ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1070×

27 examples

TechniqueUsed byProcedure example
T1070
Indicator Removal
MalwareOrz

Orz can overwrite Registry settings to reduce its visibility on the victim.

T1070
Indicator Removal
MalwareStuxnet

Stuxnet can delete OLE Automation and SQL stored procedures used to store malicious payloads.

T1070
Indicator Removal
MalwareIronWind

IronWind has used a .NET DLL named "exit-DN4-core.dll" to terminate malicious processes running on victim's systems.

T1070
Indicator Removal
MalwareSardonic

Sardonic has the ability to delete created WMI objects to evade detections.

T1070
Indicator Removal
MalwareBankshot

Bankshot deletes all artifacts associated with the malware from the infected machine.

T1070
Indicator Removal
MalwareDUSTTRAP

DUSTTRAP restores the `.text` section of compromised DLLs after malicious code is loaded into memory and before the file is closed.

T1070
Indicator Removal
MalwareNeoichor

Neoichor can clear the browser history on a compromised host by changing the `ClearBrowsingHistoryOnExit` value to 1 in the `HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Privacy` Registry key.

T1070
Indicator Removal
MalwareBlackEnergy

BlackEnergy has removed the watermark associated with enabling the TESTSIGNING boot configuration option by removing the relevant strings in the user32.dll.mui of the system.

T1070
Indicator Removal
MalwareRising Sun

Rising Sun can clear a memory blog in the process by overwriting it with junk bytes.

T1070
Indicator Removal
MalwareFlagpro

Flagpro can close specific Windows Security and Internet Explorer dialog boxes to mask external connections.

T1070
Indicator Removal
MalwareDarkWatchman

DarkWatchman can uninstall malicious components from the Registry, stop processes, and clear the browser history.

T1070
Indicator Removal
MalwareMultiLayer Wiper

MultiLayer Wiper uses a batch script to clear file system cache memory via the ProcessIdleTasks export in advapi32.dll as an anti-analysis and anti-forensics technique.

T1070
Indicator Removal
MalwareEVILNUM

EVILNUM has a function called "DeleteLeftovers" to remove certain artifacts of the attack.

T1070
Indicator Removal
MalwareMetamorfo

Metamorfo has a command to delete a Registry key it uses, \Software\Microsoft\Internet Explorer\notes.

T1070
Indicator Removal
MalwareBPFDoor

BPFDoor clears the file location `/proc/<PID>/environ` removing all environment variables for the process.

T1070
Indicator Removal
MalwareSDBbot

SDBbot has the ability to clean up and remove data structures from a compromised host.

T1070
Indicator Removal
MalwareSibot

Sibot will delete an associated registry key if a certain server response is received.

T1070
Indicator Removal
MalwareHermeticWiper

HermeticWiper can disable pop-up information about folders and desktop items and delete Registry keys to hide malicious services.

T1070
Indicator Removal
MalwareSUNBURST

SUNBURST removed HTTP proxy registry values to clean up traces of execution.

T1070
Indicator Removal
MalwareIPsec Helper

IPsec Helper can delete various registry keys related to its execution and use.

T1070
Indicator Removal
MalwareFunnyDream

FunnyDream has the ability to clean traces of malware deployment.

T1070
Indicator Removal
MalwareMaze

Maze has used the “Wow64RevertWow64FsRedirection” function following attempts to delete the shadow volumes, in order to leave the system in the same state as it was prior to redirection.

T1070
Indicator Removal
MalwareShadowPad

ShadowPad has deleted arbitrary Registry values.

T1070
Indicator Removal
ToolSILENTTRINITY

SILENTTRINITY can remove artifacts from the compromised host, including created Registry keys.

T1070
Indicator Removal
ToolCSPY Downloader

CSPY Downloader has the ability to remove values it writes to the Registry.

T1070
Indicator Removal
ToolRemcos

Remcos can clean saved cookies and logins from the web browser.

T1070
Indicator Removal
ToolDonut

Donut can erase file references to payloads in-memory after being reflectively loaded and executed.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.