Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1070.004 File Deletion |
MalwareFunnyDream | FunnyDream can delete files including its dropper component. |
| T1070.004 File Deletion |
MalwareROADSWEEP | ROADSWEEP can use embedded scripts to remove itself from the infected host. |
| T1070.004 File Deletion |
MalwareSUNSPOT | Following the successful injection of SUNBURST, SUNSPOT deleted a temporary file it created named |
| T1070.004 File Deletion |
MalwareMore_eggs | More_eggs can remove itself from a system. |
| T1070.004 File Deletion |
MalwareSysUpdate | SysUpdate can delete its configuration file from the targeted system. |
| T1070.004 File Deletion |
MalwareOutSteel | OutSteel can delete itself following the successful execution of a follow-on payload. |
| T1070.004 File Deletion |
MalwareBackConfig | BackConfig has the ability to remove files and folders related to previous infections. |
| T1070.004 File Deletion |
MalwareProton | Proton removes all files in the /tmp directory. |
| T1070.004 File Deletion |
MalwareInnaputRAT | InnaputRAT has a command to delete files. |
| T1070.004 File Deletion |
MalwareGrimAgent | GrimAgent can delete old binaries on a compromised host. |
| T1070.004 File Deletion |
MalwareLookBack | LookBack removes itself after execution and can delete files on the system. |
| T1070.004 File Deletion |
MalwareLokibot | Lokibot will delete its dropped files after bypassing UAC. |
| T1070.004 File Deletion |
MalwarePoetRAT | PoetRAT has the ability to overwrite scripts and delete itself if a sandbox environment is detected. |
| T1070.004 File Deletion |
MalwareStealBit | StealBit can self-delete its executable file from the compromised system. |
| T1070.004 File Deletion |
MalwareFELIXROOT | FELIXROOT deletes the .LNK file from the startup directory as well as the dropper components. |
| T1070.004 File Deletion |
MalwareZxShell | ZxShell can delete files from the system. |
| T1070.004 File Deletion |
MalwarePenquin | Penquin can delete downloaded executables after running them. |
| T1070.004 File Deletion |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has deleted generated files and folders from victim devices. |
| T1070.004 File Deletion |
MalwareBabyShark | BabyShark has cleaned up all files associated with the secondary payload execution. |
| T1070.004 File Deletion |
MalwareWinnti for Windows | Winnti for Windows can delete the DLLs for its various components from a compromised host. |
| T1070.004 File Deletion |
MalwareTroll Stealer | Troll Stealer creates and can execute a BAT script that will delete the malware. |
| T1070.004 File Deletion |
MalwareBLACKCOFFEE | BLACKCOFFEE has the capability to delete files. |
| T1070.004 File Deletion |
MalwareMeteor | Meteor will delete the folder containing malicious scripts if it detects the hostname as `PIS-APP`, `PIS-MOB`, `WSUSPROXY`, or `PIS-DB`. |
| T1070.004 File Deletion |
MalwarenjRAT | njRAT is capable of deleting files. |
| T1070.004 File Deletion |
MalwareIceApple | IceApple can delete files and directories from targeted systems. |
| T1070.004 File Deletion |
MalwareJPIN | JPIN's installer/uninstaller component deletes itself if it encounters a version of Windows earlier than Windows XP or identifies security-related processes running. |
| T1070.004 File Deletion |
MalwaremetaMain | metaMain has deleted collected items after uploading the content to its C2 server. |
| T1070.004 File Deletion |
MalwareHeyoka Backdoor | Heyoka Backdoor has the ability to delete folders and files from a targeted system. |
| T1070.004 File Deletion |
MalwareHTTPBrowser | HTTPBrowser deletes its original installer file once installation is complete. |
| T1070.004 File Deletion |
MalwareLunarWeb | LunarWeb can self-delete from a compromised host if safety checks of C2 connectivity fail. |
| T1070.004 File Deletion |
MalwareKillDisk | KillDisk has the ability to quit and delete itself. |
| T1070.004 File Deletion |
MalwareQilin | Qilin can delete itself from infected hosts after execution. |
| T1070.004 File Deletion |
MalwareAppleJeus | AppleJeus has deleted the MSI file after installation. |
| T1070.004 File Deletion |
MalwareKevin | Kevin can delete files created on the victim's machine. |
| T1070.004 File Deletion |
MalwarePasam | Pasam creates a backdoor through which remote attackers can delete files. |
| T1070.004 File Deletion |
MalwarePOWERSTATS | POWERSTATS can delete all files on the C:\, D:\, E:\ and, F:\ drives using PowerShell Remove-Item commands. |
| T1070.004 File Deletion |
MalwareECCENTRICBANDWAGON | ECCENTRICBANDWAGON can delete log files generated from the malware stored at |
| T1070.004 File Deletion |
MalwareLinfo | Linfo creates a backdoor through which remote attackers can delete files. |
| T1070.004 File Deletion |
MalwareQakBot | QakBot can delete folders and files including overwriting its executable with legitimate programs. |
| T1070.004 File Deletion |
MalwareDOWNIISSA | DOWNIISSA can delete files after download. |
| T1070.004 File Deletion |
MalwareHancitor | Hancitor has deleted files using the VBA |
| T1070.004 File Deletion |
MalwareGelsemium | Gelsemium can delete its dropper component from the targeted system. |
| T1070.004 File Deletion |
MalwarejRAT | jRAT has a function to delete files from the victim’s machine. |
| T1070.004 File Deletion |
MalwareKomplex | The Komplex trojan supports file deletion. |
| T1070.004 File Deletion |
MalwareDenis | Denis has a command to delete files from the victim’s machine. |
| T1070.004 File Deletion |
MalwareMacSpy | MacSpy deletes any temporary files it creates |
| T1070.004 File Deletion |
MalwareDtrack | Dtrack can remove its persistence and delete itself. |
| T1070.004 File Deletion |
MalwareLoudMiner | LoudMiner deleted installation files after completion. |
| T1070.004 File Deletion |
MalwareAzorult | Azorult can delete files from victim machines. |
| T1070.004 File Deletion |
MalwareADVSTORESHELL | ADVSTORESHELL can delete files and directories. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.