ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1105×

403 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
MalwareTONESHELL

TONESHELL has the ability to download additional files to the victim device.

T1105
Ingress Tool Transfer
MalwareKasidet

Kasidet has the ability to download and execute additional files.

T1105
Ingress Tool Transfer
MalwareHannotog

Hannotog can download additional files to the victim machine.

T1105
Ingress Tool Transfer
MalwareRainyDay

RainyDay can download files to a compromised host.

T1105
Ingress Tool Transfer
MalwareEcipekac

Ecipekac can download additional payloads to a compromised host.

T1105
Ingress Tool Transfer
MalwareBUSHWALK

BUSHWALK can write malicious payloads sent through a web request’s command parameter.

T1105
Ingress Tool Transfer
MalwaremacOS.OSAMiner

macOS.OSAMiner has used `curl` to download a Stripped Payloads from a public facing adversary-controlled webpage.

T1105
Ingress Tool Transfer
MalwareLOWBALL

LOWBALL uses the Dropbox API to request two files, one of which is the same file as the one dropped by the malicious email attachment. This is most likely meant to be a mechanism to update the compromised host with a new version of the LOWBALL malware.

T1105
Ingress Tool Transfer
MalwareNETWIRE

NETWIRE can downloaded payloads from C2 to the compromised host.

T1105
Ingress Tool Transfer
MalwareTinyTurla

TinyTurla has the ability to act as a second-stage dropper used to infect the system with additional malware.

T1105
Ingress Tool Transfer
MalwarePowerExchange

PowerExchange can decode Base64-encoded files and call `WriteAllBytes` to write the files to compromised hosts.

T1105
Ingress Tool Transfer
MalwareIMAPLoader

IMAPLoader is a loader used to retrieve follow-on payload encoded in email messages for execution on victim systems.

T1105
Ingress Tool Transfer
MalwareGreyEnergy

GreyEnergy can download additional modules and payloads.

T1105
Ingress Tool Transfer
MalwareAria-body

Aria-body has the ability to download additional payloads from C2.

T1105
Ingress Tool Transfer
MalwareEmotet

Emotet can download follow-on payloads and items via malicious `url` parameters in obfuscated PowerShell code.

T1105
Ingress Tool Transfer
MalwareCrimson

Crimson contains a command to retrieve files from its C2 server.

T1105
Ingress Tool Transfer
MalwareTomiris

Tomiris can download files and execute them on a victim's system.

T1105
Ingress Tool Transfer
MalwareDUSTTRAP

DUSTTRAP can retrieve and load additional payloads.

T1105
Ingress Tool Transfer
MalwareTurian

Turian can download additional files and tools from its C2.

T1105
Ingress Tool Transfer
MalwareBADHATCH

BADHATCH has the ability to load a second stage malicious DLL file onto a compromised machine.

T1105
Ingress Tool Transfer
MalwareMachete

Machete can download additional files for execution on the victim’s machine.

T1105
Ingress Tool Transfer
MalwarePowerLess

PowerLess can download additional payloads to a compromised host.

T1105
Ingress Tool Transfer
MalwareAction RAT

Action RAT has the ability to download additional payloads onto an infected machine.

T1105
Ingress Tool Transfer
MalwareAvenger

Avenger has the ability to download files from C2 to a compromised host.

T1105
Ingress Tool Transfer
MalwarePUBLOAD

PUBLOAD has acted as a stager that can download the next-stage payload from its C2 server. PUBLOAD has also delivered FDMTP as a secondary control tool and PTSOCKET for exfiltration to some infected systems.

T1105
Ingress Tool Transfer
MalwareSystemBC

SystemBC has downloaded additional files for execution on the victim’s machine. The server component of SystemBC has the ability to send additional files to victim machines.

T1105
Ingress Tool Transfer
MalwareGootloader

Gootloader can fetch second stage code from hardcoded web domains.

T1105
Ingress Tool Transfer
MalwareWellMess

WellMess can write files to a compromised host.

T1105
Ingress Tool Transfer
MalwareDacls

Dacls can download its payload from a C2 server.

T1105
Ingress Tool Transfer
MalwareDropBook

DropBook can download and execute additional files.

T1105
Ingress Tool Transfer
MalwareWoody RAT

Woody RAT can download files from its C2 server, including the .NET DLLs, `WoodySharpExecutor` and `WoodyPowerSession`.

T1105
Ingress Tool Transfer
MalwareMafalda

Mafalda can download additional files onto the compromised host.

T1105
Ingress Tool Transfer
MalwareKARAE

KARAE can upload and download files, including second-stage malware.

T1105
Ingress Tool Transfer
MalwareSquirrelwaffle

Squirrelwaffle has downloaded and executed additional encoded payloads.

T1105
Ingress Tool Transfer
MalwarePolyglotDuke

PolyglotDuke can retrieve payloads from the C2 server.

T1105
Ingress Tool Transfer
MalwareHexEval Loader

HexEval Loader has been used to download a malicious payload to include BeaverTail.

T1105
Ingress Tool Transfer
MalwareHildegard

Hildegard has downloaded additional scripts that build and run Monero cryptocurrency miners.

T1105
Ingress Tool Transfer
MalwareAgent.btz

Agent.btz attempts to download an encrypted binary from a specified domain.

T1105
Ingress Tool Transfer
MalwareSLOWDRIFT

SLOWDRIFT downloads additional payloads.

T1105
Ingress Tool Transfer
MalwareSHUTTERSPEED

SHUTTERSPEED can download and execute an arbitary executable.

T1105
Ingress Tool Transfer
MalwareSombRAT

SombRAT has the ability to download and execute additional payloads.

T1105
Ingress Tool Transfer
MalwareODAgent

ODAgent has the ability to download and execute files on compromised systems.

T1105
Ingress Tool Transfer
MalwareFlawedAmmyy

FlawedAmmyy can transfer files from C2.

T1105
Ingress Tool Transfer
MalwareSnip3

Snip3 can download additional payloads to compromised systems.

T1105
Ingress Tool Transfer
MalwareFYAnti

FYAnti can download additional payloads to a compromised host.

T1105
Ingress Tool Transfer
MalwareHOPLIGHT

HOPLIGHT has the ability to connect to a remote host in order to upload and download files.

T1105
Ingress Tool Transfer
MalwareGuLoader

GuLoader can download further malware for execution on the victim's machine.

T1105
Ingress Tool Transfer
MalwareMobileOrder

MobileOrder has a command to download a file from the C2 server to the victim mobile device's SD card.

T1105
Ingress Tool Transfer
MalwareRegDuke

RegDuke can download files from C2.

T1105
Ingress Tool Transfer
MalwareInvisiMole

InvisiMole can upload files to the victim's machine for operations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.