ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1070.006
Timestomp
MalwareElise

Elise performs timestomping of a CAB file it creates.

T1070.006
Timestomp
MalwareGazer

For early Gazer versions, the compilation timestamp was faked.

T1070.006
Timestomp
Malware3PARA RAT

3PARA RAT has a command to set certain attributes such as creation/modification timestamps on files.

T1070.006
Timestomp
MalwareEVILNUM

EVILNUM has changed the creation date of files.

T1070.006
Timestomp
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can change the timestamp of specified filenames.

T1070.006
Timestomp
MalwareShamoon

Shamoon can change the modified time for files to evade forensic detection.

T1070.006
Timestomp
MalwareBPFDoor

BPFDoor uses the `utimes()` function to change the executable's timestamp.

T1070.006
Timestomp
MalwareAttor

Attor has manipulated the time of last access to files and registry keys after they have been created or modified.

T1070.006
Timestomp
MalwareNightClub

NightClub can modify the Creation, Access, and Write timestamps for malicious DLLs to match those of the genuine Windows DLL user32.dll.

T1070.006
Timestomp
MalwareDerusbi

The Derusbi malware supports timestomping.

T1070.006
Timestomp
MalwareKobalos

Kobalos can modify timestamps of replaced files, such as ssh with the added credential stealer or sshd used to deploy Kobalos.

T1070.006
Timestomp
MalwareHiddenFace

HiddenFace can alter timestamps for directory content on targeted machines.

T1070.006
Timestomp
MalwareOwaAuth

OwaAuth has a command to timestop a file or directory.

T1070.006
Timestomp
MalwareCobalt Strike

Cobalt Strike can timestomp any files or payloads placed on a target machine to help them blend in.

T1070.006
Timestomp
MalwareUSBStealer

USBStealer sets the timestamps of its dropper files to the last-access and last-write timestamps of a standard Windows library chosen on the system.

T1070.006
Timestomp
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D can use the touch -t command to change timestamps.

T1070.006
Timestomp
MalwareCyclops Blink

Cyclops Blink has the ability to use the Linux API function `utime` to change the timestamps of modified firmware update images.

T1070.006
Timestomp
MalwareMacMa

MacMa has the capability to create and modify file timestamps.

T1070.006
Timestomp
MalwareSPAWNCHIMERA

SPAWNCHIMERA has updated the timestamp using the `touch` command.

T1070.006
Timestomp
MalwareWinnti for Windows

Winnti for Windows can set the timestamps for its worker and service components to match that of cmd.exe.

T1070.006
Timestomp
MalwarePowerStallion

PowerStallion modifies the MAC times of its local log files to match that of the victim's desktop.ini file.

T1070.006
Timestomp
MalwaremetaMain

metaMain can change the `CreationTime`, `LastAccessTime`, and `LastWriteTime` file time attributes when executed with `SYSTEM` privileges.

T1070.006
Timestomp
MalwarePsylo

Psylo has a command to conduct timestomping by setting a specified file’s timestamps to match those of a system file in the System32 directory.

T1070.006
Timestomp
MalwareGelsemium

Gelsemium has the ability to perform timestomping of files on targeted systems.

T1070.006
Timestomp
MalwareBitPaymer

BitPaymer can modify the timestamp of an executable so that it can be identified and restored by the decryption tool.

T1070.006
Timestomp
MalwareFALLCHILL

FALLCHILL can modify file or directory timestamps.

T1070.006
Timestomp
ToolEmpire

Empire can timestomp any files or payloads placed on a target machine to help them blend in.

T1070.007
Clear Network Connection History and Configurations
CampaignRedPenguin

During RedPenguin, UNC3886 used an implant to delete logs associated with unauthorized access to targeted Junos OS devices.

T1070.007
Clear Network Connection History and Configurations
GroupVolt Typhoon

Volt Typhoon has inspected server logs to remove their IPs.

T1070.007
Clear Network Connection History and Configurations
GroupUNC3886

UNC3886 has cleared specific events that contained the threat actor’s IP address from multiple log sources.

T1070.007
Clear Network Connection History and Configurations
MalwareSUNBURST

SUNBURST also removed the firewall rules it created during execution.

T1070.008
Clear Mailbox Data
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 removed evidence of email export requests using `Remove-MailboxExportRequest`.

T1070.008
Clear Mailbox Data
GroupScattered Spider

Scattered Spider has manually deleted emails notifying users of suspicious account activity.

T1070.008
Clear Mailbox Data
GroupAPT42

APT42 has deleted login notification emails and has cleared the Sent folder to cover their tracks.

T1070.008
Clear Mailbox Data
MalwareLunarMail

LunarMail can set the `PR_DELETE_AFTER_SUBMIT` flag to delete messages sent for data exfiltration.

T1070.008
Clear Mailbox Data
MalwareGoopy

Goopy has the ability to delete emails used for C2 once the content has been copied.

T1070.009
Clear Persistence
MalwareMisdat

Misdat is capable of deleting Registry keys used for persistence.

T1070.009
Clear Persistence
MalwareRaspberry Robin

Raspberry Robin uses a RunOnce Registry key for persistence, where the key is removed after its use on reboot then re-added by the malware after it resumes execution.

T1070.009
Clear Persistence
MalwareSplatDropper

SplatDropper has deleted its malicious payload and removed its own created service to avoid leaving traces of its presence on victim devices.

T1070.009
Clear Persistence
MalwarePlugX

PlugX has deleted registry keys that store data and maintained persistence.

T1070.009
Clear Persistence
MalwareS-Type

S-Type has deleted accounts it has created.

T1070.009
Clear Persistence
MalwareRTM

RTM has the ability to remove Registry entries that it created for persistence.

T1070.009
Clear Persistence
MalwareBazar

Bazar's loader can delete scheduled tasks created by a previous instance of the malware.

T1070.009
Clear Persistence
MalwareKapeka

Kapeka will clear registry values used for persistent configuration storage when uninstalled.

T1070.009
Clear Persistence
MalwareSUNBURST

SUNBURST removed IFEO registry values to clean up traces of persistence.

T1070.009
Clear Persistence
MalwareIPsec Helper

IPsec Helper can delete various service traces related to persistent execution when commanded.

T1070.009
Clear Persistence
MalwarePillowmint

Pillowmint can uninstall the malicious service from an infected machine.

T1070.009
Clear Persistence
MalwareGrimAgent

GrimAgent can delete previously created tasks on a compromised host.

T1070.009
Clear Persistence
MalwarenjRAT

njRAT is capable of manipulating and deleting registry keys, including those used for persistence.

T1070.009
Clear Persistence
MalwareKOCTOPUS

KOCTOPUS can delete created registry keys used for persistence as part of its cleanup procedure.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.