File Deletion

T1070.004

Sub-technique of T1070 Indicator Removal.View on attack.mitre.org

About this technique

Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: Ingress Tool Transfer) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.

There are tools available from the host operating system to perform cleanup, but adversaries may use other tools as well. Examples of built-in Command and Scripting Interpreter functions include del on Windows, rm or unlink on Linux and macOS, and `rm` on ESXi.

Detection rules28

Rules on DetectionCode tagged with T1070.004.

Sigma13

RuleLevelLog source
Prefetch File Deletedhighwindows / file_delete
Suspicious Ping/Del Command Combinationhighwindows / process_creation
ADS Zone.Identifier Deleted By Uncommon Applicationmediumwindows / file_delete
Backup Catalog Deletedmediumwindows / NULL
Cisco File Deletionmediumcisco / NULL
File Deleted Via Sysinternals SDeletemediumwindows / file_delete
Greedy File Deletion Using Delmediumwindows / process_creation
Potential Secure Deletion with SDeletemediumwindows / NULL
Potentially Suspicious Ping/Copy Command Combinationmediumwindows / process_creation
Directory Removal Via Rmdirlowwindows / process_creation
File Deletion Via Dellowwindows / process_creation
TeamViewer Log File Deletedlowwindows / file_delete
File Deletioninformationallinux / process_creation

Splunk15

RuleTypeRiskData source
Clear Unallocated Sector Using Cipher AppTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Linux Account Manipulation Of SSH Config and KeysAnomalyNULLSysmon for Linux EventID 11
Linux Deletion Of Cron JobsAnomalyNULLSysmon for Linux EventID 11
Linux Deletion Of Init Daemon ScriptTTPNULLSysmon for Linux EventID 11
Linux Deletion Of ServicesTTPNULLSysmon for Linux EventID 11
Linux Deletion of SSL CertificateAnomalyNULLSysmon for Linux EventID 11
Linux High Frequency Of File Deletion In Boot FolderTTPNULLSysmon for Linux EventID 11
Linux High Frequency Of File Deletion In Etc FolderAnomalyNULLSysmon for Linux EventID 11
Linux Indicator Removal Service File DeletionAnomalyNULLSysmon for Linux EventID 1
Recursive Delete of Directory In Batch CMDTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Sdelete Application ExecutionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Default Rdp File DeletionAnomalyNULLSysmon EventID 23, Sysmon EventID 26
Windows Rdp AutomaticDestinations DeletionAnomalyNULLSysmon EventID 23, Sysmon EventID 26
Windows RDP Cache File DeletionAnomalyNULLSysmon EventID 23, Sysmon EventID 26
Windows RDP Server Registry DeletionAnomalyNULLSysmon EventID 12, Sysmon EventID 13

Groups47

Show 23 more

Software251

Show 227 more
BOLDMOVEBPFDoorBRICKSTORMBumblebeeCalistoCanisterWormCarbanakCardinal RATCARROTBATccf32CharmPowerCherry PickercmdCOATHANGERCrimsonCryptoisticCSPY DownloaderCubaDanBotDarkGateDarkWatchmanDenisDerusbiDOWNIISSADrovorubDtrackDustySkyECCENTRICBANDWAGONEliseEmbargoEpicEvilBunnyExaramel for LinuxExbyteFALLCHILLFatDukeFELIXROOTFerociousFlawedAmmyyFruitFlyFunnyDreamFysbisGazerGelsemiumgh0st RATGold DragonGoldenSpyGomirGrandoreiroGreen LambertGreyEnergyGrimAgentGuLoaderHALFBAKEDHancitorHAWKBALLHermeticWiperHeyoka BackdoorHi-ZorHildegardHotCroissantHTTPBrowserHTTPTroyHydraqHyperBroIceAppleImminent MonitorInnaputRATInvisiMoleIPsec HelperIxesheJHUHUGITJPINjRATKazuarKevinKEYMARBLEKillDiskKivarsKomplexKONNILatrodectusLightNeuronLine RunnerLinfoLiteDukeLockBit 2.0LockBit 3.0LockerGogaLODEINFOLokibotLookBackLoudMinerLunarMailLunarWebMacheteMacMaMacSpyMagicRATMedusa RansomwareMESSAGETAPmetaMainMetamorfoMeteorMilanMini Shai-HuludMisdatMoonWindMore_eggsMoriMosquitoMultiLayer WiperMURKYTOPNanHaiShuNebulaeNICECURLNightdoornjRATNOKKINOOPLDROceanSaltODAgentOkrumOopsIEOSX_OCEANLOTUS.DOutSteelP.A.S. WebshellPasamPay2KeyPcSharePenquinPillowmintPLEADPlugXpngdownerPoetRATPonyPowerDukePowerShowerPOWERSTATSPrikormkaProLockProtonProxysvcPteranodonPUNCHBUGGYPureCrypterPyDCryptPysaQakBotQilinQUADAGENTRaccoon StealerRainyDayRansomHubRaspberry RobinRCSessionRDATRDFSNIFFERReaverRedLeavesRemcosRemsecREvilRising SunROADSWEEPROKRATRTMRunningRATS-TypeSaint BotSakulaSamSamSDBbotSDeleteSeaDukeSeasaltServHelperSharkShimRatShrinkLockerSibotSILENTTRINITYSLOTHFULMEDIASolarSombRATSPAWNCHIMERASpeakUpSQLRatStealBitStoneDrillStrifeWaterStrongPityStuxnetSUNBURSTSUNSPOTSysUpdateTaidoorTAINTEDSCRIBETDTESSTeamPCP Cloud StealerTONESHELLTRAILBLAZETrojan.KaraganyTroll StealerTYPEFRAMEUPSTYLEUroburosUrsnifUSBStealerVBShowerVERMINVersaMemVolgmerWhisperGateWINDSHIELDWindTailWingbirdWinnti for WindowsWoody RATXAgentOSXXLoaderZebrocyZeroCleareZeus PandazwShellZxShell

