ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1070.004×

251 examples

TechniqueUsed byProcedure example
T1070.004
File Deletion
MalwareEpic

Epic has a command to delete a file from the machine.

T1070.004
File Deletion
MalwareLightNeuron

LightNeuron has a function to delete files.

T1070.004
File Deletion
MalwareCuba

Cuba can use the command cmd.exe /c del to delete its artifacts from the system.

T1070.004
File Deletion
MalwarePureCrypter

PureCrypter can execute a PowerShell command to self-delete.

T1070.004
File Deletion
MalwareDarkGate

DarkGate has deleted its staging directories.

T1070.004
File Deletion
MalwareNanHaiShu

NanHaiShu launches a script to delete their original decoy file to cover tracks.

T1070.004
File Deletion
MalwareLockBit 3.0

LockBit 3.0 can delete itself from disk.

T1070.004
File Deletion
MalwareCarbanak

Carbanak has a command to delete files.

T1070.004
File Deletion
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can delete files.

T1070.004
File Deletion
MalwareFerocious

Ferocious can delete files from a compromised host.

T1070.004
File Deletion
MalwareElise

Elise is capable of launching a remote shell on the host to delete itself.

T1070.004
File Deletion
MalwareGazer

Gazer has commands to delete files and persistence mechanisms from the victim.

T1070.004
File Deletion
MalwareLatrodectus

Latrodectus has the ability to delete itself.

T1070.004
File Deletion
MalwareSaint Bot

Saint Bot can run a batch script named `del.bat` to remove any Saint Bot payload-linked files from a compromise system if anti-analysis or locale checks fail.

T1070.004
File Deletion
MalwarePay2Key

Pay2Key can remove its log file from disk.

T1070.004
File Deletion
MalwareLODEINFO

LODEINFO can delete files to remove traces of activity from victim systems.

T1070.004
File Deletion
MalwareCharmPower

CharmPower can delete created files from a compromised system.

T1070.004
File Deletion
MalwareTYPEFRAME

TYPEFRAME can delete files off the system.

T1070.004
File Deletion
MalwareMori

Mori can delete its DLL file and related files by Registry value.

T1070.004
File Deletion
MalwareQUADAGENT

QUADAGENT has a command to delete its Registry key and scheduled task.

T1070.004
File Deletion
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can delete files from a compromised host.

T1070.004
File Deletion
Malwarepngdowner

pngdowner deletes content from C2 communications that was saved to the user's temporary directory.

T1070.004
File Deletion
MalwareUroburos

Uroburos can run a `Clear Agents Track` command on an infected machine to delete Uroburos-related logs.

T1070.004
File Deletion
MalwareMetamorfo

Metamorfo has deleted itself from the system after execution.

T1070.004
File Deletion
MalwareEmbargo

Embargo has leveraged MDeployer to terminate the MS4Killer process, delete the decrypted payload files and a driver file dropped by MS4killer, and reboot the system.

T1070.004
File Deletion
MalwareTrojan.Karagany

Trojan.Karagany has used plugins with a self-delete capability.

T1070.004
File Deletion
MalwareBandook

Bandook has a command to delete a file.

T1070.004
File Deletion
MalwareMagicRAT

MagicRAT can delete files on victim systems, including itself.

T1070.004
File Deletion
MalwareKONNI

KONNI can delete files.

T1070.004
File Deletion
Malwaregh0st RAT

gh0st RAT has the capability to to delete files.

T1070.004
File Deletion
MalwareJHUHUGIT

The JHUHUGIT dropper can delete itself from the victim. Another JHUHUGIT variant has the capability to delete specified files.

T1070.004
File Deletion
MalwareBLUELIGHT

BLUELIGHT can uninstall itself.

T1070.004
File Deletion
MalwareIxeshe

Ixeshe has a command to delete a file from the machine.

T1070.004
File Deletion
MalwareVBShower

VBShower has attempted to complicate forensic analysis by deleting all the files contained in %APPDATA%\..\Local\Temporary Internet Files\Content.Word and %APPDATA%\..\Local Settings\Temporary Internet Files\Content.Word\.

T1070.004
File Deletion
MalwareBPFDoor

After initial setup, BPFDoor's original execution process deletes the dropped binary and exits.

T1070.004
File Deletion
MalwareStoneDrill

StoneDrill has been observed deleting the temporary files once they fulfill their task.

T1070.004
File Deletion
MalwareOopsIE

OopsIE has the capability to delete files and scripts from the victim's machine.

T1070.004
File Deletion
MalwareAttor

Attor’s plugin deletes the collected files and log files after exfiltration.

T1070.004
File Deletion
MalwareSQLRat

SQLRat has used been observed deleting scripts once used.

T1070.004
File Deletion
MalwareSDBbot

SDBbot has the ability to delete files from a compromised host.

T1070.004
File Deletion
MalwareMosquito

Mosquito deletes files using DeleteFileW API call.

T1070.004
File Deletion
MalwareRTM

RTM can delete all files created during its execution.

T1070.004
File Deletion
MalwareDerusbi

Derusbi is capable of deleting files. It has been observed loading a Linux Kernel Module (LKM) and then deleting it from the hard disk as well as overwriting the data with null bytes.

T1070.004
File Deletion
MalwareGrandoreiro

Grandoreiro can delete .LNK files created in the Startup folder.

T1070.004
File Deletion
MalwareLiteDuke

LiteDuke can securely delete files by first writing random data to the file.

T1070.004
File Deletion
MalwareSakula

Some Sakula samples use cmd.exe to delete temporary files.

T1070.004
File Deletion
MalwareSibot

Sibot will delete itself if a certain server response is received.

T1070.004
File Deletion
MalwareWINDSHIELD

WINDSHIELD is capable of file deletion along with other file system interaction.

T1070.004
File Deletion
MalwareDrovorub

Drovorub can delete specific files from a compromised host.

T1070.004
File Deletion
MalwareShark

Shark can delete files downloaded to the compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.