Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
MalwareRIPTIDE | APT12 has used RIPTIDE, a RAT that uses HTTP to communicate. |
| T1071.001 Web Protocols |
MalwareValak | Valak has used HTTP in communications with C2. |
| T1071.001 Web Protocols |
MalwareSamurai | Samurai can use a .NET HTTPListener class to receive and handle HTTP POST requests. |
| T1071.001 Web Protocols |
MalwarePinchDuke | PinchDuke transfers files from the compromised host via HTTP or HTTPS to a C2 server. |
| T1071.001 Web Protocols |
MalwareMilan | Milan can use HTTPS for communication with C2. |
| T1071.001 Web Protocols |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D can also use use HTTP POST and GET requests to send and receive C2 information. |
| T1071.001 Web Protocols |
MalwareOilBooster | OilBooster can send HTTP `GET`, `POST`, `PUT`, and `DELETE` requests to the Microsoft Graph API over port 443 for C2 communication. |
| T1071.001 Web Protocols |
MalwareOnionDuke | OnionDuke uses HTTP and HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareTaidoor | Taidoor has used HTTP GET and POST requests for C2. |
| T1071.001 Web Protocols |
MalwareSUPERNOVA | SUPERNOVA had to receive an HTTP GET request containing a specific set of parameters in order to execute. |
| T1071.001 Web Protocols |
MalwareCyclops Blink | Cyclops Blink can download files via HTTP and HTTPS. |
| T1071.001 Web Protocols |
MalwareSeasalt | Seasalt uses HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwarePLEAD | PLEAD has used HTTP for communications with command and control (C2) servers. |
| T1071.001 Web Protocols |
MalwareRaccoon Stealer | Raccoon Stealer uses HTTP, and particularly HTTP POST requests, for command and control actions. |
| T1071.001 Web Protocols |
MalwareIPsec Helper | IPsec Helper connects to command and control servers via HTTP POST requests based on parameters hard-coded into the malware. |
| T1071.001 Web Protocols |
MalwareDaserf | Daserf uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareGoldFinder | GoldFinder has used HTTP for C2. |
| T1071.001 Web Protocols |
MalwareCarbon | Carbon can use HTTP in C2 communications. |
| T1071.001 Web Protocols |
MalwareCardinal RAT | Cardinal RAT is downloaded using HTTP over port 443. |
| T1071.001 Web Protocols |
MalwareDanBot | DanBot can use HTTP in C2 communication. |
| T1071.001 Web Protocols |
MalwareGoldenSpy | GoldenSpy has used the Ryeol HTTP Client to facilitate HTTP internet communication. |
| T1071.001 Web Protocols |
MalwareGold Dragon | Gold Dragon uses HTTP for communication to the control servers. |
| T1071.001 Web Protocols |
MalwareRGDoor | RGDoor uses HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareRamsay | Ramsay has used HTTP for C2. |
| T1071.001 Web Protocols |
MalwareNeo-reGeorg | Neo-reGeorg can use customized HTTP headers. |
| T1071.001 Web Protocols |
MalwareAshTag | AshTag can use HTTP to send and receive data from C2. |
| T1071.001 Web Protocols |
MalwareCarberp | Carberp has connected to C2 servers via HTTP. |
| T1071.001 Web Protocols |
MalwareFRAMESTING | FRAMESTING can retrieve C2 commands from values stored in the `DSID` cookie from the current HTTP request or from decompressed zlib data within the request's `POST` data. |
| T1071.001 Web Protocols |
MalwareTrailBlazer | TrailBlazer has used HTTP requests for C2. |
| T1071.001 Web Protocols |
MalwareMOPSLED | MOPSLED can communicate to C2 nodes over HTTP. |
| T1071.001 Web Protocols |
MalwareMore_eggs | More_eggs uses HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareOutSteel | OutSteel has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareBackConfig | BackConfig has the ability to use HTTPS for C2 communiations. |
| T1071.001 Web Protocols |
MalwarePowGoop | PowGoop can send HTTP GET requests to malicious servers. |
| T1071.001 Web Protocols |
MalwareBoomBox | BoomBox has used HTTP POST requests for C2. |
| T1071.001 Web Protocols |
MalwareLAMEHUG | LAMEHUG can use HTTP POST requests to exfiltrate data from compromised hosts to C2. |
| T1071.001 Web Protocols |
MalwareMango | Mango can retrieve C2 commands sent in HTTP responses. |
| T1071.001 Web Protocols |
MalwareWIREFIRE | WIREFIRE can respond to specific HTTP `POST` requests to `/api/v1/cav/client/visits`. |
| T1071.001 Web Protocols |
MalwareGrimAgent | GrimAgent has the ability to use HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareLookBack | LookBack’s C2 proxy tool sends data to a C2 server over HTTP. |
| T1071.001 Web Protocols |
MalwareSTEADYPULSE | STEADYPULSE can parse web requests made to a targeted server to determine the next stage of execution. |
| T1071.001 Web Protocols |
MalwareYAHOYAH | YAHOYAH uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareLokibot | Lokibot has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareCloudDuke | One variant of CloudDuke uses HTTP and HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareEgregor | Egregor has communicated with its C2 servers via HTTPS protocol. |
| T1071.001 Web Protocols |
MalwarePoetRAT | PoetRAT has used HTTP and HTTPs for C2 communications. |
| T1071.001 Web Protocols |
MalwareCHOPSTICK | Various implementations of CHOPSTICK communicate with C2 over HTTP. |
| T1071.001 Web Protocols |
MalwareStealBit | StealBit can use HTTP to exfiltrate files to actor-controlled infrastructure. |
| T1071.001 Web Protocols |
MalwareFELIXROOT | FELIXROOT uses HTTP and HTTPS to communicate with the C2 server. |
| T1071.001 Web Protocols |
MalwareZxShell | ZxShell has used HTTP for C2 connections. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.