Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1105 Ingress Tool Transfer |
MalwareRTM | RTM can download additional files. |
| T1105 Ingress Tool Transfer |
MalwarePHPsert | PHPsert has the ability to retrieve remote payloads. |
| T1105 Ingress Tool Transfer |
MalwareSodaMaster | SodaMaster has the ability to download additional payloads from C2 to the targeted system. |
| T1105 Ingress Tool Transfer |
MalwareHikit | Hikit has the ability to download files to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareStrelaStealer | StrelaStealer installers have used obfuscated PowerShell scripts to retrieve follow-on payloads from WebDAV servers. |
| T1105 Ingress Tool Transfer |
MalwareGrandoreiro | Grandoreiro can download its second stage from a hardcoded URL within the loader's code. |
| T1105 Ingress Tool Transfer |
MalwareWellMail | WellMail can receive data and executable scripts from C2. |
| T1105 Ingress Tool Transfer |
MalwareLiteDuke | LiteDuke has the ability to download files. |
| T1105 Ingress Tool Transfer |
MalwareSakula | Sakula has the capability to download files. |
| T1105 Ingress Tool Transfer |
MalwareVaporRage | VaporRage has the ability to download malicious shellcode to compromised systems. |
| T1105 Ingress Tool Transfer |
MalwareSibot | Sibot can download and execute a payload onto a compromised system. |
| T1105 Ingress Tool Transfer |
MalwareZxxZ | ZxxZ can download and execute additional files. |
| T1105 Ingress Tool Transfer |
MalwareCaminho | Caminho has the ability to download files onto compromised hosts. |
| T1105 Ingress Tool Transfer |
MalwareDrovorub | Drovorub can download files to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareShark | Shark can download additional files from its C2 via HTTP or DNS. |
| T1105 Ingress Tool Transfer |
MalwareBazar | Bazar can download and deploy additional payloads, including ransomware and post-exploitation frameworks such as Cobalt Strike. |
| T1105 Ingress Tool Transfer |
MalwareBadPatch | BadPatch can download and execute or update malware. |
| T1105 Ingress Tool Transfer |
MalwareRATANKBA | RATANKBA uploads and downloads information. |
| T1105 Ingress Tool Transfer |
MalwareNidiran | Nidiran can download and execute files. |
| T1105 Ingress Tool Transfer |
MalwareHiddenFace | HiddenFace can download files from the C2 to victim systems. |
| T1105 Ingress Tool Transfer |
MalwareCryptoistic | Cryptoistic has the ability to send and receive files. |
| T1105 Ingress Tool Transfer |
MalwareABK | ABK has the ability to download files from C2. |
| T1105 Ingress Tool Transfer |
MalwareOilCheck | OilCheck can download staged payloads from an actor-controlled infrastructure. |
| T1105 Ingress Tool Transfer |
MalwareZebrocy | Zebrocy obtains additional code to execute on the victim's machine, including the downloading of a secondary payload. |
| T1105 Ingress Tool Transfer |
MalwarePandora | Pandora can load additional drivers and files onto a victim machine. |
| T1105 Ingress Tool Transfer |
MalwareSpeakUp | SpeakUp downloads and executes additional files from a remote server. |
| T1105 Ingress Tool Transfer |
MalwareCobalt Strike | Cobalt Strike can deliver additional payloads to victim machines. |
| T1105 Ingress Tool Transfer |
MalwareSampleCheck5000 | SampleCheck5000 can download additional payloads to compromised hosts. |
| T1105 Ingress Tool Transfer |
MalwareSUNBURST | SUNBURST delivered different payloads, including TEARDROP in at least one instance. |
| T1105 Ingress Tool Transfer |
MalwareEvilBunny | EvilBunny has downloaded additional Lua scripts from the C2. |
| T1105 Ingress Tool Transfer |
MalwareHotCroissant | HotCroissant has the ability to upload a file from the command and control (C2) server to the victim machine. |
| T1105 Ingress Tool Transfer |
MalwareServHelper | ServHelper may download additional files to execute. |
| T1105 Ingress Tool Transfer |
MalwareUnknown Logger | Unknown Logger is capable of downloading remote files. |
| T1105 Ingress Tool Transfer |
MalwareREvil | REvil can download a copy of itself from an attacker controlled IP address to the victim machine. |
| T1105 Ingress Tool Transfer |
MalwareValak | Valak has downloaded a variety of modules and payloads to the compromised host, including IcedID and NetSupport Manager RAT-based malware. |
| T1105 Ingress Tool Transfer |
MalwareSamurai | Samurai has been used to deploy other malware including Ninja. |
| T1105 Ingress Tool Transfer |
MalwareMilan | Milan has received files from C2 and stored them in log folders beginning with the character sequence `a9850d2f`. |
| T1105 Ingress Tool Transfer |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has a command to download and execute a file on the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareOilBooster | OilBooster can download and execute files from an actor-controlled OneDrive account. |
| T1105 Ingress Tool Transfer |
MalwareTaidoor | Taidoor has downloaded additional files onto a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareKivars | Kivars has the ability to download and execute files. |
| T1105 Ingress Tool Transfer |
MalwareCyclops Blink | Cyclops Blink has the ability to download files to target systems. |
| T1105 Ingress Tool Transfer |
MalwarePoisonIvy | PoisonIvy creates a backdoor through which remote attackers can upload files. |
| T1105 Ingress Tool Transfer |
MalwareSeasalt | Seasalt has a command to download additional files. |
| T1105 Ingress Tool Transfer |
MalwareNanoCore | NanoCore has the capability to download and activate additional modules for execution. |
| T1105 Ingress Tool Transfer |
MalwarePLEAD | PLEAD has the ability to upload and download files to and from an infected host. |
| T1105 Ingress Tool Transfer |
MalwareRaccoon Stealer | Raccoon Stealer downloads various library files enabling interaction with various data stores and structures to facilitate follow-on information theft. |
| T1105 Ingress Tool Transfer |
MalwareDaserf | Daserf can download remote files. |
| T1105 Ingress Tool Transfer |
MalwareCardinal RAT | Cardinal RAT can download and execute additional payloads. |
| T1105 Ingress Tool Transfer |
MalwareDanBot | DanBot can download additional files to a targeted system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.