ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1070.004
File Deletion
GroupFIN8

FIN8 has deleted tmp and prefetch files during post compromise cleanup activities. FIN8 has also deleted PowerShell scripts to evade detection on compromised machines.

T1070.005
Network Share Connection Removal
GroupThreat Group-3390

Threat Group-3390 has detached network shares after exfiltrating files, likely to evade detection.

T1070.006
Timestomp
GroupAPT38

APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.

T1070.006
Timestomp
GroupKimsuky

Kimsuky has manipulated timestamps for creation or compilation dates to defeat anti-forensics.

T1070.006
Timestomp
GroupAPT32

APT32 has used scheduled task raw XML with a backdated timestamp of June 2, 2016. The group has also set the creation time of the files dropped by the second stage of the exploit to match the creation time of kernel32.dll. Additionally, APT32 has used a random value to modify the timestamp of the file storing the clientID.

T1070.006
Timestomp
GroupMustang Panda

Mustang Panda has modified file timestamps from the export address table (EAT) in malware to make it difficult to identify creation times.

T1070.006
Timestomp
GroupRocke

Rocke has changed the time stamp of certain files.

T1070.006
Timestomp
GroupUNC3886

UNC3886 has used scripts to timestomp ESXi hosts prior to installing malicious vSphere Installation Bundles (VIBs).

T1070.006
Timestomp
GroupAPT29

APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory.

T1070.006
Timestomp
GroupChimera

Chimera has used a Windows version of the Linux touch command to modify the date and time stamp on DLLs.

T1070.006
Timestomp
GroupAPT28

APT28 has performed timestomping on victim files.

T1070.006
Timestomp
GroupAPT5

APT5 has modified file timestamps.

T1070.006
Timestomp
GroupLazarus Group

Several Lazarus Group malware families use timestomping, including modifying the last write timestamp of a specified Registry key to a random date, as well as copying the timestamp for legitimate .exe files (such as calc.exe or mspaint.exe) to its dropped files.

T1070.007
Clear Network Connection History and Configurations
GroupVolt Typhoon

Volt Typhoon has inspected server logs to remove their IPs.

T1070.007
Clear Network Connection History and Configurations
GroupUNC3886

UNC3886 has cleared specific events that contained the threat actor’s IP address from multiple log sources.

T1070.008
Clear Mailbox Data
GroupScattered Spider

Scattered Spider has manually deleted emails notifying users of suspicious account activity.

T1070.008
Clear Mailbox Data
GroupAPT42

APT42 has deleted login notification emails and has cleared the Sent folder to cover their tracks.

T1071
Application Layer Protocol
GroupTeamTNT

TeamTNT has used an IRC bot for C2 communications.

T1071
Application Layer Protocol
GroupRocke

Rocke issued wget requests from infected systems to the C2.

T1071
Application Layer Protocol
GroupINC Ransom

INC Ransom has used valid accounts over RDP to connect to targeted systems.

T1071
Application Layer Protocol
GroupVelvet Ant

Velvet Ant has used reverse SSH tunnels to communicate to victim devices.

T1071
Application Layer Protocol
GroupMagic Hound

Magic Hound malware has used IRC for C2.

T1071.001
Web Protocols
GroupAPT38

APT38 used a backdoor, QUICKRIDE, to communicate to the C2 server over HTTP and HTTPS.

T1071.001
Web Protocols
GroupBlackByte

BlackByte collected victim device information then transmitted this via HTTP POST to command and control infrastructure.

T1071.001
Web Protocols
GroupKimsuky

Kimsuky has used HTTP GET and POST requests for C2.

T1071.001
Web Protocols
GroupAPT41

APT41 used HTTP to download payloads for CVE-2019-19781 and CVE-2020-10189 exploits.

T1071.001
Web Protocols
GroupAPT32

APT32 has used JavaScript that communicates over HTTP or HTTPS to attacker controlled domains to download additional frameworks. The group has also used downloaded encrypted payloads over HTTP.

T1071.001
Web Protocols
GroupHAFNIUM

HAFNIUM has used open-source C2 frameworks, including Covenant.

T1071.001
Web Protocols
GroupMuddyWater

MuddyWater has used HTTP for C2 communications.

T1071.001
Web Protocols
GroupRedEcho

RedEcho network activity is associated with SSL traffic via TCP 443 and proxied HTTP traffic over non-standard ports.

T1071.001
Web Protocols
GroupGamaredon Group

Gamaredon Group has used HTTP and HTTPS for C2 communications.

T1071.001
Web Protocols
GroupTeamTNT

TeamTNT has the `curl` command to send credentials over HTTP and the `curl` and `wget` commands to download new software. TeamTNT has also used a custom user agent HTTP header in shell scripts.

T1071.001
Web Protocols
GroupSandworm Team

Sandworm Team's BCS-server tool connects to the designated C2 server via HTTP.

T1071.001
Web Protocols
GroupAPT18

APT18 uses HTTP for C2 communications.

T1071.001
Web Protocols
GroupSidewinder

Sidewinder has used HTTP in C2 communications.

T1071.001
Web Protocols
GroupMustang Panda

Mustang Panda has communicated with its C2 via HTTP POST requests.

T1071.001
Web Protocols
GroupRocke

Rocke has executed wget and curl commands to Pastebin over the HTTPS protocol.

T1071.001
Web Protocols
GroupAPT39

APT39 has used HTTP in communications with C2.

T1071.001
Web Protocols
GroupAPT37

APT37 uses HTTPS to conceal C2 communications.

T1071.001
Web Protocols
GroupOilRig

OilRig has used HTTP for C2.

T1071.001
Web Protocols
GroupHigaisa

Higaisa used HTTP and HTTPS to send data back to its C2 server.

T1071.001
Web Protocols
GroupTropic Trooper

Tropic Trooper has used HTTP in communication with the C2.

T1071.001
Web Protocols
GroupOrangeworm

Orangeworm has used HTTP for C2.

T1071.001
Web Protocols
GroupSea Turtle

Sea Turtle connected over TCP using HTTP to establish command and control channels.

T1071.001
Web Protocols
GroupKe3chang

Ke3chang malware including RoyalCli and BS2005 have communicated over HTTP with the C2 server through Internet Explorer (IE) by using the COM interface IWebBrowser2.

T1071.001
Web Protocols
GroupConfucius

Confucius has used HTTP for C2 communications.

T1071.001
Web Protocols
GroupWinter Vivern

Winter Vivern uses HTTP and HTTPS protocols for exfiltration and command and control activity.

T1071.001
Web Protocols
GroupSilverTerrier

SilverTerrier uses HTTP for C2 communications.

T1071.001
Web Protocols
GroupTurla

Turla has used HTTP and HTTPS for C2 communications.

T1071.001
Web Protocols
GroupTA505

TA505 has used HTTP to communicate with C2 nodes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.