ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1071.001×

344 examples

TechniqueUsed byProcedure example
T1071.001
Web Protocols
MalwareSibot

Sibot communicated with its C2 server via HTTP GET requests.

T1071.001
Web Protocols
MalwareDrovorub

Drovorub can use the WebSocket protocol and has initiated communication with C2 servers with an HTTP Upgrade request.

T1071.001
Web Protocols
MalwareShark

Shark has the ability to use HTTP in C2 communications.

T1071.001
Web Protocols
MalwareBazar

Bazar can use HTTP and HTTPS over ports 80 and 443 in C2 communications.

T1071.001
Web Protocols
MalwarePULSECHECK

PULSECHECK can check HTTP request headers for a specific backdoor key and if found will output the result of the command in the variable `HTTP_X_CMD.`

T1071.001
Web Protocols
MalwareBadPatch

BadPatch uses HTTP for C2.

T1071.001
Web Protocols
MalwareRATANKBA

RATANKBA uses HTTP/HTTPS for command and control communication.

T1071.001
Web Protocols
MalwareSUGARDUMP

A SUGARDUMP variant has used HTTP for C2.

T1071.001
Web Protocols
MalwareXLoader

XLoader uses HTTP and HTTPS for command and control communication.

T1071.001
Web Protocols
MalwareABK

ABK has the ability to use HTTP in communications with C2.

T1071.001
Web Protocols
MalwareFinal1stspy

Final1stspy uses HTTP for C2.

T1071.001
Web Protocols
MalwareKapeka

Kapeka utilizes HTTP for command and control.

T1071.001
Web Protocols
MalwareZebrocy

Zebrocy uses HTTP for C2.

T1071.001
Web Protocols
MalwarePandora

Pandora can communicate over HTTP.

T1071.001
Web Protocols
MalwareSpeakUp

SpeakUp uses POST and GET requests over HTTP to communicate with its main C&C server.

T1071.001
Web Protocols
MalwareOwaAuth

OwaAuth uses incoming HTTP requests with a username keyword and commands and handles them as instructions to perform actions.

T1071.001
Web Protocols
MalwareCobalt Strike

Cobalt Strike can use a custom command and control protocol that can be encapsulated in HTTP or HTTPS. All protocols use their standard assigned ports.

T1071.001
Web Protocols
MalwareSampleCheck5000

SampleCheck5000 can use the Exchange Web Services API for C2 communication.

T1071.001
Web Protocols
MalwareSUNBURST

SUNBURST communicated via HTTP GET or HTTP POST requests to third party servers for C2.

T1071.001
Web Protocols
MalwareEvilBunny

EvilBunny has executed C2 commands directly via HTTP.

T1071.001
Web Protocols
MalwareServHelper

ServHelper uses HTTP for C2.

T1071.001
Web Protocols
MalwareREvil

REvil has used HTTP and HTTPS in communication with C2.

T1071.001
Web Protocols
MalwareRIPTIDE

APT12 has used RIPTIDE, a RAT that uses HTTP to communicate.

T1071.001
Web Protocols
MalwareValak

Valak has used HTTP in communications with C2.

T1071.001
Web Protocols
MalwareSamurai

Samurai can use a .NET HTTPListener class to receive and handle HTTP POST requests.

T1071.001
Web Protocols
MalwarePinchDuke

PinchDuke transfers files from the compromised host via HTTP or HTTPS to a C2 server.

T1071.001
Web Protocols
MalwareMilan

Milan can use HTTPS for communication with C2.

T1071.001
Web Protocols
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D can also use use HTTP POST and GET requests to send and receive C2 information.

T1071.001
Web Protocols
MalwareOilBooster

OilBooster can send HTTP `GET`, `POST`, `PUT`, and `DELETE` requests to the Microsoft Graph API over port 443 for C2 communication.

T1071.001
Web Protocols
MalwareOnionDuke

OnionDuke uses HTTP and HTTPS for C2.

T1071.001
Web Protocols
MalwareTaidoor

Taidoor has used HTTP GET and POST requests for C2.

T1071.001
Web Protocols
MalwareSUPERNOVA

SUPERNOVA had to receive an HTTP GET request containing a specific set of parameters in order to execute.

T1071.001
Web Protocols
MalwareCyclops Blink

Cyclops Blink can download files via HTTP and HTTPS.

T1071.001
Web Protocols
MalwareSeasalt

Seasalt uses HTTP for C2 communications.

T1071.001
Web Protocols
MalwarePLEAD

PLEAD has used HTTP for communications with command and control (C2) servers.

T1071.001
Web Protocols
MalwareRaccoon Stealer

Raccoon Stealer uses HTTP, and particularly HTTP POST requests, for command and control actions.

T1071.001
Web Protocols
MalwareIPsec Helper

IPsec Helper connects to command and control servers via HTTP POST requests based on parameters hard-coded into the malware.

T1071.001
Web Protocols
MalwareDaserf

Daserf uses HTTP for C2.

T1071.001
Web Protocols
MalwareGoldFinder

GoldFinder has used HTTP for C2.

T1071.001
Web Protocols
MalwareCarbon

Carbon can use HTTP in C2 communications.

T1071.001
Web Protocols
MalwareCardinal RAT

Cardinal RAT is downloaded using HTTP over port 443.

T1071.001
Web Protocols
MalwareDanBot

DanBot can use HTTP in C2 communication.

T1071.001
Web Protocols
MalwareGoldenSpy

GoldenSpy has used the Ryeol HTTP Client to facilitate HTTP internet communication.

T1071.001
Web Protocols
MalwareGold Dragon

Gold Dragon uses HTTP for communication to the control servers.

T1071.001
Web Protocols
MalwareRGDoor

RGDoor uses HTTP for C2 communications.

T1071.001
Web Protocols
MalwareRamsay

Ramsay has used HTTP for C2.

T1071.001
Web Protocols
MalwareNeo-reGeorg

Neo-reGeorg can use customized HTTP headers.

T1071.001
Web Protocols
MalwareAshTag

AshTag can use HTTP to send and receive data from C2.

T1071.001
Web Protocols
MalwareCarberp

Carberp has connected to C2 servers via HTTP.

T1071.001
Web Protocols
MalwareFRAMESTING

FRAMESTING can retrieve C2 commands from values stored in the `DSID` cookie from the current HTTP request or from decompressed zlib data within the request's `POST` data.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.