Real-world descriptions of how a group, tool or campaign used a technique.
88 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1095 Non-Application Layer Protocol |
MalwareSDBbot | SDBbot has the ability to communicate with C2 with TCP over port 443. |
| T1095 Non-Application Layer Protocol |
MalwareDerusbi | Derusbi binds to a raw socket on a random source port between 31800 and 31900 for C2. |
| T1095 Non-Application Layer Protocol |
MalwareWellMail | WellMail can use TCP for C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareWINDSHIELD | WINDSHIELD C2 traffic can communicate via TCP raw sockets. |
| T1095 Non-Application Layer Protocol |
MalwareDrovorub | Drovorub can use TCP to communicate between its agent and client modules. |
| T1095 Non-Application Layer Protocol |
MalwareMoonWind | MoonWind completes network communication via raw sockets. |
| T1095 Non-Application Layer Protocol |
MalwareHiddenFace | HiddenFace can use a custom TCP protocol over Port 443 for C2. |
| T1095 Non-Application Layer Protocol |
MalwareCryptoistic | Cryptoistic can use TCP in communications with C2. |
| T1095 Non-Application Layer Protocol |
MalwareLunarMail | LunarMail can ping a specific C2 URL with the ID of a victim machine in the subdomain. |
| T1095 Non-Application Layer Protocol |
MalwareCobalt Strike | Cobalt Strike can be configured to use TCP, ICMP, and UDP for C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareSamurai | Samurai can use a proxy module to forward TCP packets to external hosts. |
| T1095 Non-Application Layer Protocol |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has used a custom binary protocol over port 443 for C2 traffic. |
| T1095 Non-Application Layer Protocol |
MalwareTaidoor | Taidoor can use TCP for C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareCarbon | Carbon uses TCP and UDP for C2. |
| T1095 Non-Application Layer Protocol |
MalwareNeo-reGeorg | Neo-reGeorg can create multiple TCP connections for a single session. |
| T1095 Non-Application Layer Protocol |
MalwareFakeM | Some variants of FakeM use SSL to communicate with C2 servers. |
| T1095 Non-Application Layer Protocol |
MalwareMacMa | MacMa has used a custom JSON-based protocol for its C&C communications. |
| T1095 Non-Application Layer Protocol |
MalwareFunnyDream | FunnyDream can communicate with C2 over TCP and UDP. |
| T1095 Non-Application Layer Protocol |
MalwareMOPSLED | MOPSLED can use a custom binary protocol over TCP for C2 communication. |
| T1095 Non-Application Layer Protocol |
MalwareLookBack | LookBack uses a custom binary protocol over sockets for C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareStealBit | StealBit can use the Windows Socket networking library to communicate with attacker-controlled endpoints. |
| T1095 Non-Application Layer Protocol |
MalwarePenquin | The Penquin C2 mechanism is based on TCP and UDP packets. |
| T1095 Non-Application Layer Protocol |
MalwareWinnti for Windows | Winnti for Windows can communicate using custom TCP. |
| T1095 Non-Application Layer Protocol |
MalwareZIPLINE | ZIPLINE can communicate with C2 using a custom binary protocol. |
| T1095 Non-Application Layer Protocol |
MalwaremetaMain | metaMain can establish an indirect and raw TCP socket-based connection to the C2 server. |
| T1095 Non-Application Layer Protocol |
MalwareMis-Type | Mis-Type network traffic can communicate over a raw socket. |
| T1095 Non-Application Layer Protocol |
MalwareStarProxy | StarProxy has used TCP for C2 communications to target IPs or domains. StarProxy contained code to support both UDP and TCP connections. |
| T1095 Non-Application Layer Protocol |
MalwareShadowPad | ShadowPad has used UDP for C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareQakBot | QakBot has the ability use TCP to send or receive C2 packets. |
| T1095 Non-Application Layer Protocol |
MalwareGelsemium | Gelsemium has the ability to use TCP and UDP in C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwarePHOREAL | PHOREAL communicates via ICMP for C2. |
| T1095 Non-Application Layer Protocol |
MalwareLizar | Lizar has used a raw TCP connection to communicate with the C2 server. |
| T1095 Non-Application Layer Protocol |
MalwareHiddenWasp | HiddenWasp communicates with a simple network protocol over TCP. |
| T1095 Non-Application Layer Protocol |
MalwareWarzoneRAT | WarzoneRAT can communicate with its C2 server via TCP over port 5200. |
| T1095 Non-Application Layer Protocol |
ToolFRP | FRP can communicate over TCP, TCP stream multiplexing, KERN Communications Protocol (KCP), QUIC, and UDP. |
| T1095 Non-Application Layer Protocol |
ToolBrute Ratel C4 | Brute Ratel C4 has the ability to use TCP for external C2. |
| T1095 Non-Application Layer Protocol |
ToolMythic | Mythic supports WebSocket and TCP-based C2 profiles. |
| T1095 Non-Application Layer Protocol |
ToolQuasarRAT | QuasarRAT can use TCP for C2 communication. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.