ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
MalwareRTM

RTM can download additional files.

T1105
Ingress Tool Transfer
MalwarePHPsert

PHPsert has the ability to retrieve remote payloads.

T1105
Ingress Tool Transfer
MalwareSodaMaster

SodaMaster has the ability to download additional payloads from C2 to the targeted system.

T1105
Ingress Tool Transfer
MalwareHikit

Hikit has the ability to download files to a compromised host.

T1105
Ingress Tool Transfer
MalwareStrelaStealer

StrelaStealer installers have used obfuscated PowerShell scripts to retrieve follow-on payloads from WebDAV servers.

T1105
Ingress Tool Transfer
MalwareGrandoreiro

Grandoreiro can download its second stage from a hardcoded URL within the loader's code.

T1105
Ingress Tool Transfer
MalwareWellMail

WellMail can receive data and executable scripts from C2.

T1105
Ingress Tool Transfer
MalwareLiteDuke

LiteDuke has the ability to download files.

T1105
Ingress Tool Transfer
MalwareSakula

Sakula has the capability to download files.

T1105
Ingress Tool Transfer
MalwareVaporRage

VaporRage has the ability to download malicious shellcode to compromised systems.

T1105
Ingress Tool Transfer
MalwareSibot

Sibot can download and execute a payload onto a compromised system.

T1105
Ingress Tool Transfer
MalwareZxxZ

ZxxZ can download and execute additional files.

T1105
Ingress Tool Transfer
MalwareCaminho

Caminho has the ability to download files onto compromised hosts.

T1105
Ingress Tool Transfer
MalwareDrovorub

Drovorub can download files to a compromised host.

T1105
Ingress Tool Transfer
MalwareShark

Shark can download additional files from its C2 via HTTP or DNS.

T1105
Ingress Tool Transfer
MalwareBazar

Bazar can download and deploy additional payloads, including ransomware and post-exploitation frameworks such as Cobalt Strike.

T1105
Ingress Tool Transfer
MalwareBadPatch

BadPatch can download and execute or update malware.

T1105
Ingress Tool Transfer
MalwareRATANKBA

RATANKBA uploads and downloads information.

T1105
Ingress Tool Transfer
MalwareNidiran

Nidiran can download and execute files.

T1105
Ingress Tool Transfer
MalwareHiddenFace

HiddenFace can download files from the C2 to victim systems.

T1105
Ingress Tool Transfer
MalwareCryptoistic

Cryptoistic has the ability to send and receive files.

T1105
Ingress Tool Transfer
MalwareABK

ABK has the ability to download files from C2.

T1105
Ingress Tool Transfer
MalwareOilCheck

OilCheck can download staged payloads from an actor-controlled infrastructure.

T1105
Ingress Tool Transfer
MalwareZebrocy

Zebrocy obtains additional code to execute on the victim's machine, including the downloading of a secondary payload.

T1105
Ingress Tool Transfer
MalwarePandora

Pandora can load additional drivers and files onto a victim machine.

T1105
Ingress Tool Transfer
MalwareSpeakUp

SpeakUp downloads and executes additional files from a remote server.

T1105
Ingress Tool Transfer
MalwareCobalt Strike

Cobalt Strike can deliver additional payloads to victim machines.

T1105
Ingress Tool Transfer
MalwareSampleCheck5000

SampleCheck5000 can download additional payloads to compromised hosts.

T1105
Ingress Tool Transfer
MalwareSUNBURST

SUNBURST delivered different payloads, including TEARDROP in at least one instance.

T1105
Ingress Tool Transfer
MalwareEvilBunny

EvilBunny has downloaded additional Lua scripts from the C2.

T1105
Ingress Tool Transfer
MalwareHotCroissant

HotCroissant has the ability to upload a file from the command and control (C2) server to the victim machine.

T1105
Ingress Tool Transfer
MalwareServHelper

ServHelper may download additional files to execute.

T1105
Ingress Tool Transfer
MalwareUnknown Logger

Unknown Logger is capable of downloading remote files.

T1105
Ingress Tool Transfer
MalwareREvil

REvil can download a copy of itself from an attacker controlled IP address to the victim machine.

T1105
Ingress Tool Transfer
MalwareValak

Valak has downloaded a variety of modules and payloads to the compromised host, including IcedID and NetSupport Manager RAT-based malware.

T1105
Ingress Tool Transfer
MalwareSamurai

Samurai has been used to deploy other malware including Ninja.

T1105
Ingress Tool Transfer
MalwareMilan

Milan has received files from C2 and stored them in log folders beginning with the character sequence `a9850d2f`.

T1105
Ingress Tool Transfer
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has a command to download and execute a file on the victim’s machine.

T1105
Ingress Tool Transfer
MalwareOilBooster

OilBooster can download and execute files from an actor-controlled OneDrive account.

T1105
Ingress Tool Transfer
MalwareTaidoor

Taidoor has downloaded additional files onto a compromised host.

T1105
Ingress Tool Transfer
MalwareKivars

Kivars has the ability to download and execute files.

T1105
Ingress Tool Transfer
MalwareCyclops Blink

Cyclops Blink has the ability to download files to target systems.

T1105
Ingress Tool Transfer
MalwarePoisonIvy

PoisonIvy creates a backdoor through which remote attackers can upload files.

T1105
Ingress Tool Transfer
MalwareSeasalt

Seasalt has a command to download additional files.

T1105
Ingress Tool Transfer
MalwareNanoCore

NanoCore has the capability to download and activate additional modules for execution.

T1105
Ingress Tool Transfer
MalwarePLEAD

PLEAD has the ability to upload and download files to and from an infected host.

T1105
Ingress Tool Transfer
MalwareRaccoon Stealer

Raccoon Stealer downloads various library files enabling interaction with various data stores and structures to facilitate follow-on information theft.

T1105
Ingress Tool Transfer
MalwareDaserf

Daserf can download remote files.

T1105
Ingress Tool Transfer
MalwareCardinal RAT

Cardinal RAT can download and execute additional payloads.

T1105
Ingress Tool Transfer
MalwareDanBot

DanBot can download additional files to a targeted system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.