Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1105 Ingress Tool Transfer |
MalwareEmissary | Emissary has the capability to download files from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareExaramel for Linux | Exaramel for Linux has a command to download a file from and to a remote C2 server. |
| T1105 Ingress Tool Transfer |
MalwareKEYMARBLE | KEYMARBLE can upload files to the victim’s machine and can download additional payloads. |
| T1105 Ingress Tool Transfer |
MalwareTAMECAT | TAMECAT has used `wget` and `curl` to download additional content. |
| T1105 Ingress Tool Transfer |
MalwarePS1 | CostaBricks can download additional payloads onto a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareUrsnif | Ursnif has dropped payload and configuration files to disk. Ursnif has also been used to download and execute additional payloads. |
| T1105 Ingress Tool Transfer |
MalwareCASTLETAP | CASTLETAP can transfer files to compromised network devices. |
| T1105 Ingress Tool Transfer |
MalwareThreatNeedle | ThreatNeedle can download additional tools to enable lateral movement. |
| T1105 Ingress Tool Transfer |
MalwareZLib | ZLib has the ability to download files. |
| T1105 Ingress Tool Transfer |
MalwareRedLeaves | RedLeaves is capable of downloading a file from a specified URL. |
| T1105 Ingress Tool Transfer |
MalwarePOWERSOURCE | POWERSOURCE has been observed being used to download TEXTMATE and the Cobalt Strike Beacon payload onto victims. |
| T1105 Ingress Tool Transfer |
MalwareTsundere Botnet | Tsundere Botnet’s loader component has downloaded the zip file node-v18.17.0-win-x64.zip from the official Node.js website, as well as pm2, a Node.js process management tool. |
| T1105 Ingress Tool Transfer |
MalwareFelismus | Felismus can download files from remote servers. |
| T1105 Ingress Tool Transfer |
MalwareZeus Panda | Zeus Panda can download additional malware plug-in modules and execute them on the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareHavoc | Havoc has the ability to upload files to infected systems. |
| T1105 Ingress Tool Transfer |
MalwareCARROTBAT | CARROTBAT has the ability to download and execute a remote file via certutil. |
| T1105 Ingress Tool Transfer |
MalwareWEBC2 | WEBC2 can download and execute a file. |
| T1105 Ingress Tool Transfer |
MalwareInvisibleFerret | InvisibleFerret has downloaded “AnyDesk.exe” into the user’s home directory from the C2 server when checks for the service fail to identify its presence in the victim environment. InvisibleFerret has also been configured to download additional payloads using a command which calls to the /bow URI. |
| T1105 Ingress Tool Transfer |
MalwareBankshot | Bankshot uploads files and secondary payloads to the victim's machine. |
| T1105 Ingress Tool Transfer |
MalwareSharpDisco | SharpDisco has been used to download a Python interpreter to `C:\Users\Public\WinTN\WinTN.exe` as well as other plugins from external sources. |
| T1105 Ingress Tool Transfer |
MalwareStrongPity | StrongPity can download files to specified targets. |
| T1105 Ingress Tool Transfer |
MalwareHAPPYWORK | can download and execute a second-stage payload. |
| T1105 Ingress Tool Transfer |
MalwarexCaon | xCaon has a command to download files to the victim's machine. |
| T1105 Ingress Tool Transfer |
MalwarePLAINTEE | PLAINTEE has downloaded and executed additional plugins. |
| T1105 Ingress Tool Transfer |
MalwarePony | Pony can download additional files onto the infected system. |
| T1105 Ingress Tool Transfer |
MalwareNebulae | Nebulae can download files from C2. |
| T1105 Ingress Tool Transfer |
MalwareAuditCred | AuditCred can download files and additional malware. |
| T1105 Ingress Tool Transfer |
MalwareTONESHELL | TONESHELL has the ability to download additional files to the victim device. |
| T1105 Ingress Tool Transfer |
MalwareKasidet | Kasidet has the ability to download and execute additional files. |
| T1105 Ingress Tool Transfer |
MalwareHannotog | Hannotog can download additional files to the victim machine. |
| T1105 Ingress Tool Transfer |
MalwareRainyDay | RainyDay can download files to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareEcipekac | Ecipekac can download additional payloads to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareBUSHWALK | BUSHWALK can write malicious payloads sent through a web request’s command parameter. |
| T1105 Ingress Tool Transfer |
MalwaremacOS.OSAMiner | macOS.OSAMiner has used `curl` to download a Stripped Payloads from a public facing adversary-controlled webpage. |
| T1105 Ingress Tool Transfer |
MalwareLOWBALL | LOWBALL uses the Dropbox API to request two files, one of which is the same file as the one dropped by the malicious email attachment. This is most likely meant to be a mechanism to update the compromised host with a new version of the LOWBALL malware. |
| T1105 Ingress Tool Transfer |
MalwareNETWIRE | NETWIRE can downloaded payloads from C2 to the compromised host. |
| T1105 Ingress Tool Transfer |
MalwareTinyTurla | TinyTurla has the ability to act as a second-stage dropper used to infect the system with additional malware. |
| T1105 Ingress Tool Transfer |
MalwarePowerExchange | PowerExchange can decode Base64-encoded files and call `WriteAllBytes` to write the files to compromised hosts. |
| T1105 Ingress Tool Transfer |
MalwareIMAPLoader | IMAPLoader is a loader used to retrieve follow-on payload encoded in email messages for execution on victim systems. |
| T1105 Ingress Tool Transfer |
MalwareGreyEnergy | GreyEnergy can download additional modules and payloads. |
| T1105 Ingress Tool Transfer |
MalwareAria-body | Aria-body has the ability to download additional payloads from C2. |
| T1105 Ingress Tool Transfer |
MalwareEmotet | Emotet can download follow-on payloads and items via malicious `url` parameters in obfuscated PowerShell code. |
| T1105 Ingress Tool Transfer |
MalwareCrimson | Crimson contains a command to retrieve files from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareTomiris | Tomiris can download files and execute them on a victim's system. |
| T1105 Ingress Tool Transfer |
MalwareDUSTTRAP | DUSTTRAP can retrieve and load additional payloads. |
| T1105 Ingress Tool Transfer |
MalwareTurian | Turian can download additional files and tools from its C2. |
| T1105 Ingress Tool Transfer |
MalwareBADHATCH | BADHATCH has the ability to load a second stage malicious DLL file onto a compromised machine. |
| T1105 Ingress Tool Transfer |
MalwareMachete | Machete can download additional files for execution on the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwarePowerLess | PowerLess can download additional payloads to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareAction RAT | Action RAT has the ability to download additional payloads onto an infected machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.