ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1105×

403 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
MalwareBisonal

Bisonal has the capability to download files to execute on the victim’s machine.

T1105
Ingress Tool Transfer
MalwareS-Type

S-Type can download additional files onto a compromised host.

T1105
Ingress Tool Transfer
MalwareSeaDuke

SeaDuke is capable of uploading and downloading files.

T1105
Ingress Tool Transfer
MalwareRemsec

Remsec contains a network loader to receive executable modules from remote attackers and run them on the local victim. It can also upload and download files over HTTP and HTTPS.

T1105
Ingress Tool Transfer
MalwareExplosive

Explosive has a function to download a file to the infected system.

T1105
Ingress Tool Transfer
MalwareXbash

Xbash can download additional malicious files from its C2 server.

T1105
Ingress Tool Transfer
MalwareLightNeuron

LightNeuron has the ability to download and execute additional files.

T1105
Ingress Tool Transfer
MalwarePeppy

Peppy can download and execute remote files.

T1105
Ingress Tool Transfer
MalwareCuba

Cuba can download files from its C2 server.

T1105
Ingress Tool Transfer
MalwareDEATHRANSOM

DEATHRANSOM can download files to a compromised host.

T1105
Ingress Tool Transfer
MalwarePureCrypter

PureCrypter can download additional payloads for execution on the compromised host.

T1105
Ingress Tool Transfer
MalwareDarkGate

DarkGate retrieves cryptocurrency mining payloads and commands in encrypted traffic from its command and control server. DarkGate uses Windows Batch scripts executing the curl command to retrieve follow-on payloads. DarkGate has stolen `sitemanager.xml` and `recentservers.xml` from `%APPDATA%\FileZilla\` if present.

T1105
Ingress Tool Transfer
MalwareMongall

Mongall can download files to targeted systems.

T1105
Ingress Tool Transfer
MalwareNanHaiShu

NanHaiShu can download additional files from URLs.

T1105
Ingress Tool Transfer
MalwareSVCReady

SVCReady has the ability to download additional tools such as the RedLine Stealer to an infected host.

T1105
Ingress Tool Transfer
MalwareThiefQuest

ThiefQuest can download and execute payloads in-memory or from disk.

T1105
Ingress Tool Transfer
MalwareFoggyWeb

FoggyWeb can receive additional malicious components from an actor controlled C2 server and execute them on a compromised AD FS server.

T1105
Ingress Tool Transfer
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can download files and additional malware components.

T1105
Ingress Tool Transfer
MalwareSHARPSTATS

SHARPSTATS has the ability to upload and download files.

T1105
Ingress Tool Transfer
MalwareCreepyDrive

CreepyDrive can download files to the compromised host.

T1105
Ingress Tool Transfer
MalwareCaterpillar WebShell

Caterpillar WebShell has a module to download and upload files to the system.

T1105
Ingress Tool Transfer
MalwareNetwalker

Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload.

T1105
Ingress Tool Transfer
MalwareElise

Elise can download additional files from the C2 server for execution.

T1105
Ingress Tool Transfer
MalwareGazer

Gazer can execute a task to download a file.

T1105
Ingress Tool Transfer
MalwareTSCookie

TSCookie has the ability to upload and download files to and from the infected host.

T1105
Ingress Tool Transfer
MalwareLatrodectus

Latrodectus can download and execute PEs, DLLs, and shellcode from C2.

T1105
Ingress Tool Transfer
MalwareSaint Bot

Saint Bot can download additional files onto a compromised host.

T1105
Ingress Tool Transfer
MalwareChaes

Chaes can download additional files onto an infected machine.

T1105
Ingress Tool Transfer
MalwareLODEINFO

LODEINFO has the ability to download additional files from the C2.

T1105
Ingress Tool Transfer
MalwareBriba

Briba downloads files onto infected hosts.

T1105
Ingress Tool Transfer
MalwareCharmPower

CharmPower has the ability to download additional modules to a compromised host.

T1105
Ingress Tool Transfer
MalwareMuddyViper

MuddyViper has the ability to download files from the C2 server. Additionally, MuddyViper has the ability to download a file in chunks with sleep time between each chunk.

T1105
Ingress Tool Transfer
MalwareTYPEFRAME

TYPEFRAME can upload and download files to the victim’s machine.

T1105
Ingress Tool Transfer
MalwareBundlore

Bundlore can download and execute new versions of itself.

T1105
Ingress Tool Transfer
MalwareP8RAT

P8RAT can download additional payloads to a target system.

T1105
Ingress Tool Transfer
MalwareEVILNUM

EVILNUM can download and upload files to the victim's computer.

T1105
Ingress Tool Transfer
MalwareSMOKEDHAM

SMOKEDHAM has used Powershell to download UltraVNC and ngrok from third-party file sharing sites.

T1105
Ingress Tool Transfer
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can download additional modules from its C2 server.

T1105
Ingress Tool Transfer
MalwareBendyBear

BendyBear is designed to download an implant from a C2 server.

T1105
Ingress Tool Transfer
MalwareGlassWorm

GlassWorm has downloaded additional payloads from C2.

T1105
Ingress Tool Transfer
MalwareUroburos

Uroburos can use a `Put` command to write files to an infected machine.

T1105
Ingress Tool Transfer
MalwareMetamorfo

Metamorfo has used MSI files to download additional files to execute.

T1105
Ingress Tool Transfer
MalwareSpica

Spica can upload and download files to and from compromised hosts.

T1105
Ingress Tool Transfer
MalwareTrojan.Karagany

Trojan.Karagany can upload, download, and execute files on the victim.

T1105
Ingress Tool Transfer
MalwareBandook

Bandook can download files to the system.

T1105
Ingress Tool Transfer
MalwarePipeMon

PipeMon can install additional modules via C2 commands.

T1105
Ingress Tool Transfer
MalwareMagicRAT

MagicRAT can import and execute additional payloads.

T1105
Ingress Tool Transfer
MalwareKONNI

KONNI can download files and execute them on the victim’s machine.

T1105
Ingress Tool Transfer
MalwareWinnti for Linux

Winnti for Linux has the ability to deploy modules directly from command and control (C2) servers, possibly for remote command execution, file exfiltration, and socks5 proxying on the infected host.

T1105
Ingress Tool Transfer
Malwaregh0st RAT

gh0st RAT can download files to the victim’s machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.