHub | RansomHub has the ability to self-delete. |
| T1070.004 File Deletion |
MalwareRedLeaves | RedLeaves can delete specified files. |
| T1070.004 File Deletion |
MalwareZeus Panda | Zeus Panda has a command to delete a file. It also can uninstall scripts and delete files to cover its track. |
| T1070.004 File Deletion |
MalwareCARROTBAT | CARROTBAT has the ability to delete downloaded files from a compromised host. |
| T1070.004 File Deletion |
MalwareBankshot | Bankshot marks files to be deleted upon the next system reboot and uninstalls and removes itself from the system. |
| T1070.004 File Deletion |
MalwareStrongPity | StrongPity can delete previously exfiltrated files from the compromised host. |
| T1070.004 File Deletion |
MalwarePony | Pony has used scripts to delete itself after execution. |
| T1070.004 File Deletion |
MalwareNebulae | Nebulae has the ability to delete files and directories. |
| T1070.004 File Deletion |
MalwareAuditCred | AuditCred can delete files from the system. |
| T1070.004 File Deletion |
MalwareTONESHELL | TONESHELL has deleted payload files received from the C2 server. |
| T1070.004 File Deletion |
MalwareUPSTYLE | UPSTYLE removes `bootstrap.min.css` after parsing command and control instructions, restoring the file to its original state. |
| T1070.004 File Deletion |
MalwareOceanSalt | OceanSalt can delete files from the system. |
| T1070.004 File Deletion |
MalwareMedusa Ransomware | Medusa Ransomware has the ability to delete itself after execution. Medusa Ransomware also has the ability to delete itself after execution through the command `cmd /c ping localhost -n 3 > nul & del`. |
| T1070.004 File Deletion |
MalwareRainyDay | RainyDay has the ability to uninstall itself by deleting its service and files. |
| T1070.004 File Deletion |
MalwareAppleSeed | AppleSeed can delete files from a compromised host after they are exfiltrated. |
| T1070.004 File Deletion |
MalwarePyDCrypt | PyDCrypt will remove all created artifacts such as dropped executables. |
| T1070.004 File Deletion |
MalwareGreyEnergy | GreyEnergy can securely delete a file by hooking into the DeleteFileA and DeleteFileW functions in the Windows API. |
| T1070.004 File Deletion |
MalwareGomir | Gomir deletes its original executable and terminates its original process after creating a systemd service. |
| T1070.004 File Deletion |
MalwareAria-body | Aria-body has the ability to delete files and directories on compromised hosts. |
| T1070.004 File Deletion |
MalwareBOLDMOVE | BOLDMOVE can remove files on victim systems. |
| T1070.004 File Deletion |
MalwareCrimson | Crimson has the ability to delete files from a compromised host. |
| T1070.004 File Deletion |
MalwareBADHATCH | BADHATCH has the ability to delete PowerShell scripts from a compromised machine. |
| T1070.004 File Deletion |
MalwareMachete | Once a file is uploaded, Machete will delete it from the machine. |
| T1070.004 File Deletion |
MalwarePrikormka | After encrypting its own log files, the log encryption module in Prikormka deletes the original, unencrypted files from the host. |
| T1070.004 File Deletion |
MalwareWoody RAT | Woody RAT has the ability to delete itself from disk by creating a suspended notepad process and writing shellcode to delete a file into the suspended process using `NtWriteVirtualMemory`. |
| T1070.004 File Deletion |
MalwareShrinkLocker | ShrinkLocker can delete itself depending on various checks performed during execution. |
| T1070.004 File Deletion |
MalwareHildegard | Hildegard has deleted scripts after execution. |
| T1070.004 File Deletion |
MalwareSombRAT | SombRAT has the ability to run |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.