Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1105 Ingress Tool Transfer |
MalwareAvenger | Avenger has the ability to download files from C2 to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwarePUBLOAD | PUBLOAD has acted as a stager that can download the next-stage payload from its C2 server. PUBLOAD has also delivered FDMTP as a secondary control tool and PTSOCKET for exfiltration to some infected systems. |
| T1105 Ingress Tool Transfer |
MalwareSystemBC | SystemBC has downloaded additional files for execution on the victim’s machine. The server component of SystemBC has the ability to send additional files to victim machines. |
| T1105 Ingress Tool Transfer |
MalwareGootloader | Gootloader can fetch second stage code from hardcoded web domains. |
| T1105 Ingress Tool Transfer |
MalwareWellMess | WellMess can write files to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareDacls | Dacls can download its payload from a C2 server. |
| T1105 Ingress Tool Transfer |
MalwareDropBook | DropBook can download and execute additional files. |
| T1105 Ingress Tool Transfer |
MalwareWoody RAT | Woody RAT can download files from its C2 server, including the .NET DLLs, `WoodySharpExecutor` and `WoodyPowerSession`. |
| T1105 Ingress Tool Transfer |
MalwareMafalda | Mafalda can download additional files onto the compromised host. |
| T1105 Ingress Tool Transfer |
MalwareKARAE | KARAE can upload and download files, including second-stage malware. |
| T1105 Ingress Tool Transfer |
MalwareSquirrelwaffle | Squirrelwaffle has downloaded and executed additional encoded payloads. |
| T1105 Ingress Tool Transfer |
MalwarePolyglotDuke | PolyglotDuke can retrieve payloads from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareHexEval Loader | HexEval Loader has been used to download a malicious payload to include BeaverTail. |
| T1105 Ingress Tool Transfer |
MalwareHildegard | Hildegard has downloaded additional scripts that build and run Monero cryptocurrency miners. |
| T1105 Ingress Tool Transfer |
MalwareAgent.btz | Agent.btz attempts to download an encrypted binary from a specified domain. |
| T1105 Ingress Tool Transfer |
MalwareSLOWDRIFT | SLOWDRIFT downloads additional payloads. |
| T1105 Ingress Tool Transfer |
MalwareSHUTTERSPEED | SHUTTERSPEED can download and execute an arbitary executable. |
| T1105 Ingress Tool Transfer |
MalwareSombRAT | SombRAT has the ability to download and execute additional payloads. |
| T1105 Ingress Tool Transfer |
MalwareODAgent | ODAgent has the ability to download and execute files on compromised systems. |
| T1105 Ingress Tool Transfer |
MalwareFlawedAmmyy | FlawedAmmyy can transfer files from C2. |
| T1105 Ingress Tool Transfer |
MalwareSnip3 | Snip3 can download additional payloads to compromised systems. |
| T1105 Ingress Tool Transfer |
MalwareFYAnti | FYAnti can download additional payloads to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareHOPLIGHT | HOPLIGHT has the ability to connect to a remote host in order to upload and download files. |
| T1105 Ingress Tool Transfer |
MalwareGuLoader | GuLoader can download further malware for execution on the victim's machine. |
| T1105 Ingress Tool Transfer |
MalwareMobileOrder | MobileOrder has a command to download a file from the C2 server to the victim mobile device's SD card. |
| T1105 Ingress Tool Transfer |
MalwareRegDuke | RegDuke can download files from C2. |
| T1105 Ingress Tool Transfer |
MalwareInvisiMole | InvisiMole can upload files to the victim's machine for operations. |
| T1105 Ingress Tool Transfer |
MalwareP.A.S. Webshell | P.A.S. Webshell can upload and download files to and from compromised hosts. |
| T1105 Ingress Tool Transfer |
MalwareVolgmer | Volgmer can download remote files and additional payloads to the victim's machine. |
| T1105 Ingress Tool Transfer |
MalwareWhisperGate | WhisperGate can download additional stages of malware from a Discord CDN channel. |
| T1105 Ingress Tool Transfer |
MalwareZeroT | ZeroT can download additional payloads onto the victim. |
| T1105 Ingress Tool Transfer |
MalwareRDAT | RDAT can download files via DNS. |
| T1105 Ingress Tool Transfer |
MalwareSkidmap | Skidmap has the ability to download files on an infected host. |
| T1105 Ingress Tool Transfer |
MalwareOkrum | Okrum has built-in commands for uploading, downloading, and executing files to the system. |
| T1105 Ingress Tool Transfer |
MalwareBonadan | Bonadan can download additional modules from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareNeoichor | Neoichor can download additional files onto a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareRaspberry Robin | Raspberry Robin retrieves its second stage payload in a variety of ways such as through msiexec.exe abuse, or running the curl command to download the payload to the victim's |
| T1105 Ingress Tool Transfer |
MalwareRemoteCMD | RemoteCMD copies a file over to the remote system before execution. |
| T1105 Ingress Tool Transfer |
MalwareDiavol | Diavol can receive configuration updates and additional payloads including wscpy.exe from C2. |
| T1105 Ingress Tool Transfer |
MalwareDoki | Doki has downloaded scripts from C2. |
| T1105 Ingress Tool Transfer |
MalwareIcedID | IcedID has the ability to download additional modules and a configuration file from C2. |
| T1105 Ingress Tool Transfer |
MalwareVERMIN | VERMIN can download and upload files to the victim's machine. |
| T1105 Ingress Tool Transfer |
MalwareUBoatRAT | UBoatRAT can upload and download files to the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareHTTPTroy | HTTPTroy has the ability to download files from C2 using the `down <FILENAME>` command. |
| T1105 Ingress Tool Transfer |
MalwareMarkiRAT | MarkiRAT can download additional files and tools from its C2 server, including through the use of BITSAdmin. |
| T1105 Ingress Tool Transfer |
MalwareKazuar | Kazuar downloads additional plug-ins to load on the victim’s machine, including the ability to upgrade and replace its own binary. |
| T1105 Ingress Tool Transfer |
MalwareNavRAT | NavRAT can download files remotely. |
| T1105 Ingress Tool Transfer |
MalwareDarkComet | DarkComet can load any files onto the infected machine to execute. |
| T1105 Ingress Tool Transfer |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can download additional files from C2. |
| T1105 Ingress Tool Transfer |
MalwareLucifer | Lucifer can download and execute a replica of itself using certutil. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.