Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1070.004 File Deletion |
MalwarePyDCrypt | PyDCrypt will remove all created artifacts such as dropped executables. |
| T1070.004 File Deletion |
MalwareGreyEnergy | GreyEnergy can securely delete a file by hooking into the DeleteFileA and DeleteFileW functions in the Windows API. |
| T1070.004 File Deletion |
MalwareGomir | Gomir deletes its original executable and terminates its original process after creating a systemd service. |
| T1070.004 File Deletion |
MalwareAria-body | Aria-body has the ability to delete files and directories on compromised hosts. |
| T1070.004 File Deletion |
MalwareBOLDMOVE | BOLDMOVE can remove files on victim systems. |
| T1070.004 File Deletion |
MalwareCrimson | Crimson has the ability to delete files from a compromised host. |
| T1070.004 File Deletion |
MalwareBADHATCH | BADHATCH has the ability to delete PowerShell scripts from a compromised machine. |
| T1070.004 File Deletion |
MalwareMachete | Once a file is uploaded, Machete will delete it from the machine. |
| T1070.004 File Deletion |
MalwarePrikormka | After encrypting its own log files, the log encryption module in Prikormka deletes the original, unencrypted files from the host. |
| T1070.004 File Deletion |
MalwareWoody RAT | Woody RAT has the ability to delete itself from disk by creating a suspended notepad process and writing shellcode to delete a file into the suspended process using `NtWriteVirtualMemory`. |
| T1070.004 File Deletion |
MalwareShrinkLocker | ShrinkLocker can delete itself depending on various checks performed during execution. |
| T1070.004 File Deletion |
MalwareHildegard | Hildegard has deleted scripts after execution. |
| T1070.004 File Deletion |
MalwareSombRAT | SombRAT has the ability to run |
| T1070.004 File Deletion |
MalwareODAgent | ODAgent can delete payloads and files used to pass C2 commands from remotely hosted cloud accounts. |
| T1070.004 File Deletion |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware deletes itself following device encryption. |
| T1070.004 File Deletion |
MalwareFlawedAmmyy | FlawedAmmyy can execute batch scripts to delete files. |
| T1070.004 File Deletion |
MalwareGuLoader | GuLoader can delete its executable from the |
| T1070.004 File Deletion |
MalwareProLock | ProLock can remove files containing its payload after they are executed. |
| T1070.004 File Deletion |
MalwareInvisiMole | InvisiMole has deleted files and directories including XML and files successfully uploaded to C2 servers. |
| T1070.004 File Deletion |
MalwareP.A.S. Webshell | P.A.S. Webshell can delete scripts from a subdirectory of /tmp after they are run. |
| T1070.004 File Deletion |
MalwareApostle | Apostle writes batch scripts to disk, such as |
| T1070.004 File Deletion |
MalwareVolgmer | Volgmer can delete files and itself after infection to avoid analysis. |
| T1070.004 File Deletion |
MalwareWhisperGate | WhisperGate can delete tools from a compromised host after execution. |
| T1070.004 File Deletion |
MalwareFruitFly | FruitFly will delete files on the system. |
| T1070.004 File Deletion |
MalwareAcidPour | AcidPour includes a self-delete function where the malware deletes itself from disk after execution and program load into memory. |
| T1070.004 File Deletion |
MalwareRDAT | RDAT can issue SOAP requests to delete already processed C2 emails. RDAT can also delete itself from the infected system. |
| T1070.004 File Deletion |
MalwareOkrum | Okrum's backdoor deletes files after they have been successfully uploaded to C2 servers. |
| T1070.004 File Deletion |
MalwareSamSam | SamSam has been seen deleting its own files and payloads to make analysis of the attack more difficult. |
| T1070.004 File Deletion |
MalwareRaspberry Robin | Raspberry Robin can delete its initial delivery script from disk during execution. |
| T1070.004 File Deletion |
MalwareFysbis | Fysbis has the ability to delete files. |
| T1070.004 File Deletion |
MalwareVERMIN | VERMIN can delete files on the victim’s machine. |
| T1070.004 File Deletion |
MalwareNightdoor | Nightdoor can self-delete. |
| T1070.004 File Deletion |
MalwareHTTPTroy | HTTPTroy can terminate its running process and then remove traces of itself through the `die <COMMAND>` command. |
| T1070.004 File Deletion |
MalwarePowerShower | PowerShower has the ability to remove all files created during the dropper process. |
| T1070.004 File Deletion |
MalwareKazuar | Kazuar can delete files. |
| T1070.004 File Deletion |
MalwareFatDuke | FatDuke can secure delete its DLL. |
| T1070.004 File Deletion |
MalwarezwShell | zwShell has deleted itself after creating a service as well as deleted a temporary file when the system reboots. |
| T1070.004 File Deletion |
MalwareRising Sun | Rising Sun can delete files and artifacts it creates. |
| T1070.004 File Deletion |
MalwareShimRat | ShimRat can uninstall itself from compromised hosts, as well create and modify directories, delete, move, copy, and rename files. |
| T1070.004 File Deletion |
MalwareHi-Zor | Hi-Zor deletes its RAT installer file as it executes its DLL payload file. |
| T1070.004 File Deletion |
MalwareXAgentOSX | XAgentOSX contains the deletFileFromPath function to delete a specified file using the NSFileManager:removeFileAtPath method. |
| T1070.004 File Deletion |
MalwareGreen Lambert | Green Lambert can delete the original executable after initial installation in addition to unused functions. |
| T1070.004 File Deletion |
MalwareLockerGoga | LockerGoga has been observed deleting its original launcher after execution. |
| T1070.004 File Deletion |
MalwarePUNCHBUGGY | PUNCHBUGGY can delete files written to disk. |
| T1070.004 File Deletion |
MalwareHyperBro | HyperBro has the ability to delete a specified file. |
| T1070.004 File Deletion |
MalwareAnchor | Anchor can self delete its dropper after the malware is successfully deployed. |
| T1070.004 File Deletion |
MalwareLine Runner | Line Runner removes its initial ZIP delivery archive after processing the enclosed LUA script. |
| T1070.004 File Deletion |
MalwarePteranodon | Pteranodon can delete files that may interfere with it executing. It also can delete temporary files and itself after the initial script executes. |
| T1070.004 File Deletion |
MalwareBeaverTail | BeaverTail has deleted files from a compromised host after they were exfiltrated. |
| T1070.004 File Deletion |
MalwareROKRAT | ROKRAT can request to delete files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.