ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
MalwareEmissary

Emissary has the capability to download files from the C2 server.

T1105
Ingress Tool Transfer
MalwareExaramel for Linux

Exaramel for Linux has a command to download a file from and to a remote C2 server.

T1105
Ingress Tool Transfer
MalwareKEYMARBLE

KEYMARBLE can upload files to the victim’s machine and can download additional payloads.

T1105
Ingress Tool Transfer
MalwareTAMECAT

TAMECAT has used `wget` and `curl` to download additional content.

T1105
Ingress Tool Transfer
MalwarePS1

CostaBricks can download additional payloads onto a compromised host.

T1105
Ingress Tool Transfer
MalwareUrsnif

Ursnif has dropped payload and configuration files to disk. Ursnif has also been used to download and execute additional payloads.

T1105
Ingress Tool Transfer
MalwareCASTLETAP

CASTLETAP can transfer files to compromised network devices.

T1105
Ingress Tool Transfer
MalwareThreatNeedle

ThreatNeedle can download additional tools to enable lateral movement.

T1105
Ingress Tool Transfer
MalwareZLib

ZLib has the ability to download files.

T1105
Ingress Tool Transfer
MalwareRedLeaves

RedLeaves is capable of downloading a file from a specified URL.

T1105
Ingress Tool Transfer
MalwarePOWERSOURCE

POWERSOURCE has been observed being used to download TEXTMATE and the Cobalt Strike Beacon payload onto victims.

T1105
Ingress Tool Transfer
MalwareTsundere Botnet

Tsundere Botnet’s loader component has downloaded the zip file node-v18.17.0-win-x64.zip from the official Node.js website, as well as pm2, a Node.js process management tool.

T1105
Ingress Tool Transfer
MalwareFelismus

Felismus can download files from remote servers.

T1105
Ingress Tool Transfer
MalwareZeus Panda

Zeus Panda can download additional malware plug-in modules and execute them on the victim’s machine.

T1105
Ingress Tool Transfer
MalwareHavoc

Havoc has the ability to upload files to infected systems.

T1105
Ingress Tool Transfer
MalwareCARROTBAT

CARROTBAT has the ability to download and execute a remote file via certutil.

T1105
Ingress Tool Transfer
MalwareWEBC2

WEBC2 can download and execute a file.

T1105
Ingress Tool Transfer
MalwareInvisibleFerret

InvisibleFerret has downloaded “AnyDesk.exe” into the user’s home directory from the C2 server when checks for the service fail to identify its presence in the victim environment. InvisibleFerret has also been configured to download additional payloads using a command which calls to the /bow URI.

T1105
Ingress Tool Transfer
MalwareBankshot

Bankshot uploads files and secondary payloads to the victim's machine.

T1105
Ingress Tool Transfer
MalwareSharpDisco

SharpDisco has been used to download a Python interpreter to `C:\Users\Public\WinTN\WinTN.exe` as well as other plugins from external sources.

T1105
Ingress Tool Transfer
MalwareStrongPity

StrongPity can download files to specified targets.

T1105
Ingress Tool Transfer
MalwareHAPPYWORK

can download and execute a second-stage payload.

T1105
Ingress Tool Transfer
MalwarexCaon

xCaon has a command to download files to the victim's machine.

T1105
Ingress Tool Transfer
MalwarePLAINTEE

PLAINTEE has downloaded and executed additional plugins.

T1105
Ingress Tool Transfer
MalwarePony

Pony can download additional files onto the infected system.

T1105
Ingress Tool Transfer
MalwareNebulae

Nebulae can download files from C2.

T1105
Ingress Tool Transfer
MalwareAuditCred

AuditCred can download files and additional malware.

T1105
Ingress Tool Transfer
MalwareTONESHELL

TONESHELL has the ability to download additional files to the victim device.

T1105
Ingress Tool Transfer
MalwareKasidet

Kasidet has the ability to download and execute additional files.

T1105
Ingress Tool Transfer
MalwareHannotog

Hannotog can download additional files to the victim machine.

T1105
Ingress Tool Transfer
MalwareRainyDay

RainyDay can download files to a compromised host.

T1105
Ingress Tool Transfer
MalwareEcipekac

Ecipekac can download additional payloads to a compromised host.

T1105
Ingress Tool Transfer
MalwareBUSHWALK

BUSHWALK can write malicious payloads sent through a web request’s command parameter.

T1105
Ingress Tool Transfer
MalwaremacOS.OSAMiner

macOS.OSAMiner has used `curl` to download a Stripped Payloads from a public facing adversary-controlled webpage.

T1105
Ingress Tool Transfer
MalwareLOWBALL

LOWBALL uses the Dropbox API to request two files, one of which is the same file as the one dropped by the malicious email attachment. This is most likely meant to be a mechanism to update the compromised host with a new version of the LOWBALL malware.

T1105
Ingress Tool Transfer
MalwareNETWIRE

NETWIRE can downloaded payloads from C2 to the compromised host.

T1105
Ingress Tool Transfer
MalwareTinyTurla

TinyTurla has the ability to act as a second-stage dropper used to infect the system with additional malware.

T1105
Ingress Tool Transfer
MalwarePowerExchange

PowerExchange can decode Base64-encoded files and call `WriteAllBytes` to write the files to compromised hosts.

T1105
Ingress Tool Transfer
MalwareIMAPLoader

IMAPLoader is a loader used to retrieve follow-on payload encoded in email messages for execution on victim systems.

T1105
Ingress Tool Transfer
MalwareGreyEnergy

GreyEnergy can download additional modules and payloads.

T1105
Ingress Tool Transfer
MalwareAria-body

Aria-body has the ability to download additional payloads from C2.

T1105
Ingress Tool Transfer
MalwareEmotet

Emotet can download follow-on payloads and items via malicious `url` parameters in obfuscated PowerShell code.

T1105
Ingress Tool Transfer
MalwareCrimson

Crimson contains a command to retrieve files from its C2 server.

T1105
Ingress Tool Transfer
MalwareTomiris

Tomiris can download files and execute them on a victim's system.

T1105
Ingress Tool Transfer
MalwareDUSTTRAP

DUSTTRAP can retrieve and load additional payloads.

T1105
Ingress Tool Transfer
MalwareTurian

Turian can download additional files and tools from its C2.

T1105
Ingress Tool Transfer
MalwareBADHATCH

BADHATCH has the ability to load a second stage malicious DLL file onto a compromised machine.

T1105
Ingress Tool Transfer
MalwareMachete

Machete can download additional files for execution on the victim’s machine.

T1105
Ingress Tool Transfer
MalwarePowerLess

PowerLess can download additional payloads to a compromised host.

T1105
Ingress Tool Transfer
MalwareAction RAT

Action RAT has the ability to download additional payloads onto an infected machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.