Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1070.004 File Deletion |
GroupFIN8 | FIN8 has deleted tmp and prefetch files during post compromise cleanup activities. FIN8 has also deleted PowerShell scripts to evade detection on compromised machines. |
| T1070.005 Network Share Connection Removal |
GroupThreat Group-3390 | Threat Group-3390 has detached network shares after exfiltrating files, likely to evade detection. |
| T1070.006 Timestomp |
GroupAPT38 | APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host. |
| T1070.006 Timestomp |
GroupKimsuky | Kimsuky has manipulated timestamps for creation or compilation dates to defeat anti-forensics. |
| T1070.006 Timestomp |
GroupAPT32 | APT32 has used scheduled task raw XML with a backdated timestamp of June 2, 2016. The group has also set the creation time of the files dropped by the second stage of the exploit to match the creation time of kernel32.dll. Additionally, APT32 has used a random value to modify the timestamp of the file storing the clientID. |
| T1070.006 Timestomp |
GroupMustang Panda | Mustang Panda has modified file timestamps from the export address table (EAT) in malware to make it difficult to identify creation times. |
| T1070.006 Timestomp |
GroupRocke | Rocke has changed the time stamp of certain files. |
| T1070.006 Timestomp |
GroupUNC3886 | UNC3886 has used scripts to timestomp ESXi hosts prior to installing malicious vSphere Installation Bundles (VIBs). |
| T1070.006 Timestomp |
GroupAPT29 | APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. |
| T1070.006 Timestomp |
GroupChimera | Chimera has used a Windows version of the Linux |
| T1070.006 Timestomp |
GroupAPT28 | APT28 has performed timestomping on victim files. |
| T1070.006 Timestomp |
GroupAPT5 | APT5 has modified file timestamps. |
| T1070.006 Timestomp |
GroupLazarus Group | Several Lazarus Group malware families use timestomping, including modifying the last write timestamp of a specified Registry key to a random date, as well as copying the timestamp for legitimate .exe files (such as calc.exe or mspaint.exe) to its dropped files. |
| T1070.007 Clear Network Connection History and Configurations |
GroupVolt Typhoon | Volt Typhoon has inspected server logs to remove their IPs. |
| T1070.007 Clear Network Connection History and Configurations |
GroupUNC3886 | UNC3886 has cleared specific events that contained the threat actor’s IP address from multiple log sources. |
| T1070.008 Clear Mailbox Data |
GroupScattered Spider | Scattered Spider has manually deleted emails notifying users of suspicious account activity. |
| T1070.008 Clear Mailbox Data |
GroupAPT42 | APT42 has deleted login notification emails and has cleared the Sent folder to cover their tracks. |
| T1071 Application Layer Protocol |
GroupTeamTNT | TeamTNT has used an IRC bot for C2 communications. |
| T1071 Application Layer Protocol |
GroupRocke | Rocke issued wget requests from infected systems to the C2. |
| T1071 Application Layer Protocol |
GroupINC Ransom | INC Ransom has used valid accounts over RDP to connect to targeted systems. |
| T1071 Application Layer Protocol |
GroupVelvet Ant | Velvet Ant has used reverse SSH tunnels to communicate to victim devices. |
| T1071 Application Layer Protocol |
GroupMagic Hound | Magic Hound malware has used IRC for C2. |
| T1071.001 Web Protocols |
GroupAPT38 | APT38 used a backdoor, QUICKRIDE, to communicate to the C2 server over HTTP and HTTPS. |
| T1071.001 Web Protocols |
GroupBlackByte | BlackByte collected victim device information then transmitted this via HTTP POST to command and control infrastructure. |
| T1071.001 Web Protocols |
GroupKimsuky | Kimsuky has used HTTP GET and POST requests for C2. |
| T1071.001 Web Protocols |
GroupAPT41 | APT41 used HTTP to download payloads for CVE-2019-19781 and CVE-2020-10189 exploits. |
| T1071.001 Web Protocols |
GroupAPT32 | APT32 has used JavaScript that communicates over HTTP or HTTPS to attacker controlled domains to download additional frameworks. The group has also used downloaded encrypted payloads over HTTP. |
| T1071.001 Web Protocols |
GroupHAFNIUM | HAFNIUM has used open-source C2 frameworks, including Covenant. |
| T1071.001 Web Protocols |
GroupMuddyWater | MuddyWater has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
GroupRedEcho | RedEcho network activity is associated with SSL traffic via TCP 443 and proxied HTTP traffic over non-standard ports. |
| T1071.001 Web Protocols |
GroupGamaredon Group | Gamaredon Group has used HTTP and HTTPS for C2 communications. |
| T1071.001 Web Protocols |
GroupTeamTNT | TeamTNT has the `curl` command to send credentials over HTTP and the `curl` and `wget` commands to download new software. TeamTNT has also used a custom user agent HTTP header in shell scripts. |
| T1071.001 Web Protocols |
GroupSandworm Team | Sandworm Team's BCS-server tool connects to the designated C2 server via HTTP. |
| T1071.001 Web Protocols |
GroupAPT18 | APT18 uses HTTP for C2 communications. |
| T1071.001 Web Protocols |
GroupSidewinder | Sidewinder has used HTTP in C2 communications. |
| T1071.001 Web Protocols |
GroupMustang Panda | Mustang Panda has communicated with its C2 via HTTP POST requests. |
| T1071.001 Web Protocols |
GroupRocke | Rocke has executed wget and curl commands to Pastebin over the HTTPS protocol. |
| T1071.001 Web Protocols |
GroupAPT39 | APT39 has used HTTP in communications with C2. |
| T1071.001 Web Protocols |
GroupAPT37 | APT37 uses HTTPS to conceal C2 communications. |
| T1071.001 Web Protocols |
GroupOilRig | OilRig has used HTTP for C2. |
| T1071.001 Web Protocols |
GroupHigaisa | Higaisa used HTTP and HTTPS to send data back to its C2 server. |
| T1071.001 Web Protocols |
GroupTropic Trooper | Tropic Trooper has used HTTP in communication with the C2. |
| T1071.001 Web Protocols |
GroupOrangeworm | Orangeworm has used HTTP for C2. |
| T1071.001 Web Protocols |
GroupSea Turtle | Sea Turtle connected over TCP using HTTP to establish command and control channels. |
| T1071.001 Web Protocols |
GroupKe3chang | Ke3chang malware including RoyalCli and BS2005 have communicated over HTTP with the C2 server through Internet Explorer (IE) by using the COM interface IWebBrowser2. |
| T1071.001 Web Protocols |
GroupConfucius | Confucius has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
GroupWinter Vivern | Winter Vivern uses HTTP and HTTPS protocols for exfiltration and command and control activity. |
| T1071.001 Web Protocols |
GroupSilverTerrier | SilverTerrier uses HTTP for C2 communications. |
| T1071.001 Web Protocols |
GroupTurla | Turla has used HTTP and HTTPS for C2 communications. |
| T1071.001 Web Protocols |
GroupTA505 | TA505 has used HTTP to communicate with C2 nodes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.