Real-world descriptions of how a group, tool or campaign used a technique.
344 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
MalwarePowerShower | PowerShower has sent HTTP GET and POST requests to C2 servers to send information and receive instructions. |
| T1071.001 Web Protocols |
MalwareKazuar | Kazuar uses HTTP and HTTPS to communicate with the C2 server. Kazuar can also act as a webserver and listen for inbound HTTP requests through an exposed API. |
| T1071.001 Web Protocols |
MalwareDarkComet | DarkComet can use HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareNETEAGLE | NETEAGLE will attempt to detect if the infected host is configured to a proxy. If so, NETEAGLE will send beacons via an HTTP POST request. NETEAGLE will also use HTTP to download resources that contain an IP address and Port Number pair to connect to for further C2. |
| T1071.001 Web Protocols |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can send `HTTP GET` requests to C2. |
| T1071.001 Web Protocols |
MalwareFatDuke | FatDuke can be controlled via a custom C2 protocol over HTTP. |
| T1071.001 Web Protocols |
MalwareBlackEnergy | BlackEnergy communicates with its C2 server over HTTP. |
| T1071.001 Web Protocols |
MalwareDRATzarus | DRATzarus can use HTTP or HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwareRising Sun | Rising Sun has used HTTP and HTTPS for command and control. |
| T1071.001 Web Protocols |
MalwareShimRat | ShimRat communicated over HTTP and HTTPS with C2 servers. |
| T1071.001 Web Protocols |
MalwareFlagpro | Flagpro can communicate with its C2 using HTTP. |
| T1071.001 Web Protocols |
MalwareHi-Zor | Hi-Zor communicates with its C2 server over HTTPS. |
| T1071.001 Web Protocols |
MalwareChina Chopper | China Chopper's server component executes code sent via HTTP POST commands. |
| T1071.001 Web Protocols |
MalwareSnappyTCP | SnappyTCP connects to the command and control server via a TCP socket using HTTP. |
| T1071.001 Web Protocols |
MalwareLightSpy | LightSpy's C2 communication is performed over WebSockets using the open source library SocketRocket with functionality such as, heartbeat, receiving commands, and updating command status. |
| T1071.001 Web Protocols |
MalwarePUNCHBUGGY | PUNCHBUGGY enables remote interaction and can obtain additional code over HTTPS GET and POST requests. |
| T1071.001 Web Protocols |
MalwareGoldMax | GoldMax has used HTTPS and HTTP GET requests with custom HTTP cookies for C2. |
| T1071.001 Web Protocols |
MalwareLIGHTWIRE | LIGHTWIRE can use HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareMiniDuke | MiniDuke uses HTTP and HTTPS for command and control. |
| T1071.001 Web Protocols |
MalwareHyperBro | HyperBro has used HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwareAnchor | Anchor has used HTTP and HTTPS in C2 communications. |
| T1071.001 Web Protocols |
MalwareLine Runner | Line Runner utilizes an HTTP-based Lua backdoor on victim machines. |
| T1071.001 Web Protocols |
MalwarePteranodon | Pteranodon can use HTTP for C2. |
| T1071.001 Web Protocols |
MalwareDarkTortilla | DarkTortilla has used HTTP and HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareBeaverTail | BeaverTail has used HTTP GET request to download malicious payloads to include InvisibleFerret and HTTP POST to exfiltrate data to C2 infrastructure. |
| T1071.001 Web Protocols |
MalwareROKRAT | ROKRAT can use HTTP and HTTPS for command and control communication. |
| T1071.001 Web Protocols |
MalwareCORESHELL | CORESHELL can communicate over HTTP for C2. |
| T1071.001 Web Protocols |
MalwareDarkWatchman | DarkWatchman uses HTTPS for command and control. |
| T1071.001 Web Protocols |
MalwareDyre | Dyre uses HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwareBlackMould | BlackMould can send commands to C2 in the body of HTTP POST requests. |
| T1071.001 Web Protocols |
MalwareBBSRAT | BBSRAT uses GET and POST requests over HTTP or HTTPS for command and control to obtain commands and send ZLIB compressed data back to the C2 server. |
| T1071.001 Web Protocols |
MalwarePlugX | PlugX can be configured to use HTTP for command and control. PlugX has also used HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareReaver | Some Reaver variants use HTTP for C2. |
| T1071.001 Web Protocols |
MalwareBisonal | Bisonal has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareS-Type | S-Type uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareLumma Stealer | Lumma Stealer has used HTTP and HTTP for command and control communication. |
| T1071.001 Web Protocols |
MalwareSeaDuke | SeaDuke uses HTTP and HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareDustySky | DustySky has used both HTTP and HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareRemsec | Remsec is capable of using HTTP and HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareExplosive | Explosive has used HTTP for communication. |
| T1071.001 Web Protocols |
MalwareXbash | Xbash uses HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareEpic | Epic uses HTTP and HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwarePeppy | Peppy can use HTTP to communicate with C2. |
| T1071.001 Web Protocols |
MalwareKEYPLUG | KEYPLUG has the ability to communicate over HTTP and WebSocket Protocol (WSS) for C2. |
| T1071.001 Web Protocols |
MalwareDEATHRANSOM | DEATHRANSOM can use HTTPS to download files. |
| T1071.001 Web Protocols |
MalwareClambling | Clambling has the ability to communicate over HTTP. |
| T1071.001 Web Protocols |
MalwareMongall | Mongall can use HTTP for C2 communication. |
| T1071.001 Web Protocols |
MalwareLockBit 3.0 | LockBit 3.0 can use HTTP to send victim host information to C2. |
| T1071.001 Web Protocols |
MalwareSVCReady | SVCReady can communicate with its C2 servers via HTTP. |
| T1071.001 Web Protocols |
MalwareThiefQuest | ThiefQuest uploads files via unencrypted HTTP. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.