ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1070.004×

251 examples

TechniqueUsed byProcedure example
T1070.004
File Deletion
MalwarePowerDuke

PowerDuke has a command to write random data across a file and delete it.

T1070.004
File Deletion
MalwareBLINDINGCAN

BLINDINGCAN has deleted itself and associated artifacts from victim machines.

T1070.004
File Deletion
MalwareRCSession

RCSession can remove files from a targeted system.

T1070.004
File Deletion
MalwareBumblebee

Bumblebee can uninstall its loader through the use of a `Sdl` command.

T1070.004
File Deletion
MalwareBRICKSTORM

BRICKSTORM has the ability to delete files and directories. BRICKSTORM also has deleted installer files after execution to reduce detection.

T1070.004
File Deletion
MalwareMURKYTOP

MURKYTOP has the capability to delete local files.

T1070.004
File Deletion
MalwareRDFSNIFFER

RDFSNIFFER has the capability of deleting local files.

T1070.004
File Deletion
MalwareNICECURL

NICECURL has a function to remove artifacts.

T1070.004
File Deletion
MalwareProxysvc

Proxysvc can delete files indicated by the attacker and remove itself from disk using a batch file.

T1070.004
File Deletion
MalwareNOKKI

NOKKI can delete files to cover tracks.

T1070.004
File Deletion
MalwareBackdoor.Oldrea

Backdoor.Oldrea contains a cleanup module that removes traces of itself from the victim.

T1070.004
File Deletion
MalwareStuxnet

Stuxnet uses an RPC server that contains a routine for file deletion and also removes itself from the system through a DLL export by deleting specific files.

T1070.004
File Deletion
MalwareVersaMem

VersaMem deleted files related to initial installation such as temporary files related to the PID of the main web process.

T1070.004
File Deletion
MalwareTDTESS

TDTESS creates then deletes log files during installation of itself as a service.

T1070.004
File Deletion
MalwareCOATHANGER

COATHANGER removes files from victim environments following use in multiple instances.

T1070.004
File Deletion
MalwareHALFBAKED

HALFBAKED can delete a specified file.

T1070.004
File Deletion
MalwareWindTail

WindTail has the ability to receive and execute a self-delete command.

T1070.004
File Deletion
MalwareMisdat

Misdat is capable of deleting the backdoor file.

T1070.004
File Deletion
MalwareExaramel for Linux

Exaramel for Linux can uninstall its persistence mechanism and delete its configuration file.

T1070.004
File Deletion
MalwareKEYMARBLE

KEYMARBLE has the capability to delete files off the victim’s machine.

T1070.004
File Deletion
MalwareHAWKBALL

HAWKBALL has the ability to delete files.

T1070.004
File Deletion
MalwareUrsnif

Ursnif has deleted data staged in tmp files after exfiltration.

T1070.004
File Deletion
MalwareRansomHub

RansomHub has the ability to self-delete.

T1070.004
File Deletion
MalwareRedLeaves

RedLeaves can delete specified files.

T1070.004
File Deletion
MalwareZeus Panda

Zeus Panda has a command to delete a file. It also can uninstall scripts and delete files to cover its track.

T1070.004
File Deletion
MalwareCARROTBAT

CARROTBAT has the ability to delete downloaded files from a compromised host.

T1070.004
File Deletion
MalwareBankshot

Bankshot marks files to be deleted upon the next system reboot and uninstalls and removes itself from the system.

T1070.004
File Deletion
MalwareStrongPity

StrongPity can delete previously exfiltrated files from the compromised host.

T1070.004
File Deletion
MalwarePony

Pony has used scripts to delete itself after execution.

T1070.004
File Deletion
MalwareNebulae

Nebulae has the ability to delete files and directories.

T1070.004
File Deletion
MalwareAuditCred

AuditCred can delete files from the system.

T1070.004
File Deletion
MalwareTONESHELL

TONESHELL has deleted payload files received from the C2 server.

T1070.004
File Deletion
MalwareUPSTYLE

UPSTYLE removes `bootstrap.min.css` after parsing command and control instructions, restoring the file to its original state.

T1070.004
File Deletion
MalwareOceanSalt

OceanSalt can delete files from the system.

T1070.004
File Deletion
MalwareMedusa Ransomware

Medusa Ransomware has the ability to delete itself after execution. Medusa Ransomware also has the ability to delete itself after execution through the command `cmd /c ping localhost -n 3 > nul & del`.

T1070.004
File Deletion
MalwareRainyDay

RainyDay has the ability to uninstall itself by deleting its service and files.

T1070.004
File Deletion
MalwareAppleSeed

AppleSeed can delete files from a compromised host after they are exfiltrated.

T1070.004
File Deletion
MalwarePyDCrypt

PyDCrypt will remove all created artifacts such as dropped executables.

T1070.004
File Deletion
MalwareGreyEnergy

GreyEnergy can securely delete a file by hooking into the DeleteFileA and DeleteFileW functions in the Windows API.

T1070.004
File Deletion
MalwareGomir

Gomir deletes its original executable and terminates its original process after creating a systemd service.

T1070.004
File Deletion
MalwareAria-body

Aria-body has the ability to delete files and directories on compromised hosts.

T1070.004
File Deletion
MalwareBOLDMOVE

BOLDMOVE can remove files on victim systems.

T1070.004
File Deletion
MalwareCrimson

Crimson has the ability to delete files from a compromised host.

T1070.004
File Deletion
MalwareBADHATCH

BADHATCH has the ability to delete PowerShell scripts from a compromised machine.

T1070.004
File Deletion
MalwareMachete

Once a file is uploaded, Machete will delete it from the machine.

T1070.004
File Deletion
MalwarePrikormka

After encrypting its own log files, the log encryption module in Prikormka deletes the original, unencrypted files from the host.

T1070.004
File Deletion
MalwareWoody RAT

Woody RAT has the ability to delete itself from disk by creating a suspended notepad process and writing shellcode to delete a file into the suspended process using `NtWriteVirtualMemory`.

T1070.004
File Deletion
MalwareShrinkLocker

ShrinkLocker can delete itself depending on various checks performed during execution.

T1070.004
File Deletion
MalwareHildegard

Hildegard has deleted scripts after execution.

T1070.004
File Deletion
MalwareSombRAT

SombRAT has the ability to run cancel or closeanddeletestorage to remove all files from storage and delete the storage temp file on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.