ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
MalwareGazer

Gazer can execute a task to download a file.

T1105
Ingress Tool Transfer
MalwareTSCookie

TSCookie has the ability to upload and download files to and from the infected host.

T1105
Ingress Tool Transfer
MalwareLatrodectus

Latrodectus can download and execute PEs, DLLs, and shellcode from C2.

T1105
Ingress Tool Transfer
MalwareSaint Bot

Saint Bot can download additional files onto a compromised host.

T1105
Ingress Tool Transfer
MalwareChaes

Chaes can download additional files onto an infected machine.

T1105
Ingress Tool Transfer
MalwareLODEINFO

LODEINFO has the ability to download additional files from the C2.

T1105
Ingress Tool Transfer
MalwareBriba

Briba downloads files onto infected hosts.

T1105
Ingress Tool Transfer
MalwareCharmPower

CharmPower has the ability to download additional modules to a compromised host.

T1105
Ingress Tool Transfer
MalwareMuddyViper

MuddyViper has the ability to download files from the C2 server. Additionally, MuddyViper has the ability to download a file in chunks with sleep time between each chunk.

T1105
Ingress Tool Transfer
MalwareTYPEFRAME

TYPEFRAME can upload and download files to the victim’s machine.

T1105
Ingress Tool Transfer
MalwareBundlore

Bundlore can download and execute new versions of itself.

T1105
Ingress Tool Transfer
MalwareP8RAT

P8RAT can download additional payloads to a target system.

T1105
Ingress Tool Transfer
MalwareEVILNUM

EVILNUM can download and upload files to the victim's computer.

T1105
Ingress Tool Transfer
MalwareSMOKEDHAM

SMOKEDHAM has used Powershell to download UltraVNC and ngrok from third-party file sharing sites.

T1105
Ingress Tool Transfer
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can download additional modules from its C2 server.

T1105
Ingress Tool Transfer
MalwareBendyBear

BendyBear is designed to download an implant from a C2 server.

T1105
Ingress Tool Transfer
MalwareGlassWorm

GlassWorm has downloaded additional payloads from C2.

T1105
Ingress Tool Transfer
MalwareUroburos

Uroburos can use a `Put` command to write files to an infected machine.

T1105
Ingress Tool Transfer
MalwareMetamorfo

Metamorfo has used MSI files to download additional files to execute.

T1105
Ingress Tool Transfer
MalwareSpica

Spica can upload and download files to and from compromised hosts.

T1105
Ingress Tool Transfer
MalwareTrojan.Karagany

Trojan.Karagany can upload, download, and execute files on the victim.

T1105
Ingress Tool Transfer
MalwareBandook

Bandook can download files to the system.

T1105
Ingress Tool Transfer
MalwarePipeMon

PipeMon can install additional modules via C2 commands.

T1105
Ingress Tool Transfer
MalwareMagicRAT

MagicRAT can import and execute additional payloads.

T1105
Ingress Tool Transfer
MalwareKONNI

KONNI can download files and execute them on the victim’s machine.

T1105
Ingress Tool Transfer
MalwareWinnti for Linux

Winnti for Linux has the ability to deploy modules directly from command and control (C2) servers, possibly for remote command execution, file exfiltration, and socks5 proxying on the infected host.

T1105
Ingress Tool Transfer
Malwaregh0st RAT

gh0st RAT can download files to the victim’s machine.

T1105
Ingress Tool Transfer
MalwareShamoon

Shamoon can download an executable to run on the victim.

T1105
Ingress Tool Transfer
MalwareDnsSystem

DnsSystem can download files to compromised systems after receiving a command with the string `downloaddd`.

T1105
Ingress Tool Transfer
MalwareMoleNet

MoleNet can download additional payloads from the C2.

T1105
Ingress Tool Transfer
MalwareJHUHUGIT

JHUHUGIT can retrieve an additional payload from its C2 server. JHUHUGIT has a command to download files to the victim’s machine.

T1105
Ingress Tool Transfer
MalwareBLUELIGHT

BLUELIGHT can download additional files onto the host.

T1105
Ingress Tool Transfer
MalwareKGH_SPY

KGH_SPY has the ability to download and execute code from remote servers.

T1105
Ingress Tool Transfer
Malwaredown_new

down_new has the ability to download files to the compromised host.

T1105
Ingress Tool Transfer
MalwareIxeshe

Ixeshe can download and execute additional files.

T1105
Ingress Tool Transfer
MalwareMicropsia

Micropsia can download and execute an executable from the C2 server.

T1105
Ingress Tool Transfer
MalwareKerrdown

Kerrdown can download specific payloads to a compromised host based on OS architecture.

T1105
Ingress Tool Transfer
MalwareRARSTONE

RARSTONE downloads its backdoor component from a C2 server and loads it directly into memory.

T1105
Ingress Tool Transfer
MalwareRedLine Stealer

RedLine Stealer has the ability download additional payloads.

T1105
Ingress Tool Transfer
MalwareVBShower

VBShower has the ability to download VBS files to the target computer.

T1105
Ingress Tool Transfer
MalwareStoneDrill

StoneDrill has downloaded and dropped temporary files containing scripts; it additionally has a function to upload files from the victims machine.

T1105
Ingress Tool Transfer
MalwareOopsIE

OopsIE can download files from its C2 server to the victim's machine.

T1105
Ingress Tool Transfer
MalwareRogueRobin

RogueRobin can save a new file to the system from the C2 server.

T1105
Ingress Tool Transfer
MalwareAttor

Attor can download additional plugins, updates and other files.

T1105
Ingress Tool Transfer
MalwareSQLRat

SQLRat can make a direct SQL connection to a Microsoft database controlled by the attackers, retrieve an item from the bindata table, then write and execute the file on disk.

T1105
Ingress Tool Transfer
MalwareLitePower

LitePower has the ability to download payloads containing system commands to a compromised host.

T1105
Ingress Tool Transfer
MalwareBoxCaon

BoxCaon can download files.

T1105
Ingress Tool Transfer
MalwareNightClub

NightClub can load multiple additional plugins on an infected host.

T1105
Ingress Tool Transfer
MalwareSDBbot

SDBbot has the ability to download a DLL from C2 to a compromised host.

T1105
Ingress Tool Transfer
MalwareMosquito

Mosquito can upload and download files to the victim.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.