Real-world descriptions of how a group, tool or campaign used a technique.
403 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1105 Ingress Tool Transfer |
MalwareShamoon | Shamoon can download an executable to run on the victim. |
| T1105 Ingress Tool Transfer |
MalwareDnsSystem | DnsSystem can download files to compromised systems after receiving a command with the string `downloaddd`. |
| T1105 Ingress Tool Transfer |
MalwareMoleNet | MoleNet can download additional payloads from the C2. |
| T1105 Ingress Tool Transfer |
MalwareJHUHUGIT | JHUHUGIT can retrieve an additional payload from its C2 server. JHUHUGIT has a command to download files to the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareBLUELIGHT | BLUELIGHT can download additional files onto the host. |
| T1105 Ingress Tool Transfer |
MalwareKGH_SPY | KGH_SPY has the ability to download and execute code from remote servers. |
| T1105 Ingress Tool Transfer |
Malwaredown_new | down_new has the ability to download files to the compromised host. |
| T1105 Ingress Tool Transfer |
MalwareIxeshe | Ixeshe can download and execute additional files. |
| T1105 Ingress Tool Transfer |
MalwareMicropsia | Micropsia can download and execute an executable from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareKerrdown | Kerrdown can download specific payloads to a compromised host based on OS architecture. |
| T1105 Ingress Tool Transfer |
MalwareRARSTONE | RARSTONE downloads its backdoor component from a C2 server and loads it directly into memory. |
| T1105 Ingress Tool Transfer |
MalwareRedLine Stealer | RedLine Stealer has the ability download additional payloads. |
| T1105 Ingress Tool Transfer |
MalwareVBShower | VBShower has the ability to download VBS files to the target computer. |
| T1105 Ingress Tool Transfer |
MalwareStoneDrill | StoneDrill has downloaded and dropped temporary files containing scripts; it additionally has a function to upload files from the victims machine. |
| T1105 Ingress Tool Transfer |
MalwareOopsIE | OopsIE can download files from its C2 server to the victim's machine. |
| T1105 Ingress Tool Transfer |
MalwareRogueRobin | RogueRobin can save a new file to the system from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareAttor | Attor can download additional plugins, updates and other files. |
| T1105 Ingress Tool Transfer |
MalwareSQLRat | SQLRat can make a direct SQL connection to a Microsoft database controlled by the attackers, retrieve an item from the bindata table, then write and execute the file on disk. |
| T1105 Ingress Tool Transfer |
MalwareLitePower | LitePower has the ability to download payloads containing system commands to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareBoxCaon | BoxCaon can download files. |
| T1105 Ingress Tool Transfer |
MalwareNightClub | NightClub can load multiple additional plugins on an infected host. |
| T1105 Ingress Tool Transfer |
MalwareSDBbot | SDBbot has the ability to download a DLL from C2 to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareMosquito | Mosquito can upload and download files to the victim. |
| T1105 Ingress Tool Transfer |
MalwareRTM | RTM can download additional files. |
| T1105 Ingress Tool Transfer |
MalwarePHPsert | PHPsert has the ability to retrieve remote payloads. |
| T1105 Ingress Tool Transfer |
MalwareSodaMaster | SodaMaster has the ability to download additional payloads from C2 to the targeted system. |
| T1105 Ingress Tool Transfer |
MalwareHikit | Hikit has the ability to download files to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareStrelaStealer | StrelaStealer installers have used obfuscated PowerShell scripts to retrieve follow-on payloads from WebDAV servers. |
| T1105 Ingress Tool Transfer |
MalwareGrandoreiro | Grandoreiro can download its second stage from a hardcoded URL within the loader's code. |
| T1105 Ingress Tool Transfer |
MalwareWellMail | WellMail can receive data and executable scripts from C2. |
| T1105 Ingress Tool Transfer |
MalwareLiteDuke | LiteDuke has the ability to download files. |
| T1105 Ingress Tool Transfer |
MalwareSakula | Sakula has the capability to download files. |
| T1105 Ingress Tool Transfer |
MalwareVaporRage | VaporRage has the ability to download malicious shellcode to compromised systems. |
| T1105 Ingress Tool Transfer |
MalwareSibot | Sibot can download and execute a payload onto a compromised system. |
| T1105 Ingress Tool Transfer |
MalwareZxxZ | ZxxZ can download and execute additional files. |
| T1105 Ingress Tool Transfer |
MalwareCaminho | Caminho has the ability to download files onto compromised hosts. |
| T1105 Ingress Tool Transfer |
MalwareDrovorub | Drovorub can download files to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareShark | Shark can download additional files from its C2 via HTTP or DNS. |
| T1105 Ingress Tool Transfer |
MalwareBazar | Bazar can download and deploy additional payloads, including ransomware and post-exploitation frameworks such as Cobalt Strike. |
| T1105 Ingress Tool Transfer |
MalwareBadPatch | BadPatch can download and execute or update malware. |
| T1105 Ingress Tool Transfer |
MalwareRATANKBA | RATANKBA uploads and downloads information. |
| T1105 Ingress Tool Transfer |
MalwareNidiran | Nidiran can download and execute files. |
| T1105 Ingress Tool Transfer |
MalwareHiddenFace | HiddenFace can download files from the C2 to victim systems. |
| T1105 Ingress Tool Transfer |
MalwareCryptoistic | Cryptoistic has the ability to send and receive files. |
| T1105 Ingress Tool Transfer |
MalwareABK | ABK has the ability to download files from C2. |
| T1105 Ingress Tool Transfer |
MalwareOilCheck | OilCheck can download staged payloads from an actor-controlled infrastructure. |
| T1105 Ingress Tool Transfer |
MalwareZebrocy | Zebrocy obtains additional code to execute on the victim's machine, including the downloading of a secondary payload. |
| T1105 Ingress Tool Transfer |
MalwarePandora | Pandora can load additional drivers and files onto a victim machine. |
| T1105 Ingress Tool Transfer |
MalwareSpeakUp | SpeakUp downloads and executes additional files from a remote server. |
| T1105 Ingress Tool Transfer |
MalwareCobalt Strike | Cobalt Strike can deliver additional payloads to victim machines. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.