T1071.001 Web Protocols — ATT&CK Technique
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. Protocols such as HTTP/S and WebSocket that carry web traffic may be very common in environments. HTTP/S packets have many fields and headers in which data can be concealed. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.
Detection coverage (50)
- Katz Stealer Suspicious User-Agent high
- Kalambur Backdoor Curl TOR SOCKS Proxy Execution high
- Axios NPM Compromise Malicious C2 Domain DNS Query high
- Curl.EXE Execution With Custom UserAgent medium
- Tunneling Tool Execution medium
- Wannacry Killswitch Domain high
- Windows WebDAV User Agent high
- HackTool - Empire UserAgent URI Combo high
- Potential Base64 Encoded User-Agent medium
- HTTP Request With Empty User Agent medium
- Suspicious Curl Change User Agents - Linux medium
- HackTool - BabyShark Agent Default URL Pattern critical
- Raw Paste Service Access high
- Suspicious Base64 Encoded User-Agent medium
- Bitsadmin to Uncommon TLD high
- Suspicious Installer Package Child Process medium
- HackTool - CobaltStrike Malleable Profile Patterns - Proxy high
- PwnDrp Access critical
- APT User Agent high
- Crypto Miner User Agent high
- Suspicious User Agent high
- Telegram API Access medium
- Malware User Agent high
- Bitsadmin to Uncommon IP Server Address high
- Exploit Framework User Agent high
- Windows PowerShell User Agent medium
- DNS Query To Devtunnels Domain medium
- DNS Query To Visual Studio Code Tunnels Domain medium
- Cloudflared Tunnels Related DNS Requests medium
- DNS Query Request By QuickAssist.EXE low
- Outbound Network Connection Initiated By Microsoft Dialer high
- Change User Agents with WebRequest medium
- Visual Studio Code Tunnel Execution medium
- Renamed Visual Studio Code Tunnel Execution high
- Visual Studio Code Tunnel Service Installation medium
- Visual Studio Code Tunnel Shell Execution medium
- Chafer Malware URL Pattern high
- Ursnif Malware Download URL Pattern high
- Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script
- Windows Non-System Process Querying Definition Update
- ComRAT Network Communication high
- Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint
- Cisco Secure Firewall - Connection to File Sharing Domain
- Cisco Secure Firewall - High EVE Threat Confidence
- Cisco Secure Firewall - Wget or Curl Download
- HTTP Malware User Agent
- HTTP C2 Framework User Agent
- HTTP RMM User Agent
- HTTP PUA User Agent
- HTTP Rapid POST with Mixed Status Codes
Malware using this technique
- HTTPBrowser
- SideTwist
- Final1stspy
- Gomir
- BRICKSTORM
- CreepySnail
- PoetRAT
- OLDBAIT
- Dyre
- TinyTurla
- Turian
- BeaverTail
- ComRAT
- Zeus Panda
- Mafalda
- Dacls
- TrailBlazer
- IronWind
- LIGHTWIRE
- Pteranodon
- ANDROMEDA
- Flagpro
- Mongall
- GrimAgent
- GuLoader
- FlawedAmmyy
- Squirrelwaffle
- WinMM
- Shark
- pngdowner
- Remexi
- Samurai
- ELMER
- Peppy
- NGLite
- njRAT
- Hi-Zor
- DarkTortilla
- THINCRUST
- NETWIRE
- StealBit
- NETEAGLE
- Bisonal
- GoldFinder
- Goopy
- LOWBALL
- Smoke Loader
- Keydnap
- Chaes
- FoggyWeb
Threat actors using this technique
- Icarus
- Inception
- Medusa Ransomware
- DragonForce
- Void Manticore
- RedNovember
- Daggerfly
- Rancor
- WIRTE
- APT35
- APT38
- BlackByte
- Kimsuky
- APT41
- APT32
- HAFNIUM
- MuddyWater
- RedEcho
- Gamaredon Group
- TeamTNT
- Sandworm Team
- APT18
- Sidewinder
- Mustang Panda
- Rocke
- APT39
- APT37
- OilRig
- Higaisa
- Tropic Trooper
- Orangeworm
- Sea Turtle
- APT15
- Confucius
- Winter Vivern
- SilverTerrier
- Turla
- APT27
- TA505
- BITTER
- RedCurl
- Stealth Falcon
- Dark Caracal
- Chimera
- BRONZE BUTLER
- TA551
- APT33
- FIN8
- Windshift
- LuminousMoth