ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1105×

403 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
MalwareP.A.S. Webshell

P.A.S. Webshell can upload and download files to and from compromised hosts.

T1105
Ingress Tool Transfer
MalwareVolgmer

Volgmer can download remote files and additional payloads to the victim's machine.

T1105
Ingress Tool Transfer
MalwareWhisperGate

WhisperGate can download additional stages of malware from a Discord CDN channel.

T1105
Ingress Tool Transfer
MalwareZeroT

ZeroT can download additional payloads onto the victim.

T1105
Ingress Tool Transfer
MalwareRDAT

RDAT can download files via DNS.

T1105
Ingress Tool Transfer
MalwareSkidmap

Skidmap has the ability to download files on an infected host.

T1105
Ingress Tool Transfer
MalwareOkrum

Okrum has built-in commands for uploading, downloading, and executing files to the system.

T1105
Ingress Tool Transfer
MalwareBonadan

Bonadan can download additional modules from the C2 server.

T1105
Ingress Tool Transfer
MalwareNeoichor

Neoichor can download additional files onto a compromised host.

T1105
Ingress Tool Transfer
MalwareRaspberry Robin

Raspberry Robin retrieves its second stage payload in a variety of ways such as through msiexec.exe abuse, or running the curl command to download the payload to the victim's %AppData% folder.

T1105
Ingress Tool Transfer
MalwareRemoteCMD

RemoteCMD copies a file over to the remote system before execution.

T1105
Ingress Tool Transfer
MalwareDiavol

Diavol can receive configuration updates and additional payloads including wscpy.exe from C2.

T1105
Ingress Tool Transfer
MalwareDoki

Doki has downloaded scripts from C2.

T1105
Ingress Tool Transfer
MalwareIcedID

IcedID has the ability to download additional modules and a configuration file from C2.

T1105
Ingress Tool Transfer
MalwareVERMIN

VERMIN can download and upload files to the victim's machine.

T1105
Ingress Tool Transfer
MalwareUBoatRAT

UBoatRAT can upload and download files to the victim’s machine.

T1105
Ingress Tool Transfer
MalwareHTTPTroy

HTTPTroy has the ability to download files from C2 using the `down <FILENAME>` command.

T1105
Ingress Tool Transfer
MalwareMarkiRAT

MarkiRAT can download additional files and tools from its C2 server, including through the use of BITSAdmin.

T1105
Ingress Tool Transfer
MalwareKazuar

Kazuar downloads additional plug-ins to load on the victim’s machine, including the ability to upgrade and replace its own binary.

T1105
Ingress Tool Transfer
MalwareNavRAT

NavRAT can download files remotely.

T1105
Ingress Tool Transfer
MalwareDarkComet

DarkComet can load any files onto the infected machine to execute.

T1105
Ingress Tool Transfer
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can download additional files from C2.

T1105
Ingress Tool Transfer
MalwareLucifer

Lucifer can download and execute a replica of itself using certutil.

T1105
Ingress Tool Transfer
MalwareDRATzarus

DRATzarus can deploy additional tools onto an infected machine.

T1105
Ingress Tool Transfer
MalwareShimRat

ShimRat can download additional files.

T1105
Ingress Tool Transfer
MalwareChrommme

Chrommme can download its code from C2.

T1105
Ingress Tool Transfer
MalwareConficker

Conficker downloads an HTTP server to the infected machine.

T1105
Ingress Tool Transfer
MalwareSocGholish

SocGholish can download additional malware to infected hosts.

T1105
Ingress Tool Transfer
MalwareFlagpro

Flagpro can download additional malware from the C2 server.

T1105
Ingress Tool Transfer
MalwareHi-Zor

Hi-Zor has the ability to upload and download files from its C2 server.

T1105
Ingress Tool Transfer
MalwareSpicyOmelette

SpicyOmelette can download malicious files from threat actor controlled AWS URL's.

T1105
Ingress Tool Transfer
MalwareChina Chopper

China Chopper's server component can download remote files.

T1105
Ingress Tool Transfer
MalwareLightSpy

On macOS, LightSpy downloads a `.json` file from the C2 server. The `.json` file contains metadata about the plugins to be downloaded, including their URL, name, version, and MD5 hash. LightSpy retrieves the plugins specified in the `.json` file, which are compiled `.dylib` files. These `.dylib` files provide task and platform specific functionality. LightSpy also imports open-source libraries to manage socket connections.

T1105
Ingress Tool Transfer
MalwarePUNCHBUGGY

PUNCHBUGGY can download additional files and payloads to compromised hosts.

T1105
Ingress Tool Transfer
MalwareGoldMax

GoldMax can download and execute additional files.

T1105
Ingress Tool Transfer
MalwareCostaBricks

CostaBricks has been used to load SombRAT onto a compromised host.

T1105
Ingress Tool Transfer
MalwareKeyBoy

KeyBoy has a download and upload functionality.

T1105
Ingress Tool Transfer
MalwarePOSHSPY

POSHSPY downloads and executes additional PowerShell code and Windows binaries.

T1105
Ingress Tool Transfer
MalwareMiniDuke

MiniDuke can download additional encrypted backdoors onto the victim via GIF files.

T1105
Ingress Tool Transfer
MalwareHyperBro

HyperBro has the ability to download additional files.

T1105
Ingress Tool Transfer
MalwareAnchor

Anchor can download additional payloads.

T1105
Ingress Tool Transfer
MalwarePteranodon

Pteranodon can download and execute additional files.

T1105
Ingress Tool Transfer
MalwareDarkTortilla

DarkTortilla can download additional packages for keylogging, cryptocurrency mining, and other capabilities; it can also retrieve malicious payloads such as Agent Tesla, AsyncRat, NanoCore, RedLine, Cobalt Strike, and Metasploit.

T1105
Ingress Tool Transfer
MalwareBeaverTail

BeaverTail has been used to download a malicious payload to include Python based malware InvisibleFerret.

T1105
Ingress Tool Transfer
MalwareROKRAT

ROKRAT can retrieve additional malicious payloads from its C2 server.

T1105
Ingress Tool Transfer
MalwareCORESHELL

CORESHELL downloads another dropper from its C2 server.

T1105
Ingress Tool Transfer
MalwareDyre

Dyre has a command to download and executes additional files.

T1105
Ingress Tool Transfer
MalwareBlackMould

BlackMould has the ability to download files to the victim's machine.

T1105
Ingress Tool Transfer
MalwareJavali

Javali can download payloads from remote C2 servers.

T1105
Ingress Tool Transfer
MalwarePlugX

PlugX has a module to download and execute files on the compromised machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.