ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1070.004×

251 examples

TechniqueUsed byProcedure example
T1070.004
File Deletion
MalwareODAgent

ODAgent can delete payloads and files used to pass C2 commands from remotely hosted cloud accounts.

T1070.004
File Deletion
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware deletes itself following device encryption.

T1070.004
File Deletion
MalwareFlawedAmmyy

FlawedAmmyy can execute batch scripts to delete files.

T1070.004
File Deletion
MalwareGuLoader

GuLoader can delete its executable from the AppData\Local\Temp directory on the compromised host.

T1070.004
File Deletion
MalwareProLock

ProLock can remove files containing its payload after they are executed.

T1070.004
File Deletion
MalwareInvisiMole

InvisiMole has deleted files and directories including XML and files successfully uploaded to C2 servers.

T1070.004
File Deletion
MalwareP.A.S. Webshell

P.A.S. Webshell can delete scripts from a subdirectory of /tmp after they are run.

T1070.004
File Deletion
MalwareApostle

Apostle writes batch scripts to disk, such as system.bat and remover.bat, that perform various anti-analysis and anti-forensic tasks, before finally deleting themselves at the end of execution. Apostle attempts to delete itself after encryption or wiping operations are complete and before shutting down the victim machine.

T1070.004
File Deletion
MalwareVolgmer

Volgmer can delete files and itself after infection to avoid analysis.

T1070.004
File Deletion
MalwareWhisperGate

WhisperGate can delete tools from a compromised host after execution.

T1070.004
File Deletion
MalwareFruitFly

FruitFly will delete files on the system.

T1070.004
File Deletion
MalwareAcidPour

AcidPour includes a self-delete function where the malware deletes itself from disk after execution and program load into memory.

T1070.004
File Deletion
MalwareRDAT

RDAT can issue SOAP requests to delete already processed C2 emails. RDAT can also delete itself from the infected system.

T1070.004
File Deletion
MalwareOkrum

Okrum's backdoor deletes files after they have been successfully uploaded to C2 servers.

T1070.004
File Deletion
MalwareSamSam

SamSam has been seen deleting its own files and payloads to make analysis of the attack more difficult.

T1070.004
File Deletion
MalwareRaspberry Robin

Raspberry Robin can delete its initial delivery script from disk during execution.

T1070.004
File Deletion
MalwareFysbis

Fysbis has the ability to delete files.

T1070.004
File Deletion
MalwareVERMIN

VERMIN can delete files on the victim’s machine.

T1070.004
File Deletion
MalwareNightdoor

Nightdoor can self-delete.

T1070.004
File Deletion
MalwareHTTPTroy

HTTPTroy can terminate its running process and then remove traces of itself through the `die <COMMAND>` command.

T1070.004
File Deletion
MalwarePowerShower

PowerShower has the ability to remove all files created during the dropper process.

T1070.004
File Deletion
MalwareKazuar

Kazuar can delete files.

T1070.004
File Deletion
MalwareFatDuke

FatDuke can secure delete its DLL.

T1070.004
File Deletion
MalwarezwShell

zwShell has deleted itself after creating a service as well as deleted a temporary file when the system reboots.

T1070.004
File Deletion
MalwareRising Sun

Rising Sun can delete files and artifacts it creates.

T1070.004
File Deletion
MalwareShimRat

ShimRat can uninstall itself from compromised hosts, as well create and modify directories, delete, move, copy, and rename files.

T1070.004
File Deletion
MalwareHi-Zor

Hi-Zor deletes its RAT installer file as it executes its DLL payload file.

T1070.004
File Deletion
MalwareXAgentOSX

XAgentOSX contains the deletFileFromPath function to delete a specified file using the NSFileManager:removeFileAtPath method.

T1070.004
File Deletion
MalwareGreen Lambert

Green Lambert can delete the original executable after initial installation in addition to unused functions.

T1070.004
File Deletion
MalwareLockerGoga

LockerGoga has been observed deleting its original launcher after execution.

T1070.004
File Deletion
MalwarePUNCHBUGGY

PUNCHBUGGY can delete files written to disk.

T1070.004
File Deletion
MalwareHyperBro

HyperBro has the ability to delete a specified file.

T1070.004
File Deletion
MalwareAnchor

Anchor can self delete its dropper after the malware is successfully deployed.

T1070.004
File Deletion
MalwareLine Runner

Line Runner removes its initial ZIP delivery archive after processing the enclosed LUA script.

T1070.004
File Deletion
MalwarePteranodon

Pteranodon can delete files that may interfere with it executing. It also can delete temporary files and itself after the initial script executes.

T1070.004
File Deletion
MalwareBeaverTail

BeaverTail has deleted files from a compromised host after they were exfiltrated.

T1070.004
File Deletion
MalwareROKRAT

ROKRAT can request to delete files.

T1070.004
File Deletion
MalwareRunningRAT

RunningRAT contains code to delete files from the victim’s machine.

T1070.004
File Deletion
MalwareExbyte

Exbyte will self-delete if a hard-coded configuration file is not found.

T1070.004
File Deletion
MalwareDarkWatchman

DarkWatchman has been observed deleting its original launcher after installation.

T1070.004
File Deletion
MalwareBBSRAT

BBSRAT can delete files and directories.

T1070.004
File Deletion
MalwarePlugX

PlugX has the remove itself and other artifacts.

T1070.004
File Deletion
MalwareReaver

Reaver deletes the original dropped file from the victim.

T1070.004
File Deletion
MalwareBisonal

Bisonal will delete its dropper and VBS scripts from the victim’s machine.

T1070.004
File Deletion
MalwareMultiLayer Wiper

MultiLayer Wiper uses a batch file, remover.bat to delete malware artifacts and the batch file itself during execution.

T1070.004
File Deletion
MalwareNOOPLDR

NOOPLDR can delete a file containing configuration instructions after use.

T1070.004
File Deletion
MalwareS-Type

S-Type has deleted files it has created on a compromised host.

T1070.004
File Deletion
MalwareSeaDuke

SeaDuke can securely delete files, including deleting itself from the victim.

T1070.004
File Deletion
MalwareDustySky

DustySky can delete files it creates from the infected system.

T1070.004
File Deletion
MalwareRemsec

Remsec is capable of deleting files on the victim. It also securely removes itself after collecting and exfiltrating data.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.