ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1570
Lateral Tool Transfer
MalwareIPsec Helper

IPsec Helper can download additional payloads from command and control nodes and execute them.

T1570
Lateral Tool Transfer
MalwareOutSteel

OutSteel can download the Saint Bot malware for follow-on execution.

T1570
Lateral Tool Transfer
MalwareVIRTUALPITA

VIRTUALPITA is capable of file transfer and arbitrary command execution.

T1570
Lateral Tool Transfer
MalwareQilin

Qilin has used PsExec to distribute a second encryptor, named encryptor_1.exe, across the targeted environment.

T1570
Lateral Tool Transfer
MalwareINC Ransomware

INC Ransomware can push its encryption executable to multiple endpoints within compromised infrastructure.

T1570
Lateral Tool Transfer
MalwareHermeticWizard

HermeticWizard can copy files to other machines on a compromised network.

T1570
Lateral Tool Transfer
ToolImpacket

Impacket has used its `wmiexec` command, leveraging Windows Management Instrumentation, to remotely stage and execute payloads in victim networks.

T1570
Lateral Tool Transfer
ToolBITSAdmin

BITSAdmin can be used to create BITS Jobs to upload and/or download files from SMB file servers.

T1570
Lateral Tool Transfer
Toolcmd

cmd can be used to copy files to/from a remotely connected internal system.

T1570
Lateral Tool Transfer
Toolesentutl

esentutl can be used to copy files to/from a remote share.

T1570
Lateral Tool Transfer
ToolExpand

Expand can be used to download or upload a file over a network share.

T1570
Lateral Tool Transfer
Toolftp

ftp may be abused by adversaries to transfer tools or files between systems within a compromised environment.

T1570
Lateral Tool Transfer
ToolPsExec

PsExec can be used to download or upload a file over a network share.

T1571
Non-Standard Port
MalwareTrickBot

Some TrickBot samples have used HTTP over ports 447 and 8082 for C2. Newer versions of TrickBot have been known to use a custom communication protocol which sends the data unencrypted over port 443.

T1571
Non-Standard Port
MalwarePikabot

Pikabot uses non-standard ports, such as 2967, 2223, and others, for HTTPS command and control communication.

T1571
Non-Standard Port
MalwareRotaJakiro

RotaJakiro uses a custom binary protocol over TCP port 443.

T1571
Non-Standard Port
MalwareSardonic

Sardonic has the ability to connect with actor-controlled C2 servers using a custom binary protocol over port 443.

T1571
Non-Standard Port
MalwareRedLeaves

RedLeaves can use HTTP over non-standard ports, such as 995, for C2.

T1571
Non-Standard Port
MalwareGravityRAT

GravityRAT has used HTTP over a non-standard port, such as TCP port 46769.

T1571
Non-Standard Port
MalwareInvisibleFerret

InvisibleFerret has been observed utilizing HTTP communications to the C2 server over ports 1224, 2245 and 8637.

T1571
Non-Standard Port
MalwareBankshot

Bankshot binds and listens on port 1058 for HTTP traffic while also utilizing a FakeTLS method.

T1571
Non-Standard Port
MalwareStrongPity

StrongPity has used HTTPS over port 1402 in C2 communication.

T1571
Non-Standard Port
MalwareHannotog

Hannotog uses non-standard listening ports, such as UDP 5900, for command and control purposes.

T1571
Non-Standard Port
MalwareEmotet

Emotet has used HTTP over ports such as 20, 22, 443, 7080, and 50000, in addition to using ports commonly associated with HTTP/S.

T1571
Non-Standard Port
MalwareSystemBC

The server component of SystemBC has used various TCP ports for C2 communication.

T1571
Non-Standard Port
MalwarePingPull

PingPull can use HTTPS over port 8080 for C2.

T1571
Non-Standard Port
MalwareSUGARUSH

SUGARUSH has used port 4585 for a TCP connection to its C2.

T1571
Non-Standard Port
MalwareHOPLIGHT

HOPLIGHT has connected outbound over TCP port 443 with a FakeTLS method.

T1571
Non-Standard Port
MalwareRaspberry Robin

Raspberry Robin will communicate via HTTP over port 8080 for command and control traffic.

T1571
Non-Standard Port
MalwareBeaverTail

BeaverTail has communicated with C2 IP addresses over ports 1224 or 1244.

T1571
Non-Standard Port
MalwarePlugX

PlugX has used random, high-number, non-standard ports to listen for subsequent actions and C2 activities.

T1571
Non-Standard Port
MalwareTYPEFRAME

TYPEFRAME has used ports 443, 8080, and 8443 with a FakeTLS method.

T1571
Non-Standard Port
MalwareVIRTUALPIE

VIRTUALPIE has created listeners on hard coded TCP port 546.

T1571
Non-Standard Port
MalwareBendyBear

BendyBear has used a custom RC4 and XOR encrypted protocol over port 443 for C2.

T1571
Non-Standard Port
MalwareGlassWorm

GlassWorm has distributed C2 using BitTorrent’s Distributed Hash Table (DHT) network to harness a decentralized command capability.

T1571
Non-Standard Port
MalwareMetamorfo

Metamorfo has communicated with hosts over raw TCP on port 9999.

T1571
Non-Standard Port
MalwareRTM

RTM used Port 44443 for its VNC module.

T1571
Non-Standard Port
MalwareDerusbi

Derusbi has used unencrypted HTTP on port 443 for C2.

T1571
Non-Standard Port
MalwareWellMail

WellMail has been observed using TCP port 25, without using SMTP, to leverage an open port for secure command and control communications.

T1571
Non-Standard Port
MalwareBADCALL

BADCALL communicates on ports 443 and 8000 with a FakeTLS method.

T1571
Non-Standard Port
MalwareMoonWind

MoonWind communicates over ports 80, 443, 53, and 8080 via raw sockets instead of the protocols usually associated with the ports.

T1571
Non-Standard Port
MalwareHiddenFace

HiddenFace's passive mode listens on TCP 47000.

T1571
Non-Standard Port
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has used a custom binary protocol over TCP port 443 for C2.

T1571
Non-Standard Port
MalwareCyclops Blink

Cyclops Blink can use non-standard ports for C2 not typically associated with HTTP or HTTPS traffic.

T1571
Non-Standard Port
MalwareGoldenSpy

GoldenSpy has used HTTP over ports 9005 and 9006 for network traffic, 9002 for C2 requests, 33666 as a WebSocket, and 8090 to download files.

T1571
Non-Standard Port
MalwareHARDRAIN

HARDRAIN binds and listens on port 443 with a FakeTLS method.

T1571
Non-Standard Port
MalwareMacMa

MacMa has used TCP port 5633 for C2 Communication.

T1571
Non-Standard Port
MalwarePoetRAT

PoetRAT used TLS to encrypt communications over port 143

T1571
Non-Standard Port
MalwareZxShell

ZxShell can use ports 1985 and 1986 in HTTP/S communication.

T1571
Non-Standard Port
MalwareSPAWNCHIMERA

SPAWNCHIMERA has the ability to bind on a localhost and listen on port 8300.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.