Real-world descriptions of how a group, tool or campaign used a technique.
251 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1070.004 File Deletion |
MalwareBazar | Bazar can delete its loader using a batch file in the Windows temporary folder. |
| T1070.004 File Deletion |
MalwareMESSAGETAP | Once loaded into memory, MESSAGETAP deletes the keyword_parm.txt and parm.txt configuration files from disk. |
| T1070.004 File Deletion |
MalwareXLoader | XLoader can delete malicious executables from compromised machines. |
| T1070.004 File Deletion |
MalwareMoonWind | MoonWind can delete itself or specified files. |
| T1070.004 File Deletion |
MalwareCryptoistic | Cryptoistic has the ability delete files from a compromised host. |
| T1070.004 File Deletion |
MalwareHermeticWiper | HermeticWiper has the ability to overwrite its own file with random bites. |
| T1070.004 File Deletion |
MalwarePysa | Pysa has deleted batch files after execution. |
| T1070.004 File Deletion |
Malwareccf32 | ccf32 can delete files and folders from compromised machines. |
| T1070.004 File Deletion |
MalwareLockBit 2.0 | LockBit 2.0 can delete itself from disk after execution. |
| T1070.004 File Deletion |
MalwareZebrocy | Zebrocy has a command to delete files and directories. |
| T1070.004 File Deletion |
MalwareSpeakUp | SpeakUp deletes files to remove evidence on the machine. |
| T1070.004 File Deletion |
MalwareLunarMail | LunarMail can delete the previously used staging directory and files on subsequent rounds of exfiltration and replace it with a new one. |
| T1070.004 File Deletion |
MalwareSUNBURST | SUNBURST had a command to delete files. |
| T1070.004 File Deletion |
MalwareEvilBunny | EvilBunny has deleted the initial dropper after running through the environment checks. |
| T1070.004 File Deletion |
MalwareWingbird | Wingbird deletes its payload along with the payload's parent process after it finishes copying files. |
| T1070.004 File Deletion |
MalwareHotCroissant | HotCroissant has the ability to clean up installed files, delete files, and delete itself from the victim’s machine. |
| T1070.004 File Deletion |
MalwareServHelper | ServHelper has a module to delete itself from the infected machine. |
| T1070.004 File Deletion |
MalwareREvil | REvil can mark its binary code for deletion after reboot. |
| T1070.004 File Deletion |
MalwareMilan | Milan can delete files via `C:\Windows\system32\cmd.exe /c ping 1.1.1.1 -n 1 -w 3000 > Nul & rmdir /s /q`. |
| T1070.004 File Deletion |
MalwareUSBStealer | USBStealer has several commands to delete files associated with the malware from the victim. |
| T1070.004 File Deletion |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has a command to delete a file from the system. OSX_OCEANLOTUS.D deletes the app bundle and dropper after execution. |
| T1070.004 File Deletion |
MalwareTaidoor | Taidoor can use |
| T1070.004 File Deletion |
MalwareCherry Picker | Recent versions of Cherry Picker delete files and registry keys created by the malware. |
| T1070.004 File Deletion |
MalwareKivars | Kivars has the ability to uninstall malware from the infected host. |
| T1070.004 File Deletion |
MalwareSeasalt | Seasalt has a command to delete a specified file. |
| T1070.004 File Deletion |
MalwarePLEAD | PLEAD has the ability to delete files on the compromised host. |
| T1070.004 File Deletion |
MalwareRaccoon Stealer | Raccoon Stealer can remove files related to use and installation. |
| T1070.004 File Deletion |
MalwareIPsec Helper | IPsec Helper can delete itself when given the appropriate command. |
| T1070.004 File Deletion |
MalwareTRAILBLAZE | TRAILBLAZE has the ability to delete temporary files and contents in specified directories to cover its tracks. |
| T1070.004 File Deletion |
MalwareCardinal RAT | Cardinal RAT can uninstall itself, including deleting its executable. |
| T1070.004 File Deletion |
MalwareDanBot | DanBot can delete its configuration file after installation. |
| T1070.004 File Deletion |
MalwareCalisto | Calisto has the capability to use |
| T1070.004 File Deletion |
MalwareSolar | Solar has the ability to delete staged files after they are uploaded to C2. |
| T1070.004 File Deletion |
MalwareGoldenSpy | GoldenSpy's uninstaller can delete registry entries, files and folders, and finally itself once these tasks have been completed. |
| T1070.004 File Deletion |
MalwareGold Dragon | Gold Dragon deletes one of its files, 2.hwp, from the endpoint after establishing persistence. |
| T1070.004 File Deletion |
MalwarePillowmint | Pillowmint has deleted the filepath |
| T1070.004 File Deletion |
MalwareMacMa | MacMa can delete itself from the compromised computer. |
| T1070.004 File Deletion |
MalwareFunnyDream | FunnyDream can delete files including its dropper component. |
| T1070.004 File Deletion |
MalwareROADSWEEP | ROADSWEEP can use embedded scripts to remove itself from the infected host. |
| T1070.004 File Deletion |
MalwareSUNSPOT | Following the successful injection of SUNBURST, SUNSPOT deleted a temporary file it created named |
| T1070.004 File Deletion |
MalwareMore_eggs | More_eggs can remove itself from a system. |
| T1070.004 File Deletion |
MalwareSysUpdate | SysUpdate can delete its configuration file from the targeted system. |
| T1070.004 File Deletion |
MalwareOutSteel | OutSteel can delete itself following the successful execution of a follow-on payload. |
| T1070.004 File Deletion |
MalwareBackConfig | BackConfig has the ability to remove files and folders related to previous infections. |
| T1070.004 File Deletion |
MalwareProton | Proton removes all files in the /tmp directory. |
| T1070.004 File Deletion |
MalwareInnaputRAT | InnaputRAT has a command to delete files. |
| T1070.004 File Deletion |
MalwareGrimAgent | GrimAgent can delete old binaries on a compromised host. |
| T1070.004 File Deletion |
MalwareLookBack | LookBack removes itself after execution and can delete files on the system. |
| T1070.004 File Deletion |
MalwareLokibot | Lokibot will delete its dropped files after bypassing UAC. |
| T1070.004 File Deletion |
MalwarePoetRAT | PoetRAT has the ability to overwrite scripts and delete itself if a sandbox environment is detected. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.