ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1071.001×

344 examples

TechniqueUsed byProcedure example
T1071.001
Web Protocols
MalwareFoggyWeb

FoggyWeb has the ability to communicate with C2 servers over HTTP GET/POST requests.

T1071.001
Web Protocols
MalwareNGLite

NGLite will initially beacon out to the NKN network via an HTTP POST over TCP 30003.

T1071.001
Web Protocols
MalwareCarbanak

The Carbanak malware communicates to its command server using HTTP with an encrypted payload.

T1071.001
Web Protocols
MalwareCreepyDrive

CreepyDrive can use HTTPS for C2 using the Microsoft Graph API.

T1071.001
Web Protocols
MalwareElise

Elise communicates over HTTP or HTTPS for C2.

T1071.001
Web Protocols
MalwareGazer

Gazer communicates with its C2 servers over HTTP.

T1071.001
Web Protocols
MalwareTSCookie

TSCookie can multiple protocols including HTTP and HTTPS in communication with command and control (C2) servers.

T1071.001
Web Protocols
MalwareLatrodectus

Latrodectus can send registration information to C2 via HTTP `POST`.

T1071.001
Web Protocols
MalwareSaint Bot

Saint Bot has used HTTP for C2 communications.

T1071.001
Web Protocols
MalwareChaes

Chaes has used HTTP for C2 communications.

T1071.001
Web Protocols
MalwareCharmPower

CharmPower can use HTTP to communicate with C2.

T1071.001
Web Protocols
MalwareMuddyViper

MuddyViper has used HTTP GET requests over port 443 and with the WINHTTP_FLAG_SECURE set to SSL/TLS via the WinHTTP API.

T1071.001
Web Protocols
Malware3PARA RAT

3PARA RAT uses HTTP for command and control.

T1071.001
Web Protocols
MalwareBundlore

Bundlore uses HTTP requests for C2.

T1071.001
Web Protocols
MalwareSMOKEDHAM

SMOKEDHAM has communicated with its C2 servers via HTTPS and HTTP POST requests.

T1071.001
Web Protocols
MalwareMori

Mori can communicate using HTTP over IPv4 or IPv6 depending on a flag set.

T1071.001
Web Protocols
MalwareQUADAGENT

QUADAGENT uses HTTPS and HTTP for C2 communications.

T1071.001
Web Protocols
MalwareSagerunex

Sagerunex communicates via HTTPS, at times using a hard-coded User Agent of `Mozilla/5.0 (compatible; MSIE 7.0; Win32)`.

T1071.001
Web Protocols
MalwareSys10

Sys10 uses HTTP for C2.

T1071.001
Web Protocols
Malwarepngdowner

pngdowner uses HTTP for command and control.

T1071.001
Web Protocols
MalwareGlassWorm

GlassWorm has used HTTP for C2 and extracts data from the HTTP response headers.

T1071.001
Web Protocols
MalwareUroburos

Uroburos can use a custom HTTP-based protocol for large data communications that can blend with normal network traffic by riding on top of standard HTTP.

T1071.001
Web Protocols
MalwareMetamorfo

Metamorfo has used HTTP for C2.

T1071.001
Web Protocols
MalwareTrojan.Karagany

Trojan.Karagany can communicate with C2 via HTTP POST requests.

T1071.001
Web Protocols
MalwareMagicRAT

MagicRAT uses HTTP POST communication for command and control.

T1071.001
Web Protocols
MalwareKONNI

KONNI has used HTTP POST for C2.

T1071.001
Web Protocols
MalwareWinnti for Linux

Winnti for Linux has used HTTP in outbound communications.

T1071.001
Web Protocols
MalwareShamoon

Shamoon has used HTTP for C2.

T1071.001
Web Protocols
MalwareJHUHUGIT

JHUHUGIT variants have communicated with C2 servers over HTTP and HTTPS.

T1071.001
Web Protocols
MalwareBLUELIGHT

BLUELIGHT can use HTTP/S for C2 using the Microsoft Graph API.

T1071.001
Web Protocols
MalwareKGH_SPY

KGH_SPY can send data to C2 with HTTP POST requests.

T1071.001
Web Protocols
Malwaredown_new

down_new has the ability to use HTTP in C2 communications.

T1071.001
Web Protocols
MalwareIxeshe

Ixeshe uses HTTP for command and control.

T1071.001
Web Protocols
MalwareMicropsia

Micropsia uses HTTP and HTTPS for C2 network communications.

T1071.001
Web Protocols
MalwareRedLine Stealer

RedLine Stealer has utilized HTTP for C2 communications. RedLine Stealer has also conducted C2 communications to hardcoded C2 servers over HTTPS. RedLine Stealer has leveraged SOAP protocol for C2 communications.

T1071.001
Web Protocols
MalwareVBShower

VBShower has attempted to obtain a VBS script from command and control (C2) nodes over HTTP.

T1071.001
Web Protocols
MalwareOopsIE

OopsIE uses HTTP for C2 communications.

T1071.001
Web Protocols
Malware4H RAT

4H RAT uses HTTP for command and control.

T1071.001
Web Protocols
MalwareDealersChoice

DealersChoice uses HTTP for communication with the C2 server.

T1071.001
Web Protocols
MalwareLitePower

LitePower can use HTTP and HTTPS for C2 communications.

T1071.001
Web Protocols
MalwareCrutch

Crutch has conducted C2 communications with a Dropbox account using the HTTP API.

T1071.001
Web Protocols
MalwareRTM

RTM has initiated connections to external domains using HTTPS.

T1071.001
Web Protocols
MalwareQUIETCANARY

QUIETCANARY can use HTTPS for C2 communications.

T1071.001
Web Protocols
MalwarePHPsert

PHPsert can retrieve remote files using HTTP POST.

T1071.001
Web Protocols
MalwareHikit

Hikit has used HTTP for C2.

T1071.001
Web Protocols
MalwareStrelaStealer

StrelaStealer communicates externally via HTTP POST with encrypted content.

T1071.001
Web Protocols
MalwareGrandoreiro

Grandoreiro has the ability to use HTTP in C2 communications.

T1071.001
Web Protocols
MalwareLiteDuke

LiteDuke can use HTTP GET requests in C2 communications.

T1071.001
Web Protocols
MalwareSakula

Sakula uses HTTP for C2.

T1071.001
Web Protocols
MalwareVaporRage

VaporRage can use HTTP to download shellcode from compromised websites.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.