ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1070.004
File Deletion
MalwarePyDCrypt

PyDCrypt will remove all created artifacts such as dropped executables.

T1070.004
File Deletion
MalwareGreyEnergy

GreyEnergy can securely delete a file by hooking into the DeleteFileA and DeleteFileW functions in the Windows API.

T1070.004
File Deletion
MalwareGomir

Gomir deletes its original executable and terminates its original process after creating a systemd service.

T1070.004
File Deletion
MalwareAria-body

Aria-body has the ability to delete files and directories on compromised hosts.

T1070.004
File Deletion
MalwareBOLDMOVE

BOLDMOVE can remove files on victim systems.

T1070.004
File Deletion
MalwareCrimson

Crimson has the ability to delete files from a compromised host.

T1070.004
File Deletion
MalwareBADHATCH

BADHATCH has the ability to delete PowerShell scripts from a compromised machine.

T1070.004
File Deletion
MalwareMachete

Once a file is uploaded, Machete will delete it from the machine.

T1070.004
File Deletion
MalwarePrikormka

After encrypting its own log files, the log encryption module in Prikormka deletes the original, unencrypted files from the host.

T1070.004
File Deletion
MalwareWoody RAT

Woody RAT has the ability to delete itself from disk by creating a suspended notepad process and writing shellcode to delete a file into the suspended process using `NtWriteVirtualMemory`.

T1070.004
File Deletion
MalwareShrinkLocker

ShrinkLocker can delete itself depending on various checks performed during execution.

T1070.004
File Deletion
MalwareHildegard

Hildegard has deleted scripts after execution.

T1070.004
File Deletion
MalwareSombRAT

SombRAT has the ability to run cancel or closeanddeletestorage to remove all files from storage and delete the storage temp file on a compromised host.

T1070.004
File Deletion
MalwareODAgent

ODAgent can delete payloads and files used to pass C2 commands from remotely hosted cloud accounts.

T1070.004
File Deletion
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware deletes itself following device encryption.

T1070.004
File Deletion
MalwareFlawedAmmyy

FlawedAmmyy can execute batch scripts to delete files.

T1070.004
File Deletion
MalwareGuLoader

GuLoader can delete its executable from the AppData\Local\Temp directory on the compromised host.

T1070.004
File Deletion
MalwareProLock

ProLock can remove files containing its payload after they are executed.

T1070.004
File Deletion
MalwareInvisiMole

InvisiMole has deleted files and directories including XML and files successfully uploaded to C2 servers.

T1070.004
File Deletion
MalwareP.A.S. Webshell

P.A.S. Webshell can delete scripts from a subdirectory of /tmp after they are run.

T1070.004
File Deletion
MalwareApostle

Apostle writes batch scripts to disk, such as system.bat and remover.bat, that perform various anti-analysis and anti-forensic tasks, before finally deleting themselves at the end of execution. Apostle attempts to delete itself after encryption or wiping operations are complete and before shutting down the victim machine.

T1070.004
File Deletion
MalwareVolgmer

Volgmer can delete files and itself after infection to avoid analysis.

T1070.004
File Deletion
MalwareWhisperGate

WhisperGate can delete tools from a compromised host after execution.

T1070.004
File Deletion
MalwareFruitFly

FruitFly will delete files on the system.

T1070.004
File Deletion
MalwareAcidPour

AcidPour includes a self-delete function where the malware deletes itself from disk after execution and program load into memory.

T1070.004
File Deletion
MalwareRDAT

RDAT can issue SOAP requests to delete already processed C2 emails. RDAT can also delete itself from the infected system.

T1070.004
File Deletion
MalwareOkrum

Okrum's backdoor deletes files after they have been successfully uploaded to C2 servers.

T1070.004
File Deletion
MalwareSamSam

SamSam has been seen deleting its own files and payloads to make analysis of the attack more difficult.

T1070.004
File Deletion
MalwareRaspberry Robin

Raspberry Robin can delete its initial delivery script from disk during execution.

T1070.004
File Deletion
MalwareFysbis

Fysbis has the ability to delete files.

T1070.004
File Deletion
MalwareVERMIN

VERMIN can delete files on the victim’s machine.

T1070.004
File Deletion
MalwareNightdoor

Nightdoor can self-delete.

T1070.004
File Deletion
MalwareHTTPTroy

HTTPTroy can terminate its running process and then remove traces of itself through the `die <COMMAND>` command.

T1070.004
File Deletion
MalwarePowerShower

PowerShower has the ability to remove all files created during the dropper process.

T1070.004
File Deletion
MalwareKazuar

Kazuar can delete files.

T1070.004
File Deletion
MalwareFatDuke

FatDuke can secure delete its DLL.

T1070.004
File Deletion
MalwarezwShell

zwShell has deleted itself after creating a service as well as deleted a temporary file when the system reboots.

T1070.004
File Deletion
MalwareRising Sun

Rising Sun can delete files and artifacts it creates.

T1070.004
File Deletion
MalwareShimRat

ShimRat can uninstall itself from compromised hosts, as well create and modify directories, delete, move, copy, and rename files.

T1070.004
File Deletion
MalwareHi-Zor

Hi-Zor deletes its RAT installer file as it executes its DLL payload file.

T1070.004
File Deletion
MalwareXAgentOSX

XAgentOSX contains the deletFileFromPath function to delete a specified file using the NSFileManager:removeFileAtPath method.

T1070.004
File Deletion
MalwareGreen Lambert

Green Lambert can delete the original executable after initial installation in addition to unused functions.

T1070.004
File Deletion
MalwareLockerGoga

LockerGoga has been observed deleting its original launcher after execution.

T1070.004
File Deletion
MalwarePUNCHBUGGY

PUNCHBUGGY can delete files written to disk.

T1070.004
File Deletion
MalwareHyperBro

HyperBro has the ability to delete a specified file.

T1070.004
File Deletion
MalwareAnchor

Anchor can self delete its dropper after the malware is successfully deployed.

T1070.004
File Deletion
MalwareLine Runner

Line Runner removes its initial ZIP delivery archive after processing the enclosed LUA script.

T1070.004
File Deletion
MalwarePteranodon

Pteranodon can delete files that may interfere with it executing. It also can delete temporary files and itself after the initial script executes.

T1070.004
File Deletion
MalwareBeaverTail

BeaverTail has deleted files from a compromised host after they were exfiltrated.

T1070.004
File Deletion
MalwareROKRAT

ROKRAT can request to delete files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.