ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1071.001×

344 examples

TechniqueUsed byProcedure example
T1071.001
Web Protocols
MalwareCozyCar

CozyCar's main method of communicating with its C2 servers is using HTTP or HTTPS.

T1071.001
Web Protocols
MalwareKevin

Variants of Kevin can communicate with C2 over HTTP.

T1071.001
Web Protocols
MalwareAgent Tesla

Agent Tesla has used HTTP for C2 communications.

T1071.001
Web Protocols
Malwarehttpclient

httpclient uses HTTP for command and control.

T1071.001
Web Protocols
MalwarePOWERTON

POWERTON has used HTTP/HTTPS for C2 traffic.

T1071.001
Web Protocols
MalwareBADNEWS

BADNEWS establishes a backdoor over HTTP.

T1071.001
Web Protocols
MalwareGoopy

Goopy has the ability to communicate with its C2 over HTTP.

T1071.001
Web Protocols
MalwareShadowPad

ShadowPad communicates over HTTP to retrieve a string that is decoded into a C2 server URL.

T1071.001
Web Protocols
MalwareRemexi

Remexi uses BITSAdmin to communicate with the C2 server over HTTP.

T1071.001
Web Protocols
MalwareQakBot

QakBot has the ability to use HTTP and HTTPS in communication with C2 servers.

T1071.001
Web Protocols
MalwareGelsemium

Gelsemium can use HTTP/S in C2 communications.

T1071.001
Web Protocols
MalwareHelminth

Helminth can use HTTP for C2.

T1071.001
Web Protocols
MalwareDridex

Dridex has used POST requests and HTTPS for C2 communications.

T1071.001
Web Protocols
MalwareBBK

BBK has the ability to use HTTP in communications with C2.

T1071.001
Web Protocols
MalwareKomplex

The Komplex C2 channel uses HTTP POST requests.

T1071.001
Web Protocols
MalwareComnie

Comnie uses HTTP for C2 communication.

T1071.001
Web Protocols
MalwareVasport

Vasport creates a backdoor by making a connection using a HTTP POST.

T1071.001
Web Protocols
MalwareMacSpy

MacSpy uses HTTP for command and control.

T1071.001
Web Protocols
MalwareBACKSPACE

BACKSPACE uses HTTP as a transport to communicate with its command server.

T1071.001
Web Protocols
MalwareUPPERCUT

UPPERCUT has used HTTP for C2, including sending error codes in cookie headers.

T1071.001
Web Protocols
MalwareADVSTORESHELL

ADVSTORESHELL connects to port 80 of a C2 server using Wininet API. Data is exchanged via HTTP POSTs.

T1071.001
Web Protocols
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has used HTTP and HTTPS for C2 communications.

T1071.001
Web Protocols
MalwareXORIndex Loader

XORIndex Loader has used HTTPS POST to communicate with C2.

T1071.001
Web Protocols
MalwareSmall Sieve

Small Sieve can contact actor-controlled C2 servers by using the Telegram API over HTTPS.

T1071.001
Web Protocols
ToolCovenant

Covenant can establish command and control via HTTP.

T1071.001
Web Protocols
ToolShimRatReporter

ShimRatReporter communicated over HTTP with preconfigured C2 servers.

T1071.001
Web Protocols
ToolSliver

Sliver has the ability to support C2 communications over HTTP and HTTPS.

T1071.001
Web Protocols
Toolevilginx2

evilginx2 can proxy HTTPS connections between victims and destination websites.

T1071.001
Web Protocols
ToolEmpire

Empire can conduct command and control over protocols like HTTP and HTTPS.

T1071.001
Web Protocols
ToolFRP

FRP has the ability to use HTTP and HTTPS to enable the forwarding of requests for internal services via domain name.

T1071.001
Web Protocols
ToolPcShare

PcShare has used HTTP for C2 communication.

T1071.001
Web Protocols
ToolPoshC2

PoshC2 can use protocols like HTTP/HTTPS for command and control traffic.

T1071.001
Web Protocols
ToolCSPY Downloader

CSPY Downloader can use GET requests to download additional payloads from C2.

T1071.001
Web Protocols
ToolBrute Ratel C4

Brute Ratel C4 can use HTTPS and HTTPS for C2 communication.

T1071.001
Web Protocols
ToolOut1

Out1 can use HTTP and HTTPS in communications with remote hosts.

T1071.001
Web Protocols
ToolMCMD

MCMD can use HTTPS in communication with C2 web servers.

T1071.001
Web Protocols
ToolDonut

Donut can use HTTP to download previously staged shellcode payloads.

T1071.001
Web Protocols
ToolKoadic

Koadic has used HTTP for C2 communications.

T1071.001
Web Protocols
ToolPupy

Pupy can communicate over HTTP for C2.

T1071.001
Web Protocols
ToolMythic

Mythic supports HTTP-based C2 profiles.

T1071.001
Web Protocols
ToolQuick Assist

Quick Assist communicates over TCP 443 via HTTPS to a remote session server, under which RDP traffic is transferred.

T1071.001
Web Protocols
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has used `curl` to upload stolen data to attacker controlled domains.

T1071.001
Web Protocols
MalwareMini Shai-Hulud

Mini Shai-Hulud has has exfiltrated data through the use of HTTPS POST requests to C2 domains.

T1071.001
Web Protocols
MalwareKali365

Kali365's desktop client has made Microsoft Graph API calls using the distinct User-Agent string `kali365-live/1.0.0` to access victim mailboxes and enumerate account data following OAuth token capture.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.