ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1105×

403 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
MalwareShamoon

Shamoon can download an executable to run on the victim.

T1105
Ingress Tool Transfer
MalwareDnsSystem

DnsSystem can download files to compromised systems after receiving a command with the string `downloaddd`.

T1105
Ingress Tool Transfer
MalwareMoleNet

MoleNet can download additional payloads from the C2.

T1105
Ingress Tool Transfer
MalwareJHUHUGIT

JHUHUGIT can retrieve an additional payload from its C2 server. JHUHUGIT has a command to download files to the victim’s machine.

T1105
Ingress Tool Transfer
MalwareBLUELIGHT

BLUELIGHT can download additional files onto the host.

T1105
Ingress Tool Transfer
MalwareKGH_SPY

KGH_SPY has the ability to download and execute code from remote servers.

T1105
Ingress Tool Transfer
Malwaredown_new

down_new has the ability to download files to the compromised host.

T1105
Ingress Tool Transfer
MalwareIxeshe

Ixeshe can download and execute additional files.

T1105
Ingress Tool Transfer
MalwareMicropsia

Micropsia can download and execute an executable from the C2 server.

T1105
Ingress Tool Transfer
MalwareKerrdown

Kerrdown can download specific payloads to a compromised host based on OS architecture.

T1105
Ingress Tool Transfer
MalwareRARSTONE

RARSTONE downloads its backdoor component from a C2 server and loads it directly into memory.

T1105
Ingress Tool Transfer
MalwareRedLine Stealer

RedLine Stealer has the ability download additional payloads.

T1105
Ingress Tool Transfer
MalwareVBShower

VBShower has the ability to download VBS files to the target computer.

T1105
Ingress Tool Transfer
MalwareStoneDrill

StoneDrill has downloaded and dropped temporary files containing scripts; it additionally has a function to upload files from the victims machine.

T1105
Ingress Tool Transfer
MalwareOopsIE

OopsIE can download files from its C2 server to the victim's machine.

T1105
Ingress Tool Transfer
MalwareRogueRobin

RogueRobin can save a new file to the system from the C2 server.

T1105
Ingress Tool Transfer
MalwareAttor

Attor can download additional plugins, updates and other files.

T1105
Ingress Tool Transfer
MalwareSQLRat

SQLRat can make a direct SQL connection to a Microsoft database controlled by the attackers, retrieve an item from the bindata table, then write and execute the file on disk.

T1105
Ingress Tool Transfer
MalwareLitePower

LitePower has the ability to download payloads containing system commands to a compromised host.

T1105
Ingress Tool Transfer
MalwareBoxCaon

BoxCaon can download files.

T1105
Ingress Tool Transfer
MalwareNightClub

NightClub can load multiple additional plugins on an infected host.

T1105
Ingress Tool Transfer
MalwareSDBbot

SDBbot has the ability to download a DLL from C2 to a compromised host.

T1105
Ingress Tool Transfer
MalwareMosquito

Mosquito can upload and download files to the victim.

T1105
Ingress Tool Transfer
MalwareRTM

RTM can download additional files.

T1105
Ingress Tool Transfer
MalwarePHPsert

PHPsert has the ability to retrieve remote payloads.

T1105
Ingress Tool Transfer
MalwareSodaMaster

SodaMaster has the ability to download additional payloads from C2 to the targeted system.

T1105
Ingress Tool Transfer
MalwareHikit

Hikit has the ability to download files to a compromised host.

T1105
Ingress Tool Transfer
MalwareStrelaStealer

StrelaStealer installers have used obfuscated PowerShell scripts to retrieve follow-on payloads from WebDAV servers.

T1105
Ingress Tool Transfer
MalwareGrandoreiro

Grandoreiro can download its second stage from a hardcoded URL within the loader's code.

T1105
Ingress Tool Transfer
MalwareWellMail

WellMail can receive data and executable scripts from C2.

T1105
Ingress Tool Transfer
MalwareLiteDuke

LiteDuke has the ability to download files.

T1105
Ingress Tool Transfer
MalwareSakula

Sakula has the capability to download files.

T1105
Ingress Tool Transfer
MalwareVaporRage

VaporRage has the ability to download malicious shellcode to compromised systems.

T1105
Ingress Tool Transfer
MalwareSibot

Sibot can download and execute a payload onto a compromised system.

T1105
Ingress Tool Transfer
MalwareZxxZ

ZxxZ can download and execute additional files.

T1105
Ingress Tool Transfer
MalwareCaminho

Caminho has the ability to download files onto compromised hosts.

T1105
Ingress Tool Transfer
MalwareDrovorub

Drovorub can download files to a compromised host.

T1105
Ingress Tool Transfer
MalwareShark

Shark can download additional files from its C2 via HTTP or DNS.

T1105
Ingress Tool Transfer
MalwareBazar

Bazar can download and deploy additional payloads, including ransomware and post-exploitation frameworks such as Cobalt Strike.

T1105
Ingress Tool Transfer
MalwareBadPatch

BadPatch can download and execute or update malware.

T1105
Ingress Tool Transfer
MalwareRATANKBA

RATANKBA uploads and downloads information.

T1105
Ingress Tool Transfer
MalwareNidiran

Nidiran can download and execute files.

T1105
Ingress Tool Transfer
MalwareHiddenFace

HiddenFace can download files from the C2 to victim systems.

T1105
Ingress Tool Transfer
MalwareCryptoistic

Cryptoistic has the ability to send and receive files.

T1105
Ingress Tool Transfer
MalwareABK

ABK has the ability to download files from C2.

T1105
Ingress Tool Transfer
MalwareOilCheck

OilCheck can download staged payloads from an actor-controlled infrastructure.

T1105
Ingress Tool Transfer
MalwareZebrocy

Zebrocy obtains additional code to execute on the victim's machine, including the downloading of a secondary payload.

T1105
Ingress Tool Transfer
MalwarePandora

Pandora can load additional drivers and files onto a victim machine.

T1105
Ingress Tool Transfer
MalwareSpeakUp

SpeakUp downloads and executes additional files from a remote server.

T1105
Ingress Tool Transfer
MalwareCobalt Strike

Cobalt Strike can deliver additional payloads to victim machines.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.