Real-world descriptions of how a group, tool or campaign used a technique.
344 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
MalwareSibot | Sibot communicated with its C2 server via HTTP GET requests. |
| T1071.001 Web Protocols |
MalwareDrovorub | Drovorub can use the WebSocket protocol and has initiated communication with C2 servers with an HTTP Upgrade request. |
| T1071.001 Web Protocols |
MalwareShark | Shark has the ability to use HTTP in C2 communications. |
| T1071.001 Web Protocols |
MalwareBazar | Bazar can use HTTP and HTTPS over ports 80 and 443 in C2 communications. |
| T1071.001 Web Protocols |
MalwarePULSECHECK | PULSECHECK can check HTTP request headers for a specific backdoor key and if found will output the result of the command in the variable `HTTP_X_CMD.` |
| T1071.001 Web Protocols |
MalwareBadPatch | BadPatch uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareRATANKBA | RATANKBA uses HTTP/HTTPS for command and control communication. |
| T1071.001 Web Protocols |
MalwareSUGARDUMP | A SUGARDUMP variant has used HTTP for C2. |
| T1071.001 Web Protocols |
MalwareXLoader | XLoader uses HTTP and HTTPS for command and control communication. |
| T1071.001 Web Protocols |
MalwareABK | ABK has the ability to use HTTP in communications with C2. |
| T1071.001 Web Protocols |
MalwareFinal1stspy | Final1stspy uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareKapeka | Kapeka utilizes HTTP for command and control. |
| T1071.001 Web Protocols |
MalwareZebrocy | Zebrocy uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwarePandora | Pandora can communicate over HTTP. |
| T1071.001 Web Protocols |
MalwareSpeakUp | SpeakUp uses POST and GET requests over HTTP to communicate with its main C&C server. |
| T1071.001 Web Protocols |
MalwareOwaAuth | OwaAuth uses incoming HTTP requests with a username keyword and commands and handles them as instructions to perform actions. |
| T1071.001 Web Protocols |
MalwareCobalt Strike | Cobalt Strike can use a custom command and control protocol that can be encapsulated in HTTP or HTTPS. All protocols use their standard assigned ports. |
| T1071.001 Web Protocols |
MalwareSampleCheck5000 | SampleCheck5000 can use the Exchange Web Services API for C2 communication. |
| T1071.001 Web Protocols |
MalwareSUNBURST | SUNBURST communicated via HTTP GET or HTTP POST requests to third party servers for C2. |
| T1071.001 Web Protocols |
MalwareEvilBunny | EvilBunny has executed C2 commands directly via HTTP. |
| T1071.001 Web Protocols |
MalwareServHelper | ServHelper uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareREvil | REvil has used HTTP and HTTPS in communication with C2. |
| T1071.001 Web Protocols |
MalwareRIPTIDE | APT12 has used RIPTIDE, a RAT that uses HTTP to communicate. |
| T1071.001 Web Protocols |
MalwareValak | Valak has used HTTP in communications with C2. |
| T1071.001 Web Protocols |
MalwareSamurai | Samurai can use a .NET HTTPListener class to receive and handle HTTP POST requests. |
| T1071.001 Web Protocols |
MalwarePinchDuke | PinchDuke transfers files from the compromised host via HTTP or HTTPS to a C2 server. |
| T1071.001 Web Protocols |
MalwareMilan | Milan can use HTTPS for communication with C2. |
| T1071.001 Web Protocols |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D can also use use HTTP POST and GET requests to send and receive C2 information. |
| T1071.001 Web Protocols |
MalwareOilBooster | OilBooster can send HTTP `GET`, `POST`, `PUT`, and `DELETE` requests to the Microsoft Graph API over port 443 for C2 communication. |
| T1071.001 Web Protocols |
MalwareOnionDuke | OnionDuke uses HTTP and HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareTaidoor | Taidoor has used HTTP GET and POST requests for C2. |
| T1071.001 Web Protocols |
MalwareSUPERNOVA | SUPERNOVA had to receive an HTTP GET request containing a specific set of parameters in order to execute. |
| T1071.001 Web Protocols |
MalwareCyclops Blink | Cyclops Blink can download files via HTTP and HTTPS. |
| T1071.001 Web Protocols |
MalwareSeasalt | Seasalt uses HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwarePLEAD | PLEAD has used HTTP for communications with command and control (C2) servers. |
| T1071.001 Web Protocols |
MalwareRaccoon Stealer | Raccoon Stealer uses HTTP, and particularly HTTP POST requests, for command and control actions. |
| T1071.001 Web Protocols |
MalwareIPsec Helper | IPsec Helper connects to command and control servers via HTTP POST requests based on parameters hard-coded into the malware. |
| T1071.001 Web Protocols |
MalwareDaserf | Daserf uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareGoldFinder | GoldFinder has used HTTP for C2. |
| T1071.001 Web Protocols |
MalwareCarbon | Carbon can use HTTP in C2 communications. |
| T1071.001 Web Protocols |
MalwareCardinal RAT | Cardinal RAT is downloaded using HTTP over port 443. |
| T1071.001 Web Protocols |
MalwareDanBot | DanBot can use HTTP in C2 communication. |
| T1071.001 Web Protocols |
MalwareGoldenSpy | GoldenSpy has used the Ryeol HTTP Client to facilitate HTTP internet communication. |
| T1071.001 Web Protocols |
MalwareGold Dragon | Gold Dragon uses HTTP for communication to the control servers. |
| T1071.001 Web Protocols |
MalwareRGDoor | RGDoor uses HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareRamsay | Ramsay has used HTTP for C2. |
| T1071.001 Web Protocols |
MalwareNeo-reGeorg | Neo-reGeorg can use customized HTTP headers. |
| T1071.001 Web Protocols |
MalwareAshTag | AshTag can use HTTP to send and receive data from C2. |
| T1071.001 Web Protocols |
MalwareCarberp | Carberp has connected to C2 servers via HTTP. |
| T1071.001 Web Protocols |
MalwareFRAMESTING | FRAMESTING can retrieve C2 commands from values stored in the `DSID` cookie from the current HTTP request or from decompressed zlib data within the request's `POST` data. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.