Real-world descriptions of how a group, tool or campaign used a technique.
344 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
MalwareFoggyWeb | FoggyWeb has the ability to communicate with C2 servers over HTTP GET/POST requests. |
| T1071.001 Web Protocols |
MalwareNGLite | NGLite will initially beacon out to the NKN network via an HTTP POST over TCP 30003. |
| T1071.001 Web Protocols |
MalwareCarbanak | The Carbanak malware communicates to its command server using HTTP with an encrypted payload. |
| T1071.001 Web Protocols |
MalwareCreepyDrive | CreepyDrive can use HTTPS for C2 using the Microsoft Graph API. |
| T1071.001 Web Protocols |
MalwareElise | Elise communicates over HTTP or HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareGazer | Gazer communicates with its C2 servers over HTTP. |
| T1071.001 Web Protocols |
MalwareTSCookie | TSCookie can multiple protocols including HTTP and HTTPS in communication with command and control (C2) servers. |
| T1071.001 Web Protocols |
MalwareLatrodectus | Latrodectus can send registration information to C2 via HTTP `POST`. |
| T1071.001 Web Protocols |
MalwareSaint Bot | Saint Bot has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareChaes | Chaes has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareCharmPower | CharmPower can use HTTP to communicate with C2. |
| T1071.001 Web Protocols |
MalwareMuddyViper | MuddyViper has used HTTP GET requests over port 443 and with the WINHTTP_FLAG_SECURE set to SSL/TLS via the WinHTTP API. |
| T1071.001 Web Protocols |
Malware3PARA RAT | 3PARA RAT uses HTTP for command and control. |
| T1071.001 Web Protocols |
MalwareBundlore | Bundlore uses HTTP requests for C2. |
| T1071.001 Web Protocols |
MalwareSMOKEDHAM | SMOKEDHAM has communicated with its C2 servers via HTTPS and HTTP POST requests. |
| T1071.001 Web Protocols |
MalwareMori | Mori can communicate using HTTP over IPv4 or IPv6 depending on a flag set. |
| T1071.001 Web Protocols |
MalwareQUADAGENT | QUADAGENT uses HTTPS and HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareSagerunex | Sagerunex communicates via HTTPS, at times using a hard-coded User Agent of `Mozilla/5.0 (compatible; MSIE 7.0; Win32)`. |
| T1071.001 Web Protocols |
MalwareSys10 | Sys10 uses HTTP for C2. |
| T1071.001 Web Protocols |
Malwarepngdowner | pngdowner uses HTTP for command and control. |
| T1071.001 Web Protocols |
MalwareGlassWorm | GlassWorm has used HTTP for C2 and extracts data from the HTTP response headers. |
| T1071.001 Web Protocols |
MalwareUroburos | Uroburos can use a custom HTTP-based protocol for large data communications that can blend with normal network traffic by riding on top of standard HTTP. |
| T1071.001 Web Protocols |
MalwareMetamorfo | Metamorfo has used HTTP for C2. |
| T1071.001 Web Protocols |
MalwareTrojan.Karagany | Trojan.Karagany can communicate with C2 via HTTP POST requests. |
| T1071.001 Web Protocols |
MalwareMagicRAT | MagicRAT uses HTTP POST communication for command and control. |
| T1071.001 Web Protocols |
MalwareKONNI | KONNI has used HTTP POST for C2. |
| T1071.001 Web Protocols |
MalwareWinnti for Linux | Winnti for Linux has used HTTP in outbound communications. |
| T1071.001 Web Protocols |
MalwareShamoon | Shamoon has used HTTP for C2. |
| T1071.001 Web Protocols |
MalwareJHUHUGIT | JHUHUGIT variants have communicated with C2 servers over HTTP and HTTPS. |
| T1071.001 Web Protocols |
MalwareBLUELIGHT | BLUELIGHT can use HTTP/S for C2 using the Microsoft Graph API. |
| T1071.001 Web Protocols |
MalwareKGH_SPY | KGH_SPY can send data to C2 with HTTP POST requests. |
| T1071.001 Web Protocols |
Malwaredown_new | down_new has the ability to use HTTP in C2 communications. |
| T1071.001 Web Protocols |
MalwareIxeshe | Ixeshe uses HTTP for command and control. |
| T1071.001 Web Protocols |
MalwareMicropsia | Micropsia uses HTTP and HTTPS for C2 network communications. |
| T1071.001 Web Protocols |
MalwareRedLine Stealer | RedLine Stealer has utilized HTTP for C2 communications. RedLine Stealer has also conducted C2 communications to hardcoded C2 servers over HTTPS. RedLine Stealer has leveraged SOAP protocol for C2 communications. |
| T1071.001 Web Protocols |
MalwareVBShower | VBShower has attempted to obtain a VBS script from command and control (C2) nodes over HTTP. |
| T1071.001 Web Protocols |
MalwareOopsIE | OopsIE uses HTTP for C2 communications. |
| T1071.001 Web Protocols |
Malware4H RAT | 4H RAT uses HTTP for command and control. |
| T1071.001 Web Protocols |
MalwareDealersChoice | DealersChoice uses HTTP for communication with the C2 server. |
| T1071.001 Web Protocols |
MalwareLitePower | LitePower can use HTTP and HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwareCrutch | Crutch has conducted C2 communications with a Dropbox account using the HTTP API. |
| T1071.001 Web Protocols |
MalwareRTM | RTM has initiated connections to external domains using HTTPS. |
| T1071.001 Web Protocols |
MalwareQUIETCANARY | QUIETCANARY can use HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwarePHPsert | PHPsert can retrieve remote files using HTTP POST. |
| T1071.001 Web Protocols |
MalwareHikit | Hikit has used HTTP for C2. |
| T1071.001 Web Protocols |
MalwareStrelaStealer | StrelaStealer communicates externally via HTTP POST with encrypted content. |
| T1071.001 Web Protocols |
MalwareGrandoreiro | Grandoreiro has the ability to use HTTP in C2 communications. |
| T1071.001 Web Protocols |
MalwareLiteDuke | LiteDuke can use HTTP GET requests in C2 communications. |
| T1071.001 Web Protocols |
MalwareSakula | Sakula uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareVaporRage | VaporRage can use HTTP to download shellcode from compromised websites. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.