ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1070.004×

251 examples

TechniqueUsed byProcedure example
T1070.004
File Deletion
MalwareBazar

Bazar can delete its loader using a batch file in the Windows temporary folder.

T1070.004
File Deletion
MalwareMESSAGETAP

Once loaded into memory, MESSAGETAP deletes the keyword_parm.txt and parm.txt configuration files from disk.

T1070.004
File Deletion
MalwareXLoader

XLoader can delete malicious executables from compromised machines.

T1070.004
File Deletion
MalwareMoonWind

MoonWind can delete itself or specified files.

T1070.004
File Deletion
MalwareCryptoistic

Cryptoistic has the ability delete files from a compromised host.

T1070.004
File Deletion
MalwareHermeticWiper

HermeticWiper has the ability to overwrite its own file with random bites.

T1070.004
File Deletion
MalwarePysa

Pysa has deleted batch files after execution.

T1070.004
File Deletion
Malwareccf32

ccf32 can delete files and folders from compromised machines.

T1070.004
File Deletion
MalwareLockBit 2.0

LockBit 2.0 can delete itself from disk after execution.

T1070.004
File Deletion
MalwareZebrocy

Zebrocy has a command to delete files and directories.

T1070.004
File Deletion
MalwareSpeakUp

SpeakUp deletes files to remove evidence on the machine.

T1070.004
File Deletion
MalwareLunarMail

LunarMail can delete the previously used staging directory and files on subsequent rounds of exfiltration and replace it with a new one.

T1070.004
File Deletion
MalwareSUNBURST

SUNBURST had a command to delete files.

T1070.004
File Deletion
MalwareEvilBunny

EvilBunny has deleted the initial dropper after running through the environment checks.

T1070.004
File Deletion
MalwareWingbird

Wingbird deletes its payload along with the payload's parent process after it finishes copying files.

T1070.004
File Deletion
MalwareHotCroissant

HotCroissant has the ability to clean up installed files, delete files, and delete itself from the victim’s machine.

T1070.004
File Deletion
MalwareServHelper

ServHelper has a module to delete itself from the infected machine.

T1070.004
File Deletion
MalwareREvil

REvil can mark its binary code for deletion after reboot.

T1070.004
File Deletion
MalwareMilan

Milan can delete files via `C:\Windows\system32\cmd.exe /c ping 1.1.1.1 -n 1 -w 3000 > Nul & rmdir /s /q`.

T1070.004
File Deletion
MalwareUSBStealer

USBStealer has several commands to delete files associated with the malware from the victim.

T1070.004
File Deletion
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has a command to delete a file from the system. OSX_OCEANLOTUS.D deletes the app bundle and dropper after execution.

T1070.004
File Deletion
MalwareTaidoor

Taidoor can use DeleteFileA to remove files from infected hosts.

T1070.004
File Deletion
MalwareCherry Picker

Recent versions of Cherry Picker delete files and registry keys created by the malware.

T1070.004
File Deletion
MalwareKivars

Kivars has the ability to uninstall malware from the infected host.

T1070.004
File Deletion
MalwareSeasalt

Seasalt has a command to delete a specified file.

T1070.004
File Deletion
MalwarePLEAD

PLEAD has the ability to delete files on the compromised host.

T1070.004
File Deletion
MalwareRaccoon Stealer

Raccoon Stealer can remove files related to use and installation.

T1070.004
File Deletion
MalwareIPsec Helper

IPsec Helper can delete itself when given the appropriate command.

T1070.004
File Deletion
MalwareTRAILBLAZE

TRAILBLAZE has the ability to delete temporary files and contents in specified directories to cover its tracks.

T1070.004
File Deletion
MalwareCardinal RAT

Cardinal RAT can uninstall itself, including deleting its executable.

T1070.004
File Deletion
MalwareDanBot

DanBot can delete its configuration file after installation.

T1070.004
File Deletion
MalwareCalisto

Calisto has the capability to use rm -rf to remove folders and files from the victim's machine.

T1070.004
File Deletion
MalwareSolar

Solar has the ability to delete staged files after they are uploaded to C2.

T1070.004
File Deletion
MalwareGoldenSpy

GoldenSpy's uninstaller can delete registry entries, files and folders, and finally itself once these tasks have been completed.

T1070.004
File Deletion
MalwareGold Dragon

Gold Dragon deletes one of its files, 2.hwp, from the endpoint after establishing persistence.

T1070.004
File Deletion
MalwarePillowmint

Pillowmint has deleted the filepath %APPDATA%\Intel\devmonsrv.exe.

T1070.004
File Deletion
MalwareMacMa

MacMa can delete itself from the compromised computer.

T1070.004
File Deletion
MalwareFunnyDream

FunnyDream can delete files including its dropper component.

T1070.004
File Deletion
MalwareROADSWEEP

ROADSWEEP can use embedded scripts to remove itself from the infected host.

T1070.004
File Deletion
MalwareSUNSPOT

Following the successful injection of SUNBURST, SUNSPOT deleted a temporary file it created named InventoryManager.bk after restoring the original SolarWinds Orion source code to the software library.

T1070.004
File Deletion
MalwareMore_eggs

More_eggs can remove itself from a system.

T1070.004
File Deletion
MalwareSysUpdate

SysUpdate can delete its configuration file from the targeted system.

T1070.004
File Deletion
MalwareOutSteel

OutSteel can delete itself following the successful execution of a follow-on payload.

T1070.004
File Deletion
MalwareBackConfig

BackConfig has the ability to remove files and folders related to previous infections.

T1070.004
File Deletion
MalwareProton

Proton removes all files in the /tmp directory.

T1070.004
File Deletion
MalwareInnaputRAT

InnaputRAT has a command to delete files.

T1070.004
File Deletion
MalwareGrimAgent

GrimAgent can delete old binaries on a compromised host.

T1070.004
File Deletion
MalwareLookBack

LookBack removes itself after execution and can delete files on the system.

T1070.004
File Deletion
MalwareLokibot

Lokibot will delete its dropped files after bypassing UAC.

T1070.004
File Deletion
MalwarePoetRAT

PoetRAT has the ability to overwrite scripts and delete itself if a sandbox environment is detected.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.