Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
MalwareMetamorfo | Metamorfo has used HTTP for C2. |
| T1071.001 Web Protocols |
MalwareTrojan.Karagany | Trojan.Karagany can communicate with C2 via HTTP POST requests. |
| T1071.001 Web Protocols |
MalwareMagicRAT | MagicRAT uses HTTP POST communication for command and control. |
| T1071.001 Web Protocols |
MalwareKONNI | KONNI has used HTTP POST for C2. |
| T1071.001 Web Protocols |
MalwareWinnti for Linux | Winnti for Linux has used HTTP in outbound communications. |
| T1071.001 Web Protocols |
MalwareShamoon | Shamoon has used HTTP for C2. |
| T1071.001 Web Protocols |
MalwareJHUHUGIT | JHUHUGIT variants have communicated with C2 servers over HTTP and HTTPS. |
| T1071.001 Web Protocols |
MalwareBLUELIGHT | BLUELIGHT can use HTTP/S for C2 using the Microsoft Graph API. |
| T1071.001 Web Protocols |
MalwareKGH_SPY | KGH_SPY can send data to C2 with HTTP POST requests. |
| T1071.001 Web Protocols |
Malwaredown_new | down_new has the ability to use HTTP in C2 communications. |
| T1071.001 Web Protocols |
MalwareIxeshe | Ixeshe uses HTTP for command and control. |
| T1071.001 Web Protocols |
MalwareMicropsia | Micropsia uses HTTP and HTTPS for C2 network communications. |
| T1071.001 Web Protocols |
MalwareRedLine Stealer | RedLine Stealer has utilized HTTP for C2 communications. RedLine Stealer has also conducted C2 communications to hardcoded C2 servers over HTTPS. RedLine Stealer has leveraged SOAP protocol for C2 communications. |
| T1071.001 Web Protocols |
MalwareVBShower | VBShower has attempted to obtain a VBS script from command and control (C2) nodes over HTTP. |
| T1071.001 Web Protocols |
MalwareOopsIE | OopsIE uses HTTP for C2 communications. |
| T1071.001 Web Protocols |
Malware4H RAT | 4H RAT uses HTTP for command and control. |
| T1071.001 Web Protocols |
MalwareDealersChoice | DealersChoice uses HTTP for communication with the C2 server. |
| T1071.001 Web Protocols |
MalwareLitePower | LitePower can use HTTP and HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwareCrutch | Crutch has conducted C2 communications with a Dropbox account using the HTTP API. |
| T1071.001 Web Protocols |
MalwareRTM | RTM has initiated connections to external domains using HTTPS. |
| T1071.001 Web Protocols |
MalwareQUIETCANARY | QUIETCANARY can use HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwarePHPsert | PHPsert can retrieve remote files using HTTP POST. |
| T1071.001 Web Protocols |
MalwareHikit | Hikit has used HTTP for C2. |
| T1071.001 Web Protocols |
MalwareStrelaStealer | StrelaStealer communicates externally via HTTP POST with encrypted content. |
| T1071.001 Web Protocols |
MalwareGrandoreiro | Grandoreiro has the ability to use HTTP in C2 communications. |
| T1071.001 Web Protocols |
MalwareLiteDuke | LiteDuke can use HTTP GET requests in C2 communications. |
| T1071.001 Web Protocols |
MalwareSakula | Sakula uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareVaporRage | VaporRage can use HTTP to download shellcode from compromised websites. |
| T1071.001 Web Protocols |
MalwareSibot | Sibot communicated with its C2 server via HTTP GET requests. |
| T1071.001 Web Protocols |
MalwareDrovorub | Drovorub can use the WebSocket protocol and has initiated communication with C2 servers with an HTTP Upgrade request. |
| T1071.001 Web Protocols |
MalwareShark | Shark has the ability to use HTTP in C2 communications. |
| T1071.001 Web Protocols |
MalwareBazar | Bazar can use HTTP and HTTPS over ports 80 and 443 in C2 communications. |
| T1071.001 Web Protocols |
MalwarePULSECHECK | PULSECHECK can check HTTP request headers for a specific backdoor key and if found will output the result of the command in the variable `HTTP_X_CMD.` |
| T1071.001 Web Protocols |
MalwareBadPatch | BadPatch uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareRATANKBA | RATANKBA uses HTTP/HTTPS for command and control communication. |
| T1071.001 Web Protocols |
MalwareSUGARDUMP | A SUGARDUMP variant has used HTTP for C2. |
| T1071.001 Web Protocols |
MalwareXLoader | XLoader uses HTTP and HTTPS for command and control communication. |
| T1071.001 Web Protocols |
MalwareABK | ABK has the ability to use HTTP in communications with C2. |
| T1071.001 Web Protocols |
MalwareFinal1stspy | Final1stspy uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareKapeka | Kapeka utilizes HTTP for command and control. |
| T1071.001 Web Protocols |
MalwareZebrocy | Zebrocy uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwarePandora | Pandora can communicate over HTTP. |
| T1071.001 Web Protocols |
MalwareSpeakUp | SpeakUp uses POST and GET requests over HTTP to communicate with its main C&C server. |
| T1071.001 Web Protocols |
MalwareOwaAuth | OwaAuth uses incoming HTTP requests with a username keyword and commands and handles them as instructions to perform actions. |
| T1071.001 Web Protocols |
MalwareCobalt Strike | Cobalt Strike can use a custom command and control protocol that can be encapsulated in HTTP or HTTPS. All protocols use their standard assigned ports. |
| T1071.001 Web Protocols |
MalwareSampleCheck5000 | SampleCheck5000 can use the Exchange Web Services API for C2 communication. |
| T1071.001 Web Protocols |
MalwareSUNBURST | SUNBURST communicated via HTTP GET or HTTP POST requests to third party servers for C2. |
| T1071.001 Web Protocols |
MalwareEvilBunny | EvilBunny has executed C2 commands directly via HTTP. |
| T1071.001 Web Protocols |
MalwareServHelper | ServHelper uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareREvil | REvil has used HTTP and HTTPS in communication with C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.