ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1071.001
Web Protocols
MalwarePteranodon

Pteranodon can use HTTP for C2.

T1071.001
Web Protocols
MalwareDarkTortilla

DarkTortilla has used HTTP and HTTPS for C2.

T1071.001
Web Protocols
MalwareBeaverTail

BeaverTail has used HTTP GET request to download malicious payloads to include InvisibleFerret and HTTP POST to exfiltrate data to C2 infrastructure.

T1071.001
Web Protocols
MalwareROKRAT

ROKRAT can use HTTP and HTTPS for command and control communication.

T1071.001
Web Protocols
MalwareCORESHELL

CORESHELL can communicate over HTTP for C2.

T1071.001
Web Protocols
MalwareDarkWatchman

DarkWatchman uses HTTPS for command and control.

T1071.001
Web Protocols
MalwareDyre

Dyre uses HTTPS for C2 communications.

T1071.001
Web Protocols
MalwareBlackMould

BlackMould can send commands to C2 in the body of HTTP POST requests.

T1071.001
Web Protocols
MalwareBBSRAT

BBSRAT uses GET and POST requests over HTTP or HTTPS for command and control to obtain commands and send ZLIB compressed data back to the C2 server.

T1071.001
Web Protocols
MalwarePlugX

PlugX can be configured to use HTTP for command and control. PlugX has also used HTTPS for C2.

T1071.001
Web Protocols
MalwareReaver

Some Reaver variants use HTTP for C2.

T1071.001
Web Protocols
MalwareBisonal

Bisonal has used HTTP for C2 communications.

T1071.001
Web Protocols
MalwareS-Type

S-Type uses HTTP for C2.

T1071.001
Web Protocols
MalwareLumma Stealer

Lumma Stealer has used HTTP and HTTP for command and control communication.

T1071.001
Web Protocols
MalwareSeaDuke

SeaDuke uses HTTP and HTTPS for C2.

T1071.001
Web Protocols
MalwareDustySky

DustySky has used both HTTP and HTTPS for C2.

T1071.001
Web Protocols
MalwareRemsec

Remsec is capable of using HTTP and HTTPS for C2.

T1071.001
Web Protocols
MalwareExplosive

Explosive has used HTTP for communication.

T1071.001
Web Protocols
MalwareXbash

Xbash uses HTTP for C2 communications.

T1071.001
Web Protocols
MalwareEpic

Epic uses HTTP and HTTPS for C2 communications.

T1071.001
Web Protocols
MalwarePeppy

Peppy can use HTTP to communicate with C2.

T1071.001
Web Protocols
MalwareKEYPLUG

KEYPLUG has the ability to communicate over HTTP and WebSocket Protocol (WSS) for C2.

T1071.001
Web Protocols
MalwareDEATHRANSOM

DEATHRANSOM can use HTTPS to download files.

T1071.001
Web Protocols
MalwareClambling

Clambling has the ability to communicate over HTTP.

T1071.001
Web Protocols
MalwareMongall

Mongall can use HTTP for C2 communication.

T1071.001
Web Protocols
MalwareLockBit 3.0

LockBit 3.0 can use HTTP to send victim host information to C2.

T1071.001
Web Protocols
MalwareSVCReady

SVCReady can communicate with its C2 servers via HTTP.

T1071.001
Web Protocols
MalwareThiefQuest

ThiefQuest uploads files via unencrypted HTTP.

T1071.001
Web Protocols
MalwareFoggyWeb

FoggyWeb has the ability to communicate with C2 servers over HTTP GET/POST requests.

T1071.001
Web Protocols
MalwareNGLite

NGLite will initially beacon out to the NKN network via an HTTP POST over TCP 30003.

T1071.001
Web Protocols
MalwareCarbanak

The Carbanak malware communicates to its command server using HTTP with an encrypted payload.

T1071.001
Web Protocols
MalwareCreepyDrive

CreepyDrive can use HTTPS for C2 using the Microsoft Graph API.

T1071.001
Web Protocols
MalwareElise

Elise communicates over HTTP or HTTPS for C2.

T1071.001
Web Protocols
MalwareGazer

Gazer communicates with its C2 servers over HTTP.

T1071.001
Web Protocols
MalwareTSCookie

TSCookie can multiple protocols including HTTP and HTTPS in communication with command and control (C2) servers.

T1071.001
Web Protocols
MalwareLatrodectus

Latrodectus can send registration information to C2 via HTTP `POST`.

T1071.001
Web Protocols
MalwareSaint Bot

Saint Bot has used HTTP for C2 communications.

T1071.001
Web Protocols
MalwareChaes

Chaes has used HTTP for C2 communications.

T1071.001
Web Protocols
MalwareCharmPower

CharmPower can use HTTP to communicate with C2.

T1071.001
Web Protocols
MalwareMuddyViper

MuddyViper has used HTTP GET requests over port 443 and with the WINHTTP_FLAG_SECURE set to SSL/TLS via the WinHTTP API.

T1071.001
Web Protocols
Malware3PARA RAT

3PARA RAT uses HTTP for command and control.

T1071.001
Web Protocols
MalwareBundlore

Bundlore uses HTTP requests for C2.

T1071.001
Web Protocols
MalwareSMOKEDHAM

SMOKEDHAM has communicated with its C2 servers via HTTPS and HTTP POST requests.

T1071.001
Web Protocols
MalwareMori

Mori can communicate using HTTP over IPv4 or IPv6 depending on a flag set.

T1071.001
Web Protocols
MalwareQUADAGENT

QUADAGENT uses HTTPS and HTTP for C2 communications.

T1071.001
Web Protocols
MalwareSagerunex

Sagerunex communicates via HTTPS, at times using a hard-coded User Agent of `Mozilla/5.0 (compatible; MSIE 7.0; Win32)`.

T1071.001
Web Protocols
MalwareSys10

Sys10 uses HTTP for C2.

T1071.001
Web Protocols
Malwarepngdowner

pngdowner uses HTTP for command and control.

T1071.001
Web Protocols
MalwareGlassWorm

GlassWorm has used HTTP for C2 and extracts data from the HTTP response headers.

T1071.001
Web Protocols
MalwareUroburos

Uroburos can use a custom HTTP-based protocol for large data communications that can blend with normal network traffic by riding on top of standard HTTP.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.