ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1071.001×

344 examples

TechniqueUsed byProcedure example
T1071.001
Web Protocols
MalwareCosmicDuke

CosmicDuke can use HTTP or HTTPS for command and control to hard-coded C2 servers.

T1071.001
Web Protocols
MalwareGreyEnergy

GreyEnergy uses HTTP and HTTPS for C2 communications.

T1071.001
Web Protocols
MalwareGomir

Gomir periodically communicates to its command and control infrastructure through HTTP POST requests.

T1071.001
Web Protocols
MalwareAria-body

Aria-body has used HTTP in C2 communications.

T1071.001
Web Protocols
MalwareEmotet

Emotet has used HTTP for command and control.

T1071.001
Web Protocols
MalwareSNUGRIDE

SNUGRIDE communicates with its C2 server over HTTP.

T1071.001
Web Protocols
MalwareBOLDMOVE

BOLDMOVE uses web services for command and control communication.

T1071.001
Web Protocols
MalwareCrimson

Crimson can use a HTTP GET request to download its final payload.

T1071.001
Web Protocols
MalwareTomiris

Tomiris can use HTTP to establish C2 communications.

T1071.001
Web Protocols
MalwareTurian

Turian has the ability to use HTTP for its C2.

T1071.001
Web Protocols
MalwareTHINCRUST

THINCRUST can use HTTP POST requests in C2 communications.

T1071.001
Web Protocols
MalwareBADHATCH

BADHATCH can use HTTP and HTTPS over port 443 to communicate with actor-controlled C2 servers.

T1071.001
Web Protocols
MalwareMachete

Machete uses HTTP for Command & Control.

T1071.001
Web Protocols
MalwareAction RAT

Action RAT can use HTTP to communicate with C2 servers.

T1071.001
Web Protocols
MalwareAvenger

Avenger has the ability to use HTTP in communication with C2.

T1071.001
Web Protocols
MalwarePUBLOAD

PUBLOAD has communicated via `curl` over HTTP to identify device IP data. PUBLOAD has also utilized HTTP for a command-and-control protocol through HTTP POST. PUBLOAD has also leveraged HTTPS for C2.

T1071.001
Web Protocols
MalwarePingPull

A PingPull variant can communicate with its C2 servers by using HTTPS.

T1071.001
Web Protocols
MalwareWellMess

WellMess can use HTTP and HTTPS in C2 communications.

T1071.001
Web Protocols
MalwareDacls

Dacls can use HTTPS in C2 communications.

T1071.001
Web Protocols
MalwareWoody RAT

Woody RAT can communicate with its C2 server using HTTP requests.

T1071.001
Web Protocols
MalwareMafalda

Mafalda can use HTTP for C2.

T1071.001
Web Protocols
MalwareSquirrelwaffle

Squirrelwaffle has used HTTP POST requests for C2 communications.

T1071.001
Web Protocols
MalwareELMER

ELMER uses HTTP for command and control.

T1071.001
Web Protocols
MalwarePolyglotDuke

PolyglotDuke has has used HTTP GET requests in C2 communications.

T1071.001
Web Protocols
MalwareHexEval Loader

HexEval Loader has used HTTP and HTTPS POST requests to communicate with C2.

T1071.001
Web Protocols
MalwareAuTo Stealer

AuTo Stealer can use HTTP to communicate with its C2 servers.

T1071.001
Web Protocols
MalwareShrinkLocker

ShrinkLocker uses HTTP POST requests to communicate victim information back to the threat actor.

T1071.001
Web Protocols
MalwareFlawedAmmyy

FlawedAmmyy has used HTTP for C2.

T1071.001
Web Protocols
MalwareCuckoo Stealer

Cuckoo Stealer can use the curl API for C2 communications.

T1071.001
Web Protocols
MalwareGuLoader

GuLoader can use HTTP to retrieve additional binaries.

T1071.001
Web Protocols
MalwareInvisiMole

InvisiMole uses HTTP for C2 communications.

T1071.001
Web Protocols
MalwareP.A.S. Webshell

P.A.S. Webshell can issue commands via HTTP POST.

T1071.001
Web Protocols
MalwareWhisperGate

WhisperGate can make an HTTPS connection to download additional files.

T1071.001
Web Protocols
MalwareZeroT

ZeroT has used HTTP for C2.

T1071.001
Web Protocols
MalwareKeydnap

Keydnap uses HTTPS for command and control.

T1071.001
Web Protocols
MalwareRDAT

RDAT can use HTTP communications for C2, as well as using the WinHTTP library to make requests to the Exchange Web Services API.

T1071.001
Web Protocols
MalwareOkrum

Okrum uses HTTP for communication with its C2.

T1071.001
Web Protocols
MalwareTRANSLATEXT

TRANSLATEXT has used HTTP to communicate with the C2 server.

T1071.001
Web Protocols
MalwareRegin

The Regin malware platform supports many standard protocols, including HTTP and HTTPS.

T1071.001
Web Protocols
MalwareLine Dancer

Line Dancer uses HTTP POST requests to interact with compromised devices.

T1071.001
Web Protocols
MalwareNeoichor

Neoichor can use HTTP for C2 communications.

T1071.001
Web Protocols
MalwareRaspberry Robin

Raspberry Robin uses outbound HTTP requests containing victim information for retrieving second stage payloads. Variants of Raspberry Robin can download archive files (such as 7-Zip files) via the victim web browser for second stage execution.

T1071.001
Web Protocols
MalwareDiavol

Diavol has used HTTP GET and POST requests for C2.

T1071.001
Web Protocols
MalwareDoki

Doki has communicated with C2 over HTTPS.

T1071.001
Web Protocols
MalwareRustyWater

RustyWater has used the Rust request library for HTTP C2 communication.

T1071.001
Web Protocols
MalwareIcedID

IcedID has used HTTPS in communications with C2.

T1071.001
Web Protocols
MalwareVERMIN

VERMIN uses HTTP for C2 communications.

T1071.001
Web Protocols
MalwareUBoatRAT

UBoatRAT has used HTTP for C2 communications.

T1071.001
Web Protocols
MalwareHTTPTroy

HTTPTroy has used HTTP POST requests to communicate with C2.

T1071.001
Web Protocols
MalwareMarkiRAT

MarkiRAT can initiate communication over HTTP/HTTPS for its C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.