Campaigns13

Procedure examples311

Groups47

Used byProcedure example
GroupAPT18

APT18 actors deleted tools and batch files from victim systems.

GroupAPT28

APT28 has intentionally deleted computer files to cover their tracks, including with use of the program CCleaner.

GroupAPT29

APT29 has used SDelete to remove artifacts from victim networks.

GroupAPT3

APT3 has a tool that can delete files.

GroupAPT32

APT32's macOS backdoor can receive a “delete” command.

GroupAPT38

APT38 has used a utility called CLOSESHAVE that can securely delete a file from the system. They have also removed malware, tools, or other non-native files used during the intrusion to reduce their footprint or as part of the post-intrusion cleanup process.

GroupAPT39

APT39 has used malware to delete files after they are deployed on a compromised host.

GroupAPT41

APT41 deleted files from the system.

View all 47 groups examples

Software251

Used byProcedure example
MalwareAcidPour

AcidPour includes a self-delete function where the malware deletes itself from disk after execution and program load into memory.

MalwareADVSTORESHELL

ADVSTORESHELL can delete files and directories.

MalwareAnchor

Anchor can self delete its dropper after the malware is successfully deployed.

MalwareApostle

Apostle writes batch scripts to disk, such as system.bat and remover.bat, that perform various anti-analysis and anti-forensic tasks, before finally deleting themselves at the end of execution. Apostle attempts to delete itself after encryption or wiping operations are complete and before shutting down the victim machine.

MalwareAppleJeus

AppleJeus has deleted the MSI file after installation.

MalwareAppleSeed

AppleSeed can delete files from a compromised host after they are exfiltrated.

MalwareAria-body

Aria-body has the ability to delete files and directories on compromised hosts.

MalwareAttor

Attor’s plugin deletes the collected files and log files after exfiltration.

View all 251 software examples

Campaigns13

Used byProcedure example
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, vba_macro.exe deletes itself after `FONTCACHE.DAT`, `rundll32.exe`, and the associated .lnk file is delivered.

CampaignAPT41 DUST

APT41 DUST deleted various artifacts from victim systems following use.

CampaignArcaneDoor

ArcaneDoor included multiple instances of file deletion or removal during execution and other adversary actions.

CampaignC0032

During the C0032 campaign, TEMP.Veles routinely deleted tools, logs, and other files after they were finished with them.

CampaignCutting Edge

During Cutting Edge, threat actors deleted `/tmp/test1.txt` on compromised Ivanti Connect Secure VPNs which was used to hold stolen configuration and cache files.

CampaignKV Botnet Activity

KV Botnet Activity removes on-disk copies of tools and other artifacts after it the primary botnet payload has been loaded into memory on the victim device.

CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace deleted delivered tools and files from compromised hosts.

CampaignOperation Digital Eye

During Operation Digital Eye, threat actors deleted files delivered to compromised hosts, often named with the pattern do.* such as do.exe.

View all 13 campaigns examples

References1

  1. Microsoft SDelete July 2016 Open source
    Russinovich, M. (2016, July 4). SDelete v2.0. Retrieved February 8, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.