Real-world descriptions of how a group, tool or campaign used a technique.
27 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1070 Indicator Removal |
MalwareOrz | Orz can overwrite Registry settings to reduce its visibility on the victim. |
| T1070 Indicator Removal |
MalwareStuxnet | Stuxnet can delete OLE Automation and SQL stored procedures used to store malicious payloads. |
| T1070 Indicator Removal |
MalwareIronWind | IronWind has used a .NET DLL named "exit-DN4-core.dll" to terminate malicious processes running on victim's systems. |
| T1070 Indicator Removal |
MalwareSardonic | Sardonic has the ability to delete created WMI objects to evade detections. |
| T1070 Indicator Removal |
MalwareBankshot | Bankshot deletes all artifacts associated with the malware from the infected machine. |
| T1070 Indicator Removal |
MalwareDUSTTRAP | DUSTTRAP restores the `.text` section of compromised DLLs after malicious code is loaded into memory and before the file is closed. |
| T1070 Indicator Removal |
MalwareNeoichor | Neoichor can clear the browser history on a compromised host by changing the `ClearBrowsingHistoryOnExit` value to 1 in the `HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Privacy` Registry key. |
| T1070 Indicator Removal |
MalwareBlackEnergy | BlackEnergy has removed the watermark associated with enabling the |
| T1070 Indicator Removal |
MalwareRising Sun | Rising Sun can clear a memory blog in the process by overwriting it with junk bytes. |
| T1070 Indicator Removal |
MalwareFlagpro | Flagpro can close specific Windows Security and Internet Explorer dialog boxes to mask external connections. |
| T1070 Indicator Removal |
MalwareDarkWatchman | DarkWatchman can uninstall malicious components from the Registry, stop processes, and clear the browser history. |
| T1070 Indicator Removal |
MalwareMultiLayer Wiper | MultiLayer Wiper uses a batch script to clear file system cache memory via the |
| T1070 Indicator Removal |
MalwareEVILNUM | EVILNUM has a function called "DeleteLeftovers" to remove certain artifacts of the attack. |
| T1070 Indicator Removal |
MalwareMetamorfo | Metamorfo has a command to delete a Registry key it uses, |
| T1070 Indicator Removal |
MalwareBPFDoor | BPFDoor clears the file location `/proc/<PID>/environ` removing all environment variables for the process. |
| T1070 Indicator Removal |
MalwareSDBbot | SDBbot has the ability to clean up and remove data structures from a compromised host. |
| T1070 Indicator Removal |
MalwareSibot | Sibot will delete an associated registry key if a certain server response is received. |
| T1070 Indicator Removal |
MalwareHermeticWiper | HermeticWiper can disable pop-up information about folders and desktop items and delete Registry keys to hide malicious services. |
| T1070 Indicator Removal |
MalwareSUNBURST | SUNBURST removed HTTP proxy registry values to clean up traces of execution. |
| T1070 Indicator Removal |
MalwareIPsec Helper | IPsec Helper can delete various registry keys related to its execution and use. |
| T1070 Indicator Removal |
MalwareFunnyDream | FunnyDream has the ability to clean traces of malware deployment. |
| T1070 Indicator Removal |
MalwareMaze | Maze has used the “Wow64RevertWow64FsRedirection” function following attempts to delete the shadow volumes, in order to leave the system in the same state as it was prior to redirection. |
| T1070 Indicator Removal |
MalwareShadowPad | ShadowPad has deleted arbitrary Registry values. |
| T1070 Indicator Removal |
ToolSILENTTRINITY | SILENTTRINITY can remove artifacts from the compromised host, including created Registry keys. |
| T1070 Indicator Removal |
ToolCSPY Downloader | CSPY Downloader has the ability to remove values it writes to the Registry. |
| T1070 Indicator Removal |
ToolRemcos | Remcos can clean saved cookies and logins from the web browser. |
| T1070 Indicator Removal |
ToolDonut | Donut can erase file references to payloads in-memory after being reflectively loaded and executed. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.