ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1070.004×

251 examples

TechniqueUsed byProcedure example
T1070.004
File Deletion
MalwareStealBit

StealBit can self-delete its executable file from the compromised system.

T1070.004
File Deletion
MalwareFELIXROOT

FELIXROOT deletes the .LNK file from the startup directory as well as the dropper components.

T1070.004
File Deletion
MalwareZxShell

ZxShell can delete files from the system.

T1070.004
File Deletion
MalwarePenquin

Penquin can delete downloaded executables after running them.

T1070.004
File Deletion
MalwareSPAWNCHIMERA

SPAWNCHIMERA has deleted generated files and folders from victim devices.

T1070.004
File Deletion
MalwareBabyShark

BabyShark has cleaned up all files associated with the secondary payload execution.

T1070.004
File Deletion
MalwareWinnti for Windows

Winnti for Windows can delete the DLLs for its various components from a compromised host.

T1070.004
File Deletion
MalwareTroll Stealer

Troll Stealer creates and can execute a BAT script that will delete the malware.

T1070.004
File Deletion
MalwareBLACKCOFFEE

BLACKCOFFEE has the capability to delete files.

T1070.004
File Deletion
MalwareMeteor

Meteor will delete the folder containing malicious scripts if it detects the hostname as `PIS-APP`, `PIS-MOB`, `WSUSPROXY`, or `PIS-DB`.

T1070.004
File Deletion
MalwarenjRAT

njRAT is capable of deleting files.

T1070.004
File Deletion
MalwareIceApple

IceApple can delete files and directories from targeted systems.

T1070.004
File Deletion
MalwareJPIN

JPIN's installer/uninstaller component deletes itself if it encounters a version of Windows earlier than Windows XP or identifies security-related processes running.

T1070.004
File Deletion
MalwaremetaMain

metaMain has deleted collected items after uploading the content to its C2 server.

T1070.004
File Deletion
MalwareHeyoka Backdoor

Heyoka Backdoor has the ability to delete folders and files from a targeted system.

T1070.004
File Deletion
MalwareHTTPBrowser

HTTPBrowser deletes its original installer file once installation is complete.

T1070.004
File Deletion
MalwareLunarWeb

LunarWeb can self-delete from a compromised host if safety checks of C2 connectivity fail.

T1070.004
File Deletion
MalwareKillDisk

KillDisk has the ability to quit and delete itself.

T1070.004
File Deletion
MalwareQilin

Qilin can delete itself from infected hosts after execution.

T1070.004
File Deletion
MalwareAppleJeus

AppleJeus has deleted the MSI file after installation.

T1070.004
File Deletion
MalwareKevin

Kevin can delete files created on the victim's machine.

T1070.004
File Deletion
MalwarePasam

Pasam creates a backdoor through which remote attackers can delete files.

T1070.004
File Deletion
MalwarePOWERSTATS

POWERSTATS can delete all files on the C:\, D:\, E:\ and, F:\ drives using PowerShell Remove-Item commands.

T1070.004
File Deletion
MalwareECCENTRICBANDWAGON

ECCENTRICBANDWAGON can delete log files generated from the malware stored at C:\windows\temp\tmp0207.

T1070.004
File Deletion
MalwareLinfo

Linfo creates a backdoor through which remote attackers can delete files.

T1070.004
File Deletion
MalwareQakBot

QakBot can delete folders and files including overwriting its executable with legitimate programs.

T1070.004
File Deletion
MalwareDOWNIISSA

DOWNIISSA can delete files after download.

T1070.004
File Deletion
MalwareHancitor

Hancitor has deleted files using the VBA kill function.

T1070.004
File Deletion
MalwareGelsemium

Gelsemium can delete its dropper component from the targeted system.

T1070.004
File Deletion
MalwarejRAT

jRAT has a function to delete files from the victim’s machine.

T1070.004
File Deletion
MalwareKomplex

The Komplex trojan supports file deletion.

T1070.004
File Deletion
MalwareDenis

Denis has a command to delete files from the victim’s machine.

T1070.004
File Deletion
MalwareMacSpy

MacSpy deletes any temporary files it creates

T1070.004
File Deletion
MalwareDtrack

Dtrack can remove its persistence and delete itself.

T1070.004
File Deletion
MalwareLoudMiner

LoudMiner deleted installation files after completion.

T1070.004
File Deletion
MalwareAzorult

Azorult can delete files from victim machines.

T1070.004
File Deletion
MalwareADVSTORESHELL

ADVSTORESHELL can delete files and directories.

T1070.004
File Deletion
MalwareStrifeWater

StrifeWater can self delete to cover its tracks.

T1070.004
File Deletion
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has deleted itself and the 'index.dat' file on a compromised machine to remove recent Internet history from the system.

T1070.004
File Deletion
MalwareFALLCHILL

FALLCHILL can delete malware and associated artifacts from the victim.

T1070.004
File Deletion
ToolSILENTTRINITY

SILENTTRINITY can remove files from the compromised host.

T1070.004
File Deletion
ToolPcShare

PcShare has deleted its files and components from a compromised host.

T1070.004
File Deletion
ToolCSPY Downloader

CSPY Downloader has the ability to self delete.

T1070.004
File Deletion
ToolRemcos

Remcos can delete files and folders from victim machines.

T1070.004
File Deletion
ToolImminent Monitor

Imminent Monitor has deleted files related to its dynamic debugger feature.

T1070.004
File Deletion
Toolcmd

cmd can be used to delete files from the file system.

T1070.004
File Deletion
ToolSDelete

SDelete deletes data in a way that makes it unrecoverable.

T1070.004
File Deletion
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has the ability to remove all staged files after exfiltration.

T1070.004
File Deletion
MalwareMini Shai-Hulud

Mini Shai-Hulud has deleted all artifacts to include gathered credential archives to reduce disk persistence and detection.

T1070.004
File Deletion
MalwareCanisterWorm

CanisterWorm has deleted itself after execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.