ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1071.001
Web Protocols
MalwareMetamorfo

Metamorfo has used HTTP for C2.

T1071.001
Web Protocols
MalwareTrojan.Karagany

Trojan.Karagany can communicate with C2 via HTTP POST requests.

T1071.001
Web Protocols
MalwareMagicRAT

MagicRAT uses HTTP POST communication for command and control.

T1071.001
Web Protocols
MalwareKONNI

KONNI has used HTTP POST for C2.

T1071.001
Web Protocols
MalwareWinnti for Linux

Winnti for Linux has used HTTP in outbound communications.

T1071.001
Web Protocols
MalwareShamoon

Shamoon has used HTTP for C2.

T1071.001
Web Protocols
MalwareJHUHUGIT

JHUHUGIT variants have communicated with C2 servers over HTTP and HTTPS.

T1071.001
Web Protocols
MalwareBLUELIGHT

BLUELIGHT can use HTTP/S for C2 using the Microsoft Graph API.

T1071.001
Web Protocols
MalwareKGH_SPY

KGH_SPY can send data to C2 with HTTP POST requests.

T1071.001
Web Protocols
Malwaredown_new

down_new has the ability to use HTTP in C2 communications.

T1071.001
Web Protocols
MalwareIxeshe

Ixeshe uses HTTP for command and control.

T1071.001
Web Protocols
MalwareMicropsia

Micropsia uses HTTP and HTTPS for C2 network communications.

T1071.001
Web Protocols
MalwareRedLine Stealer

RedLine Stealer has utilized HTTP for C2 communications. RedLine Stealer has also conducted C2 communications to hardcoded C2 servers over HTTPS. RedLine Stealer has leveraged SOAP protocol for C2 communications.

T1071.001
Web Protocols
MalwareVBShower

VBShower has attempted to obtain a VBS script from command and control (C2) nodes over HTTP.

T1071.001
Web Protocols
MalwareOopsIE

OopsIE uses HTTP for C2 communications.

T1071.001
Web Protocols
Malware4H RAT

4H RAT uses HTTP for command and control.

T1071.001
Web Protocols
MalwareDealersChoice

DealersChoice uses HTTP for communication with the C2 server.

T1071.001
Web Protocols
MalwareLitePower

LitePower can use HTTP and HTTPS for C2 communications.

T1071.001
Web Protocols
MalwareCrutch

Crutch has conducted C2 communications with a Dropbox account using the HTTP API.

T1071.001
Web Protocols
MalwareRTM

RTM has initiated connections to external domains using HTTPS.

T1071.001
Web Protocols
MalwareQUIETCANARY

QUIETCANARY can use HTTPS for C2 communications.

T1071.001
Web Protocols
MalwarePHPsert

PHPsert can retrieve remote files using HTTP POST.

T1071.001
Web Protocols
MalwareHikit

Hikit has used HTTP for C2.

T1071.001
Web Protocols
MalwareStrelaStealer

StrelaStealer communicates externally via HTTP POST with encrypted content.

T1071.001
Web Protocols
MalwareGrandoreiro

Grandoreiro has the ability to use HTTP in C2 communications.

T1071.001
Web Protocols
MalwareLiteDuke

LiteDuke can use HTTP GET requests in C2 communications.

T1071.001
Web Protocols
MalwareSakula

Sakula uses HTTP for C2.

T1071.001
Web Protocols
MalwareVaporRage

VaporRage can use HTTP to download shellcode from compromised websites.

T1071.001
Web Protocols
MalwareSibot

Sibot communicated with its C2 server via HTTP GET requests.

T1071.001
Web Protocols
MalwareDrovorub

Drovorub can use the WebSocket protocol and has initiated communication with C2 servers with an HTTP Upgrade request.

T1071.001
Web Protocols
MalwareShark

Shark has the ability to use HTTP in C2 communications.

T1071.001
Web Protocols
MalwareBazar

Bazar can use HTTP and HTTPS over ports 80 and 443 in C2 communications.

T1071.001
Web Protocols
MalwarePULSECHECK

PULSECHECK can check HTTP request headers for a specific backdoor key and if found will output the result of the command in the variable `HTTP_X_CMD.`

T1071.001
Web Protocols
MalwareBadPatch

BadPatch uses HTTP for C2.

T1071.001
Web Protocols
MalwareRATANKBA

RATANKBA uses HTTP/HTTPS for command and control communication.

T1071.001
Web Protocols
MalwareSUGARDUMP

A SUGARDUMP variant has used HTTP for C2.

T1071.001
Web Protocols
MalwareXLoader

XLoader uses HTTP and HTTPS for command and control communication.

T1071.001
Web Protocols
MalwareABK

ABK has the ability to use HTTP in communications with C2.

T1071.001
Web Protocols
MalwareFinal1stspy

Final1stspy uses HTTP for C2.

T1071.001
Web Protocols
MalwareKapeka

Kapeka utilizes HTTP for command and control.

T1071.001
Web Protocols
MalwareZebrocy

Zebrocy uses HTTP for C2.

T1071.001
Web Protocols
MalwarePandora

Pandora can communicate over HTTP.

T1071.001
Web Protocols
MalwareSpeakUp

SpeakUp uses POST and GET requests over HTTP to communicate with its main C&C server.

T1071.001
Web Protocols
MalwareOwaAuth

OwaAuth uses incoming HTTP requests with a username keyword and commands and handles them as instructions to perform actions.

T1071.001
Web Protocols
MalwareCobalt Strike

Cobalt Strike can use a custom command and control protocol that can be encapsulated in HTTP or HTTPS. All protocols use their standard assigned ports.

T1071.001
Web Protocols
MalwareSampleCheck5000

SampleCheck5000 can use the Exchange Web Services API for C2 communication.

T1071.001
Web Protocols
MalwareSUNBURST

SUNBURST communicated via HTTP GET or HTTP POST requests to third party servers for C2.

T1071.001
Web Protocols
MalwareEvilBunny

EvilBunny has executed C2 commands directly via HTTP.

T1071.001
Web Protocols
MalwareServHelper

ServHelper uses HTTP for C2.

T1071.001
Web Protocols
MalwareREvil

REvil has used HTTP and HTTPS in communication with C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.