Real-world descriptions of how a group, tool or campaign used a technique.
403 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1105 Ingress Tool Transfer |
MalwareBisonal | Bisonal has the capability to download files to execute on the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareS-Type | S-Type can download additional files onto a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareSeaDuke | SeaDuke is capable of uploading and downloading files. |
| T1105 Ingress Tool Transfer |
MalwareRemsec | Remsec contains a network loader to receive executable modules from remote attackers and run them on the local victim. It can also upload and download files over HTTP and HTTPS. |
| T1105 Ingress Tool Transfer |
MalwareExplosive | Explosive has a function to download a file to the infected system. |
| T1105 Ingress Tool Transfer |
MalwareXbash | Xbash can download additional malicious files from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareLightNeuron | LightNeuron has the ability to download and execute additional files. |
| T1105 Ingress Tool Transfer |
MalwarePeppy | Peppy can download and execute remote files. |
| T1105 Ingress Tool Transfer |
MalwareCuba | Cuba can download files from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareDEATHRANSOM | DEATHRANSOM can download files to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwarePureCrypter | PureCrypter can download additional payloads for execution on the compromised host. |
| T1105 Ingress Tool Transfer |
MalwareDarkGate | DarkGate retrieves cryptocurrency mining payloads and commands in encrypted traffic from its command and control server. DarkGate uses Windows Batch scripts executing the |
| T1105 Ingress Tool Transfer |
MalwareMongall | Mongall can download files to targeted systems. |
| T1105 Ingress Tool Transfer |
MalwareNanHaiShu | NanHaiShu can download additional files from URLs. |
| T1105 Ingress Tool Transfer |
MalwareSVCReady | SVCReady has the ability to download additional tools such as the RedLine Stealer to an infected host. |
| T1105 Ingress Tool Transfer |
MalwareThiefQuest | ThiefQuest can download and execute payloads in-memory or from disk. |
| T1105 Ingress Tool Transfer |
MalwareFoggyWeb | FoggyWeb can receive additional malicious components from an actor controlled C2 server and execute them on a compromised AD FS server. |
| T1105 Ingress Tool Transfer |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can download files and additional malware components. |
| T1105 Ingress Tool Transfer |
MalwareSHARPSTATS | SHARPSTATS has the ability to upload and download files. |
| T1105 Ingress Tool Transfer |
MalwareCreepyDrive | CreepyDrive can download files to the compromised host. |
| T1105 Ingress Tool Transfer |
MalwareCaterpillar WebShell | Caterpillar WebShell has a module to download and upload files to the system. |
| T1105 Ingress Tool Transfer |
MalwareNetwalker | Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload. |
| T1105 Ingress Tool Transfer |
MalwareElise | Elise can download additional files from the C2 server for execution. |
| T1105 Ingress Tool Transfer |
MalwareGazer | Gazer can execute a task to download a file. |
| T1105 Ingress Tool Transfer |
MalwareTSCookie | TSCookie has the ability to upload and download files to and from the infected host. |
| T1105 Ingress Tool Transfer |
MalwareLatrodectus | Latrodectus can download and execute PEs, DLLs, and shellcode from C2. |
| T1105 Ingress Tool Transfer |
MalwareSaint Bot | Saint Bot can download additional files onto a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareChaes | Chaes can download additional files onto an infected machine. |
| T1105 Ingress Tool Transfer |
MalwareLODEINFO | LODEINFO has the ability to download additional files from the C2. |
| T1105 Ingress Tool Transfer |
MalwareBriba | Briba downloads files onto infected hosts. |
| T1105 Ingress Tool Transfer |
MalwareCharmPower | CharmPower has the ability to download additional modules to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareMuddyViper | MuddyViper has the ability to download files from the C2 server. Additionally, MuddyViper has the ability to download a file in chunks with sleep time between each chunk. |
| T1105 Ingress Tool Transfer |
MalwareTYPEFRAME | TYPEFRAME can upload and download files to the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareBundlore | Bundlore can download and execute new versions of itself. |
| T1105 Ingress Tool Transfer |
MalwareP8RAT | P8RAT can download additional payloads to a target system. |
| T1105 Ingress Tool Transfer |
MalwareEVILNUM | EVILNUM can download and upload files to the victim's computer. |
| T1105 Ingress Tool Transfer |
MalwareSMOKEDHAM | SMOKEDHAM has used Powershell to download UltraVNC and ngrok from third-party file sharing sites. |
| T1105 Ingress Tool Transfer |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can download additional modules from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareBendyBear | BendyBear is designed to download an implant from a C2 server. |
| T1105 Ingress Tool Transfer |
MalwareGlassWorm | GlassWorm has downloaded additional payloads from C2. |
| T1105 Ingress Tool Transfer |
MalwareUroburos | Uroburos can use a `Put` command to write files to an infected machine. |
| T1105 Ingress Tool Transfer |
MalwareMetamorfo | Metamorfo has used MSI files to download additional files to execute. |
| T1105 Ingress Tool Transfer |
MalwareSpica | Spica can upload and download files to and from compromised hosts. |
| T1105 Ingress Tool Transfer |
MalwareTrojan.Karagany | Trojan.Karagany can upload, download, and execute files on the victim. |
| T1105 Ingress Tool Transfer |
MalwareBandook | Bandook can download files to the system. |
| T1105 Ingress Tool Transfer |
MalwarePipeMon | PipeMon can install additional modules via C2 commands. |
| T1105 Ingress Tool Transfer |
MalwareMagicRAT | MagicRAT can import and execute additional payloads. |
| T1105 Ingress Tool Transfer |
MalwareKONNI | KONNI can download files and execute them on the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareWinnti for Linux | Winnti for Linux has the ability to deploy modules directly from command and control (C2) servers, possibly for remote command execution, file exfiltration, and socks5 proxying on the infected host. |
| T1105 Ingress Tool Transfer |
Malwaregh0st RAT | gh0st RAT can download files to the victim’s machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.