ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1071.001×

344 examples

TechniqueUsed byProcedure example
T1071.001
Web Protocols
MalwareTrickBot

TrickBot uses HTTPS to communicate with its C2 servers, to get malware updates, modules that perform most of the malware logic and various configuration files.

T1071.001
Web Protocols
MalwareBLINDINGCAN

BLINDINGCAN has used HTTPS over port 443 for command and control.

T1071.001
Web Protocols
MalwareNinja

Ninja can use HTTP for C2 communications.

T1071.001
Web Protocols
MalwareRCSession

RCSession can use HTTP in C2 communications.

T1071.001
Web Protocols
MalwareSpark

Spark has used HTTP POST requests to communicate with its C2 server to receive commands.

T1071.001
Web Protocols
MalwareQuietSieve

QuietSieve can use HTTPS in C2 communications.

T1071.001
Web Protocols
MalwareBRICKSTORM

BRICKSTORM has communicated to hardcoded C2 through WebSockets (WSS) to include domains associated with Cloudflare Workers. BRICKSTORM has also leveraged Gorilla mux library to serve its HTTP API calls.

T1071.001
Web Protocols
MalwareAmadey

Amadey has used HTTP for C2 communications.

T1071.001
Web Protocols
MalwareNICECURL

NICECURL has used HTTPS for C2 communications.

T1071.001
Web Protocols
MalwareProxysvc

Proxysvc uses HTTP over SSL to communicate commands with the control server.

T1071.001
Web Protocols
MalwareTorisma

Torisma can use HTTP and HTTPS for C2 communications.

T1071.001
Web Protocols
MalwareNOKKI

NOKKI has used HTTP for C2 communications.

T1071.001
Web Protocols
MalwareStuxnet

Stuxnet uses HTTP to communicate with a command and control server.

T1071.001
Web Protocols
MalwareIronWind

IronWind can used HTTP to send information to C2 about the targeted system.

T1071.001
Web Protocols
MalwareGet2

Get2 has the ability to use HTTP to send information collected from an infected host to C2.

T1071.001
Web Protocols
MalwarePOWRUNER

POWRUNER can use HTTP for C2 communications.

T1071.001
Web Protocols
MalwareKOPILUWAK

KOPILUWAK has used HTTP POST requests to send data to C2.

T1071.001
Web Protocols
MalwareCOATHANGER

COATHANGER uses an HTTP GET request to initialize a follow-on TLS tunnel for command and control.

T1071.001
Web Protocols
MalwareSmoke Loader

Smoke Loader uses HTTP for C2.

T1071.001
Web Protocols
MalwareWindTail

WindTail has the ability to use HTTP for C2 communications.

T1071.001
Web Protocols
MalwarereGeorg

reGeorg can use HTTP to tunnel connections in and out of targeted networks.

T1071.001
Web Protocols
MalwareEmissary

Emissary uses HTTP or HTTPS for C2.

T1071.001
Web Protocols
MalwareExaramel for Linux

Exaramel for Linux uses HTTPS for C2 communications.

T1071.001
Web Protocols
MalwareBUBBLEWRAP

BUBBLEWRAP can communicate using HTTP or HTTPS.

T1071.001
Web Protocols
MalwareHAWKBALL

HAWKBALL has used HTTP to communicate with a single hard-coded C2 server.

T1071.001
Web Protocols
MalwareTAMECAT

TAMECAT has used HTTP for C2 communications.

T1071.001
Web Protocols
MalwareUrsnif

Ursnif has used HTTPS for C2.

T1071.001
Web Protocols
MalwareZLib

ZLib communicates over HTTP for C2.

T1071.001
Web Protocols
MalwareRedLeaves

RedLeaves can communicate to its C2 over HTTP and HTTPS if directed.

T1071.001
Web Protocols
MalwareTsundere Botnet

Tsundere Botnet has obtained the WebSocket C2 address by making remote procedure call (RPC) APIs to Ethereum blockchain nodes.

T1071.001
Web Protocols
MalwareFelismus

Felismus uses HTTP for C2.

T1071.001
Web Protocols
MalwareZeus Panda

Zeus Panda uses HTTP for C2 communications.

T1071.001
Web Protocols
MalwareGeminiDuke

GeminiDuke uses HTTP and HTTPS for command and control.

T1071.001
Web Protocols
MalwareHavoc

Havoc can use HTTP/S listeners to establish and maintain C2 communications.

T1071.001
Web Protocols
MalwareGravityRAT

GravityRAT uses HTTP for C2.

T1071.001
Web Protocols
MalwareInvisibleFerret

InvisibleFerret has used HTTP for C2 communications.

T1071.001
Web Protocols
MalwareBankshot

Bankshot uses HTTP for command and control communication.

T1071.001
Web Protocols
MalwareStrongPity

StrongPity can use HTTP and HTTPS in C2 communications.

T1071.001
Web Protocols
MalwarexCaon

xCaon has communicated with the C2 server by sending POST requests over HTTP.

T1071.001
Web Protocols
MalwarePony

Pony has sent collected information to the C2 via HTTP POST request.

T1071.001
Web Protocols
MalwareWinMM

WinMM uses HTTP for C2.

T1071.001
Web Protocols
MalwareTONESHELL

TONESHELL has utilized HTTP for a C2 protocol through HTTP POST. TONESHELL has also utilized HTTPS for C2.

T1071.001
Web Protocols
MalwareRainyDay

RainyDay can use HTTP in C2 communications.

T1071.001
Web Protocols
MalwareAppleSeed

AppleSeed has the ability to communicate with C2 over HTTP.

T1071.001
Web Protocols
MalwareLOWBALL

LOWBALL command and control occurs via HTTPS over port 443.

T1071.001
Web Protocols
MalwareNETWIRE

NETWIRE has the ability to communicate over HTTP.

T1071.001
Web Protocols
MalwareTinyTurla

TinyTurla can use HTTPS in C2 communications.

T1071.001
Web Protocols
MalwareBOOKWORM

BOOKWORM has communicated with its C2 via HTTP POST requests.

T1071.001
Web Protocols
MalwareHAMMERTOSS

The "Uploader" variant of HAMMERTOSS visits a hard-coded server over HTTP/S to download the images HAMMERTOSS uses to receive commands.

T1071.001
Web Protocols
MalwareOLDBAIT

OLDBAIT can use HTTP for C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.