T1071.001 Web Protocols in real malware
ATT&CK technique T1071.001 Web Protocols appears in 2313 publicly analyzed samples on MalwareAnalyzer by Cyble, 2.0% of the analyzed corpus. Seven-day prevalence is flat (0 recent vs 0 prior). Most associated families: HUILoader, Upantix, VJadtre, Wapomi.
Tactics: command-and-control
Prevalence in the corpus
- Samples exhibiting T1071.001: 2313
- Share of analyzed corpus: 2.0%
- Last 7 days: 0 · prior 7 days: 0 (flat)
Malware families using T1071.001
Example samples
- virussign.com_22628d2409b7ef5eb0094ab3b69abce0.vir - malicious
- 1d241c1a63758f8aa1bffd5e05d9207889ac8ddc3649b5877d791ddd3aae28f4 - malicious
- 102c4ca4c419347616ceda7afb8e9adc97f30e0d6aa10cd6b22614077f658bf5 - malicious
- 3e22901e7b039f8e5f0abf40183e598b61c97eae4c8e518c5053be9bea070fe3 - malicious
- c5c7032ed404dec1f9970a019167220ff011b4ce117e7e775262278ba900e195 - malicious
- bdbcbde4080ace797d4c004d78662af16d0f0a487b057d10dcf9fc76a852ff83 - malicious
- 1ca3945af366e5ccfd8d82bfe5106ad6a637076fd5ce6352fb8eb6c280f12958 - malicious
- 54d4eb0020db0f03774fb6e5fb2d8fe5baa10116cfdbd324d195b250353d769a - malicious
- 1d07b34ed0014d9b6c8bdde925e1a537cb79df78245e081c93059a87f64a9a46 - malicious
- 86e038d9fb1bb8e60915593a3f0ebb053408825037bf13767856d1c5a21f9d42 - malicious
- e2a51f5b4ad465f2fff73fc910b6588db7841608bc48922953725a4cd1e58a0c - malicious
- 46cfeb049ec1b54df89c49003c2b772750bbcd89e6ebb235bf1861771a6613a3 - malicious
- 1f7d174cd538b18a9a747aee93a0b52bd5cdf554dc2da7389ca33ff605845966 - malicious
- 8d426aeabdb126c6af992785f00d1dbc176142905c4fa281bb2b6eb6b28b0fe3 - malicious
- 40c7ea5324b8cf722ef21e1e81bb3ab0bbf7a9372269dcaf35f8f428e103bd94 - malicious
- 63cd8db640f701949b78fa766ca66aa32e3480b13e4ce1abd85faddb47056e2b - malicious
- 0aa16df38d44af2e5d29d58fe212c6460a2b4ea000cfe23a3c0333391ccd397d - malicious
- 8a5c793dfcdb407b439d00ea9688b620ea6976c4871112293d50a58a3572bf73 - malicious
- c6a598722f0da67eae7a2d89c231ecab1fd79dfbe1cab2686083f1e407eed554 - suspicious
- f7c144fef9adbf0b13b0b2e949daad9c650c97db549a8ee984f59232ec80e933 - malicious
- 4daaa8c721d73c4e924ef31e2c9d17eb164e28c583b78cd291e9463bac26bcdd - malicious
- dca7fe5ac2d1b1b972d6d0f6fee28d481a50cb654bd25a93542cd74a694b6282 - malicious
- 97f36ab0a4ff9453413a38a118c000c659008125fe8fc31c2b79027e580f4a8d - malicious
- 18fc8425052b4a74b9f2e98b036ee63bfc42ed8ed3810f74f2c92d7bfaaa974b - malicious
- 58e4c7b1cf10849700e4112f1c34da25addd8030ebe6d8a8e95fcbf4ea28a897 - malicious
Canonical technique definition: MITRE ATT&CK T1071.001 (ATT&CK v19.1, CC BY 4.0).
Frequently asked about T1071.001
- How common is ATT&CK T1071.001 (Web Protocols) in real malware?
- ATT&CK technique T1071.001 Web Protocols appears in 2313 publicly analyzed samples on MalwareAnalyzer by Cyble, 2.0% of the analyzed corpus. Seven-day prevalence is flat (0 recent vs 0 prior). Most associated families: HUILoader, Upantix, VJadtre, Wapomi.
- Which malware families use T1071.001?
- In this corpus T1071.001 is most associated with HUILoader (380), Upantix (320), VJadtre (145), Wapomi (114). Counts are analyzed samples per family in which the technique was observed.
- What share of analyzed samples use T1071.001?
- 2.0% of the publicly analyzed corpus (2313 of 114609 samples) exhibits T1071.001. Technique attribution comes from behavior captured during real sandbox detonation and from static analysis, not from a vendor label.
All ATT&CK techniques in the corpus · Latest analyzed threats