ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1070.004
File Deletion
MalwareStrifeWater

StrifeWater can self delete to cover its tracks.

T1070.004
File Deletion
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has deleted itself and the 'index.dat' file on a compromised machine to remove recent Internet history from the system.

T1070.004
File Deletion
MalwareFALLCHILL

FALLCHILL can delete malware and associated artifacts from the victim.

T1070.004
File Deletion
ToolSILENTTRINITY

SILENTTRINITY can remove files from the compromised host.

T1070.004
File Deletion
ToolPcShare

PcShare has deleted its files and components from a compromised host.

T1070.004
File Deletion
ToolCSPY Downloader

CSPY Downloader has the ability to self delete.

T1070.004
File Deletion
ToolRemcos

Remcos can delete files and folders from victim machines.

T1070.004
File Deletion
ToolImminent Monitor

Imminent Monitor has deleted files related to its dynamic debugger feature.

T1070.004
File Deletion
Toolcmd

cmd can be used to delete files from the file system.

T1070.004
File Deletion
ToolSDelete

SDelete deletes data in a way that makes it unrecoverable.

T1070.004
File Deletion
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has the ability to remove all staged files after exfiltration.

T1070.004
File Deletion
MalwareMini Shai-Hulud

Mini Shai-Hulud has deleted all artifacts to include gathered credential archives to reduce disk persistence and detection.

T1070.004
File Deletion
MalwareCanisterWorm

CanisterWorm has deleted itself after execution.

T1070.004
File Deletion
MalwareZeroCleare

ZeroCleare has the ability to uninstall the RawDisk driver and delete the `rwdsk` file on disk.

T1070.005
Network Share Connection Removal
GroupThreat Group-3390

Threat Group-3390 has detached network shares after exfiltrating files, likely to evade detection.

T1070.005
Network Share Connection Removal
MalwareRobbinHood

RobbinHood disconnects all network shares from the computer with the command net use * /DELETE /Y.

T1070.005
Network Share Connection Removal
MalwareDUSTTRAP

DUSTTRAP can remove network shares from infected systems.

T1070.005
Network Share Connection Removal
MalwareInvisiMole

InvisiMole can disconnect previously connected remote drives.

T1070.005
Network Share Connection Removal
ToolNet

The net use \\system\share /delete command can be used in Net to remove an established connection to a network share.

T1070.006
Timestomp
CampaignCutting Edge

During Cutting Edge, threat actors changed timestamps of multiple files on compromised Ivanti Secure Connect VPNs to conceal malicious activity.

T1070.006
Timestomp
CampaignC0032

During the C0032 campaign, TEMP.Veles used timestomping to modify the $STANDARD_INFORMATION attribute on tools.

T1070.006
Timestomp
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 modified timestamps of backdoors to match legitimate Windows files.

T1070.006
Timestomp
GroupAPT38

APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.

T1070.006
Timestomp
GroupKimsuky

Kimsuky has manipulated timestamps for creation or compilation dates to defeat anti-forensics.

T1070.006
Timestomp
GroupAPT32

APT32 has used scheduled task raw XML with a backdated timestamp of June 2, 2016. The group has also set the creation time of the files dropped by the second stage of the exploit to match the creation time of kernel32.dll. Additionally, APT32 has used a random value to modify the timestamp of the file storing the clientID.

T1070.006
Timestomp
GroupMustang Panda

Mustang Panda has modified file timestamps from the export address table (EAT) in malware to make it difficult to identify creation times.

T1070.006
Timestomp
GroupRocke

Rocke has changed the time stamp of certain files.

T1070.006
Timestomp
GroupUNC3886

UNC3886 has used scripts to timestomp ESXi hosts prior to installing malicious vSphere Installation Bundles (VIBs).

T1070.006
Timestomp
GroupAPT29

APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory.

T1070.006
Timestomp
GroupChimera

Chimera has used a Windows version of the Linux touch command to modify the date and time stamp on DLLs.

T1070.006
Timestomp
GroupAPT28

APT28 has performed timestomping on victim files.

T1070.006
Timestomp
GroupAPT5

APT5 has modified file timestamps.

T1070.006
Timestomp
GroupLazarus Group

Several Lazarus Group malware families use timestomping, including modifying the last write timestamp of a specified Registry key to a random date, as well as copying the timestamp for legitimate .exe files (such as calc.exe or mspaint.exe) to its dropped files.

T1070.006
Timestomp
MalwareBLINDINGCAN

BLINDINGCAN has modified file and directory timestamps.

T1070.006
Timestomp
MalwareNinja

Ninja can change or create the last access or write times.

T1070.006
Timestomp
MalwareStuxnet

Stuxnet extracts and writes driver files that match the times of other legitimate files.

T1070.006
Timestomp
MalwareSEASHARPEE

SEASHARPEE can timestomp files on victims using a Web shell.

T1070.006
Timestomp
MalwareTDTESS

After creating a new service for persistence, TDTESS sets the file creation time for the service to the creation time of the victim's legitimate svchost.exe file.

T1070.006
Timestomp
MalwareMisdat

Many Misdat samples were programmed using Borland Delphi, which will mangle the default PE compile timestamp of a file.

T1070.006
Timestomp
MalwareBankshot

Bankshot modifies the time of a file as specified by the control server.

T1070.006
Timestomp
MalwareUPSTYLE

UPSTYLE restores timestamps to original values following modification.

T1070.006
Timestomp
MalwareBOOKWORM

BOOKWORM has modified file timestamps from the export address table (EAT) to make it difficult to discern when the module was created.

T1070.006
Timestomp
MalwarePingPull

PingPull has the ability to timestomp a file.

T1070.006
Timestomp
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware can timestomp files for defense evasion and anti-forensics purposes.

T1070.006
Timestomp
MalwareInvisiMole

InvisiMole samples were timestomped by the authors by setting the PE timestamps to all zero values. InvisiMole also has a built-in command to modify file times.

T1070.006
Timestomp
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can time stomp its executable, previously dating it between 2010 to 2021.

T1070.006
Timestomp
MalwareChina Chopper

China Chopper's server component can change the timestamp of files.

T1070.006
Timestomp
MalwareKeyBoy

KeyBoy time-stomped its DLL in order to evade detection.

T1070.006
Timestomp
MalwarePOSHSPY

POSHSPY modifies timestamps of all downloaded executables to match a randomly selected file created prior to 2013.

T1070.006
Timestomp
MalwareMultiLayer Wiper

MultiLayer Wiper changes timestamps of overwritten files to either 1601.1.1 for NTFS filesystems, or 1980.1.1 for all other filesystems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.