ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1095×

88 examples

TechniqueUsed byProcedure example
T1095
Non-Application Layer Protocol
MalwareSDBbot

SDBbot has the ability to communicate with C2 with TCP over port 443.

T1095
Non-Application Layer Protocol
MalwareDerusbi

Derusbi binds to a raw socket on a random source port between 31800 and 31900 for C2.

T1095
Non-Application Layer Protocol
MalwareWellMail

WellMail can use TCP for C2 communications.

T1095
Non-Application Layer Protocol
MalwareWINDSHIELD

WINDSHIELD C2 traffic can communicate via TCP raw sockets.

T1095
Non-Application Layer Protocol
MalwareDrovorub

Drovorub can use TCP to communicate between its agent and client modules.

T1095
Non-Application Layer Protocol
MalwareMoonWind

MoonWind completes network communication via raw sockets.

T1095
Non-Application Layer Protocol
MalwareHiddenFace

HiddenFace can use a custom TCP protocol over Port 443 for C2.

T1095
Non-Application Layer Protocol
MalwareCryptoistic

Cryptoistic can use TCP in communications with C2.

T1095
Non-Application Layer Protocol
MalwareLunarMail

LunarMail can ping a specific C2 URL with the ID of a victim machine in the subdomain.

T1095
Non-Application Layer Protocol
MalwareCobalt Strike

Cobalt Strike can be configured to use TCP, ICMP, and UDP for C2 communications.

T1095
Non-Application Layer Protocol
MalwareSamurai

Samurai can use a proxy module to forward TCP packets to external hosts.

T1095
Non-Application Layer Protocol
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has used a custom binary protocol over port 443 for C2 traffic.

T1095
Non-Application Layer Protocol
MalwareTaidoor

Taidoor can use TCP for C2 communications.

T1095
Non-Application Layer Protocol
MalwareCarbon

Carbon uses TCP and UDP for C2.

T1095
Non-Application Layer Protocol
MalwareNeo-reGeorg

Neo-reGeorg can create multiple TCP connections for a single session.

T1095
Non-Application Layer Protocol
MalwareFakeM

Some variants of FakeM use SSL to communicate with C2 servers.

T1095
Non-Application Layer Protocol
MalwareMacMa

MacMa has used a custom JSON-based protocol for its C&C communications.

T1095
Non-Application Layer Protocol
MalwareFunnyDream

FunnyDream can communicate with C2 over TCP and UDP.

T1095
Non-Application Layer Protocol
MalwareMOPSLED

MOPSLED can use a custom binary protocol over TCP for C2 communication.

T1095
Non-Application Layer Protocol
MalwareLookBack

LookBack uses a custom binary protocol over sockets for C2 communications.

T1095
Non-Application Layer Protocol
MalwareStealBit

StealBit can use the Windows Socket networking library to communicate with attacker-controlled endpoints.

T1095
Non-Application Layer Protocol
MalwarePenquin

The Penquin C2 mechanism is based on TCP and UDP packets.

T1095
Non-Application Layer Protocol
MalwareWinnti for Windows

Winnti for Windows can communicate using custom TCP.

T1095
Non-Application Layer Protocol
MalwareZIPLINE

ZIPLINE can communicate with C2 using a custom binary protocol.

T1095
Non-Application Layer Protocol
MalwaremetaMain

metaMain can establish an indirect and raw TCP socket-based connection to the C2 server.

T1095
Non-Application Layer Protocol
MalwareMis-Type

Mis-Type network traffic can communicate over a raw socket.

T1095
Non-Application Layer Protocol
MalwareStarProxy

StarProxy has used TCP for C2 communications to target IPs or domains. StarProxy contained code to support both UDP and TCP connections.

T1095
Non-Application Layer Protocol
MalwareShadowPad

ShadowPad has used UDP for C2 communications.

T1095
Non-Application Layer Protocol
MalwareQakBot

QakBot has the ability use TCP to send or receive C2 packets.

T1095
Non-Application Layer Protocol
MalwareGelsemium

Gelsemium has the ability to use TCP and UDP in C2 communications.

T1095
Non-Application Layer Protocol
MalwarePHOREAL

PHOREAL communicates via ICMP for C2.

T1095
Non-Application Layer Protocol
MalwareLizar

Lizar has used a raw TCP connection to communicate with the C2 server.

T1095
Non-Application Layer Protocol
MalwareHiddenWasp

HiddenWasp communicates with a simple network protocol over TCP.

T1095
Non-Application Layer Protocol
MalwareWarzoneRAT

WarzoneRAT can communicate with its C2 server via TCP over port 5200.

T1095
Non-Application Layer Protocol
ToolFRP

FRP can communicate over TCP, TCP stream multiplexing, KERN Communications Protocol (KCP), QUIC, and UDP.

T1095
Non-Application Layer Protocol
ToolBrute Ratel C4

Brute Ratel C4 has the ability to use TCP for external C2.

T1095
Non-Application Layer Protocol
ToolMythic

Mythic supports WebSocket and TCP-based C2 profiles.

T1095
Non-Application Layer Protocol
ToolQuasarRAT

QuasarRAT can use TCP for C2 communication.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.