Real-world descriptions of how a group, tool or campaign used a technique.
403 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1105 Ingress Tool Transfer |
MalwareTONESHELL | TONESHELL has the ability to download additional files to the victim device. |
| T1105 Ingress Tool Transfer |
MalwareKasidet | Kasidet has the ability to download and execute additional files. |
| T1105 Ingress Tool Transfer |
MalwareHannotog | Hannotog can download additional files to the victim machine. |
| T1105 Ingress Tool Transfer |
MalwareRainyDay | RainyDay can download files to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareEcipekac | Ecipekac can download additional payloads to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareBUSHWALK | BUSHWALK can write malicious payloads sent through a web request’s command parameter. |
| T1105 Ingress Tool Transfer |
MalwaremacOS.OSAMiner | macOS.OSAMiner has used `curl` to download a Stripped Payloads from a public facing adversary-controlled webpage. |
| T1105 Ingress Tool Transfer |
MalwareLOWBALL | LOWBALL uses the Dropbox API to request two files, one of which is the same file as the one dropped by the malicious email attachment. This is most likely meant to be a mechanism to update the compromised host with a new version of the LOWBALL malware. |
| T1105 Ingress Tool Transfer |
MalwareNETWIRE | NETWIRE can downloaded payloads from C2 to the compromised host. |
| T1105 Ingress Tool Transfer |
MalwareTinyTurla | TinyTurla has the ability to act as a second-stage dropper used to infect the system with additional malware. |
| T1105 Ingress Tool Transfer |
MalwarePowerExchange | PowerExchange can decode Base64-encoded files and call `WriteAllBytes` to write the files to compromised hosts. |
| T1105 Ingress Tool Transfer |
MalwareIMAPLoader | IMAPLoader is a loader used to retrieve follow-on payload encoded in email messages for execution on victim systems. |
| T1105 Ingress Tool Transfer |
MalwareGreyEnergy | GreyEnergy can download additional modules and payloads. |
| T1105 Ingress Tool Transfer |
MalwareAria-body | Aria-body has the ability to download additional payloads from C2. |
| T1105 Ingress Tool Transfer |
MalwareEmotet | Emotet can download follow-on payloads and items via malicious `url` parameters in obfuscated PowerShell code. |
| T1105 Ingress Tool Transfer |
MalwareCrimson | Crimson contains a command to retrieve files from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareTomiris | Tomiris can download files and execute them on a victim's system. |
| T1105 Ingress Tool Transfer |
MalwareDUSTTRAP | DUSTTRAP can retrieve and load additional payloads. |
| T1105 Ingress Tool Transfer |
MalwareTurian | Turian can download additional files and tools from its C2. |
| T1105 Ingress Tool Transfer |
MalwareBADHATCH | BADHATCH has the ability to load a second stage malicious DLL file onto a compromised machine. |
| T1105 Ingress Tool Transfer |
MalwareMachete | Machete can download additional files for execution on the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwarePowerLess | PowerLess can download additional payloads to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareAction RAT | Action RAT has the ability to download additional payloads onto an infected machine. |
| T1105 Ingress Tool Transfer |
MalwareAvenger | Avenger has the ability to download files from C2 to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwarePUBLOAD | PUBLOAD has acted as a stager that can download the next-stage payload from its C2 server. PUBLOAD has also delivered FDMTP as a secondary control tool and PTSOCKET for exfiltration to some infected systems. |
| T1105 Ingress Tool Transfer |
MalwareSystemBC | SystemBC has downloaded additional files for execution on the victim’s machine. The server component of SystemBC has the ability to send additional files to victim machines. |
| T1105 Ingress Tool Transfer |
MalwareGootloader | Gootloader can fetch second stage code from hardcoded web domains. |
| T1105 Ingress Tool Transfer |
MalwareWellMess | WellMess can write files to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareDacls | Dacls can download its payload from a C2 server. |
| T1105 Ingress Tool Transfer |
MalwareDropBook | DropBook can download and execute additional files. |
| T1105 Ingress Tool Transfer |
MalwareWoody RAT | Woody RAT can download files from its C2 server, including the .NET DLLs, `WoodySharpExecutor` and `WoodyPowerSession`. |
| T1105 Ingress Tool Transfer |
MalwareMafalda | Mafalda can download additional files onto the compromised host. |
| T1105 Ingress Tool Transfer |
MalwareKARAE | KARAE can upload and download files, including second-stage malware. |
| T1105 Ingress Tool Transfer |
MalwareSquirrelwaffle | Squirrelwaffle has downloaded and executed additional encoded payloads. |
| T1105 Ingress Tool Transfer |
MalwarePolyglotDuke | PolyglotDuke can retrieve payloads from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareHexEval Loader | HexEval Loader has been used to download a malicious payload to include BeaverTail. |
| T1105 Ingress Tool Transfer |
MalwareHildegard | Hildegard has downloaded additional scripts that build and run Monero cryptocurrency miners. |
| T1105 Ingress Tool Transfer |
MalwareAgent.btz | Agent.btz attempts to download an encrypted binary from a specified domain. |
| T1105 Ingress Tool Transfer |
MalwareSLOWDRIFT | SLOWDRIFT downloads additional payloads. |
| T1105 Ingress Tool Transfer |
MalwareSHUTTERSPEED | SHUTTERSPEED can download and execute an arbitary executable. |
| T1105 Ingress Tool Transfer |
MalwareSombRAT | SombRAT has the ability to download and execute additional payloads. |
| T1105 Ingress Tool Transfer |
MalwareODAgent | ODAgent has the ability to download and execute files on compromised systems. |
| T1105 Ingress Tool Transfer |
MalwareFlawedAmmyy | FlawedAmmyy can transfer files from C2. |
| T1105 Ingress Tool Transfer |
MalwareSnip3 | Snip3 can download additional payloads to compromised systems. |
| T1105 Ingress Tool Transfer |
MalwareFYAnti | FYAnti can download additional payloads to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareHOPLIGHT | HOPLIGHT has the ability to connect to a remote host in order to upload and download files. |
| T1105 Ingress Tool Transfer |
MalwareGuLoader | GuLoader can download further malware for execution on the victim's machine. |
| T1105 Ingress Tool Transfer |
MalwareMobileOrder | MobileOrder has a command to download a file from the C2 server to the victim mobile device's SD card. |
| T1105 Ingress Tool Transfer |
MalwareRegDuke | RegDuke can download files from C2. |
| T1105 Ingress Tool Transfer |
MalwareInvisiMole | InvisiMole can upload files to the victim's machine for operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.