ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
MalwareBISCUIT

BISCUIT has a command to download a file from the C2 server.

T1105
Ingress Tool Transfer
MalwareCalisto

Calisto has the capability to upload and download files to the victim's machine.

T1105
Ingress Tool Transfer
MalwareSolar

Solar has the ability to download and execute files.

T1105
Ingress Tool Transfer
MalwarePisloader

Pisloader has a command to upload a file to the victim machine.

T1105
Ingress Tool Transfer
MalwareGoldenSpy

GoldenSpy constantly attempts to download and execute files from the remote C2, including GoldenSpy itself if not found on the system.

T1105
Ingress Tool Transfer
MalwareGold Dragon

Gold Dragon can download additional components from the C2 server.

T1105
Ingress Tool Transfer
MalwareRGDoor

RGDoor uploads and downloads files to and from the victim’s machine.

T1105
Ingress Tool Transfer
MalwareNeo-reGeorg

Neo-reGeorg has the ability to download files to targeted systems.

T1105
Ingress Tool Transfer
MalwareAshTag

The AshTag stager component can retrieve and execute the main payload.

T1105
Ingress Tool Transfer
MalwareCarberp

Carberp can download and execute new plugins from the C2 server.

T1105
Ingress Tool Transfer
MalwareRevenge RAT

Revenge RAT has the ability to upload and download files.

T1105
Ingress Tool Transfer
MalwareMacMa

MacMa has downloaded additional files, including an exploit for used privilege escalation.

T1105
Ingress Tool Transfer
MalwareFunnyDream

FunnyDream can download additional files onto a compromised host.

T1105
Ingress Tool Transfer
MalwareMore_eggs

More_eggs can download and launch additional payloads.

T1105
Ingress Tool Transfer
MalwareSysUpdate

SysUpdate has the ability to download files to a compromised host.

T1105
Ingress Tool Transfer
MalwareOutSteel

OutSteel can download files from its C2 server.

T1105
Ingress Tool Transfer
MalwareBackConfig

BackConfig can download and execute additional payloads on a compromised host.

T1105
Ingress Tool Transfer
MalwareKwampirs

Kwampirs downloads additional files from C2 servers.

T1105
Ingress Tool Transfer
MalwareNerex

Nerex creates a backdoor through which remote attackers can download files onto a compromised host.

T1105
Ingress Tool Transfer
MalwareBoomBox

BoomBox has the ability to download next stage malware components to a compromised system.

T1105
Ingress Tool Transfer
MalwareWIREFIRE

WIREFIRE has the ability to download files to compromised devices.

T1105
Ingress Tool Transfer
MalwareKessel

Kessel can download additional modules from the C2 server.

T1105
Ingress Tool Transfer
MalwareGrimAgent

GrimAgent has the ability to download and execute additional payloads.

T1105
Ingress Tool Transfer
MalwareSTEADYPULSE

STEADYPULSE can add lines to a Perl script on a targeted server to import additional Perl modules.

T1105
Ingress Tool Transfer
MalwarePHASEJAM

PHASEJAM has the ability to upload files onto the compromised appliance.

T1105
Ingress Tool Transfer
MalwareYAHOYAH

YAHOYAH uses HTTP GET requests to download other files that are executed in memory.

T1105
Ingress Tool Transfer
MalwareLokibot

Lokibot downloaded several staged items onto the victim's machine.

T1105
Ingress Tool Transfer
MalwareCallMe

CallMe has the capability to download a file to the victim from the C2 server.

T1105
Ingress Tool Transfer
MalwareCloudDuke

CloudDuke downloads and executes additional malware from either a Web address or a Microsoft OneDrive account.

T1105
Ingress Tool Transfer
MalwareEgregor

Egregor has the ability to download files from its C2 server.

T1105
Ingress Tool Transfer
MalwarePoetRAT

PoetRAT has the ability to copy files and download/upload files into C2 channels using FTP and HTTPS.

T1105
Ingress Tool Transfer
MalwareCHOPSTICK

CHOPSTICK is capable of performing remote file transmission.

T1105
Ingress Tool Transfer
MalwareFELIXROOT

FELIXROOT downloads and uploads files to and from the victim’s machine.

T1105
Ingress Tool Transfer
MalwareZxShell

ZxShell has a command to transfer files from a remote host.

T1105
Ingress Tool Transfer
MalwareRIFLESPINE

RIFLESPINE can download and execute files.

T1105
Ingress Tool Transfer
MalwareSLIGHTPULSE

RAPIDPULSE can transfer files to and from compromised hosts.

T1105
Ingress Tool Transfer
MalwareNDiskMonitor

NDiskMonitor can download and execute a file from given URL.

T1105
Ingress Tool Transfer
MalwareCoinTicker

CoinTicker executes a Python script to download its second stage.

T1105
Ingress Tool Transfer
MalwareDDKONG

DDKONG downloads and uploads files on the victim’s machine.

T1105
Ingress Tool Transfer
MalwarePenquin

Penquin can execute the command code do_download to retrieve remote files from C2.

T1105
Ingress Tool Transfer
MalwareBabyShark

BabyShark has downloaded additional files from the C2.

T1105
Ingress Tool Transfer
MalwareCannon

Cannon can download a payload for execution.

T1105
Ingress Tool Transfer
Malwarebuild_downer

build_downer has the ability to download files from C2 to the infected host.

T1105
Ingress Tool Transfer
MalwareMelcoz

Melcoz has the ability to download additional files to a compromised host.

T1105
Ingress Tool Transfer
MalwareWinnti for Windows

The Winnti for Windows dropper can place malicious payloads on targeted systems.

T1105
Ingress Tool Transfer
MalwarePowerPunch

PowerPunch can download payloads from adversary infrastructure.

T1105
Ingress Tool Transfer
MalwareBONDUPDATER

BONDUPDATER can download or upload files from its C2 server.

T1105
Ingress Tool Transfer
MalwareKinsing

Kinsing has downloaded additional lateral movement scripts from C2.

T1105
Ingress Tool Transfer
MalwareMeteor

Meteor has the ability to download additional files for execution on the victim's machine.

T1105
Ingress Tool Transfer
MalwarenjRAT

njRAT can download files to the victim’s machine. APT-C-36 has used modified versions of njRAT to enable the download of .NET assemblies.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.