ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
MalwareAvenger

Avenger has the ability to download files from C2 to a compromised host.

T1105
Ingress Tool Transfer
MalwarePUBLOAD

PUBLOAD has acted as a stager that can download the next-stage payload from its C2 server. PUBLOAD has also delivered FDMTP as a secondary control tool and PTSOCKET for exfiltration to some infected systems.

T1105
Ingress Tool Transfer
MalwareSystemBC

SystemBC has downloaded additional files for execution on the victim’s machine. The server component of SystemBC has the ability to send additional files to victim machines.

T1105
Ingress Tool Transfer
MalwareGootloader

Gootloader can fetch second stage code from hardcoded web domains.

T1105
Ingress Tool Transfer
MalwareWellMess

WellMess can write files to a compromised host.

T1105
Ingress Tool Transfer
MalwareDacls

Dacls can download its payload from a C2 server.

T1105
Ingress Tool Transfer
MalwareDropBook

DropBook can download and execute additional files.

T1105
Ingress Tool Transfer
MalwareWoody RAT

Woody RAT can download files from its C2 server, including the .NET DLLs, `WoodySharpExecutor` and `WoodyPowerSession`.

T1105
Ingress Tool Transfer
MalwareMafalda

Mafalda can download additional files onto the compromised host.

T1105
Ingress Tool Transfer
MalwareKARAE

KARAE can upload and download files, including second-stage malware.

T1105
Ingress Tool Transfer
MalwareSquirrelwaffle

Squirrelwaffle has downloaded and executed additional encoded payloads.

T1105
Ingress Tool Transfer
MalwarePolyglotDuke

PolyglotDuke can retrieve payloads from the C2 server.

T1105
Ingress Tool Transfer
MalwareHexEval Loader

HexEval Loader has been used to download a malicious payload to include BeaverTail.

T1105
Ingress Tool Transfer
MalwareHildegard

Hildegard has downloaded additional scripts that build and run Monero cryptocurrency miners.

T1105
Ingress Tool Transfer
MalwareAgent.btz

Agent.btz attempts to download an encrypted binary from a specified domain.

T1105
Ingress Tool Transfer
MalwareSLOWDRIFT

SLOWDRIFT downloads additional payloads.

T1105
Ingress Tool Transfer
MalwareSHUTTERSPEED

SHUTTERSPEED can download and execute an arbitary executable.

T1105
Ingress Tool Transfer
MalwareSombRAT

SombRAT has the ability to download and execute additional payloads.

T1105
Ingress Tool Transfer
MalwareODAgent

ODAgent has the ability to download and execute files on compromised systems.

T1105
Ingress Tool Transfer
MalwareFlawedAmmyy

FlawedAmmyy can transfer files from C2.

T1105
Ingress Tool Transfer
MalwareSnip3

Snip3 can download additional payloads to compromised systems.

T1105
Ingress Tool Transfer
MalwareFYAnti

FYAnti can download additional payloads to a compromised host.

T1105
Ingress Tool Transfer
MalwareHOPLIGHT

HOPLIGHT has the ability to connect to a remote host in order to upload and download files.

T1105
Ingress Tool Transfer
MalwareGuLoader

GuLoader can download further malware for execution on the victim's machine.

T1105
Ingress Tool Transfer
MalwareMobileOrder

MobileOrder has a command to download a file from the C2 server to the victim mobile device's SD card.

T1105
Ingress Tool Transfer
MalwareRegDuke

RegDuke can download files from C2.

T1105
Ingress Tool Transfer
MalwareInvisiMole

InvisiMole can upload files to the victim's machine for operations.

T1105
Ingress Tool Transfer
MalwareP.A.S. Webshell

P.A.S. Webshell can upload and download files to and from compromised hosts.

T1105
Ingress Tool Transfer
MalwareVolgmer

Volgmer can download remote files and additional payloads to the victim's machine.

T1105
Ingress Tool Transfer
MalwareWhisperGate

WhisperGate can download additional stages of malware from a Discord CDN channel.

T1105
Ingress Tool Transfer
MalwareZeroT

ZeroT can download additional payloads onto the victim.

T1105
Ingress Tool Transfer
MalwareRDAT

RDAT can download files via DNS.

T1105
Ingress Tool Transfer
MalwareSkidmap

Skidmap has the ability to download files on an infected host.

T1105
Ingress Tool Transfer
MalwareOkrum

Okrum has built-in commands for uploading, downloading, and executing files to the system.

T1105
Ingress Tool Transfer
MalwareBonadan

Bonadan can download additional modules from the C2 server.

T1105
Ingress Tool Transfer
MalwareNeoichor

Neoichor can download additional files onto a compromised host.

T1105
Ingress Tool Transfer
MalwareRaspberry Robin

Raspberry Robin retrieves its second stage payload in a variety of ways such as through msiexec.exe abuse, or running the curl command to download the payload to the victim's %AppData% folder.

T1105
Ingress Tool Transfer
MalwareRemoteCMD

RemoteCMD copies a file over to the remote system before execution.

T1105
Ingress Tool Transfer
MalwareDiavol

Diavol can receive configuration updates and additional payloads including wscpy.exe from C2.

T1105
Ingress Tool Transfer
MalwareDoki

Doki has downloaded scripts from C2.

T1105
Ingress Tool Transfer
MalwareIcedID

IcedID has the ability to download additional modules and a configuration file from C2.

T1105
Ingress Tool Transfer
MalwareVERMIN

VERMIN can download and upload files to the victim's machine.

T1105
Ingress Tool Transfer
MalwareUBoatRAT

UBoatRAT can upload and download files to the victim’s machine.

T1105
Ingress Tool Transfer
MalwareHTTPTroy

HTTPTroy has the ability to download files from C2 using the `down <FILENAME>` command.

T1105
Ingress Tool Transfer
MalwareMarkiRAT

MarkiRAT can download additional files and tools from its C2 server, including through the use of BITSAdmin.

T1105
Ingress Tool Transfer
MalwareKazuar

Kazuar downloads additional plug-ins to load on the victim’s machine, including the ability to upgrade and replace its own binary.

T1105
Ingress Tool Transfer
MalwareNavRAT

NavRAT can download files remotely.

T1105
Ingress Tool Transfer
MalwareDarkComet

DarkComet can load any files onto the infected machine to execute.

T1105
Ingress Tool Transfer
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can download additional files from C2.

T1105
Ingress Tool Transfer
MalwareLucifer

Lucifer can download and execute a replica of itself using certutil.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.