ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1105×

403 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
MalwareSampleCheck5000

SampleCheck5000 can download additional payloads to compromised hosts.

T1105
Ingress Tool Transfer
MalwareSUNBURST

SUNBURST delivered different payloads, including TEARDROP in at least one instance.

T1105
Ingress Tool Transfer
MalwareEvilBunny

EvilBunny has downloaded additional Lua scripts from the C2.

T1105
Ingress Tool Transfer
MalwareHotCroissant

HotCroissant has the ability to upload a file from the command and control (C2) server to the victim machine.

T1105
Ingress Tool Transfer
MalwareServHelper

ServHelper may download additional files to execute.

T1105
Ingress Tool Transfer
MalwareUnknown Logger

Unknown Logger is capable of downloading remote files.

T1105
Ingress Tool Transfer
MalwareREvil

REvil can download a copy of itself from an attacker controlled IP address to the victim machine.

T1105
Ingress Tool Transfer
MalwareValak

Valak has downloaded a variety of modules and payloads to the compromised host, including IcedID and NetSupport Manager RAT-based malware.

T1105
Ingress Tool Transfer
MalwareSamurai

Samurai has been used to deploy other malware including Ninja.

T1105
Ingress Tool Transfer
MalwareMilan

Milan has received files from C2 and stored them in log folders beginning with the character sequence `a9850d2f`.

T1105
Ingress Tool Transfer
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has a command to download and execute a file on the victim’s machine.

T1105
Ingress Tool Transfer
MalwareOilBooster

OilBooster can download and execute files from an actor-controlled OneDrive account.

T1105
Ingress Tool Transfer
MalwareTaidoor

Taidoor has downloaded additional files onto a compromised host.

T1105
Ingress Tool Transfer
MalwareKivars

Kivars has the ability to download and execute files.

T1105
Ingress Tool Transfer
MalwareCyclops Blink

Cyclops Blink has the ability to download files to target systems.

T1105
Ingress Tool Transfer
MalwarePoisonIvy

PoisonIvy creates a backdoor through which remote attackers can upload files.

T1105
Ingress Tool Transfer
MalwareSeasalt

Seasalt has a command to download additional files.

T1105
Ingress Tool Transfer
MalwareNanoCore

NanoCore has the capability to download and activate additional modules for execution.

T1105
Ingress Tool Transfer
MalwarePLEAD

PLEAD has the ability to upload and download files to and from an infected host.

T1105
Ingress Tool Transfer
MalwareRaccoon Stealer

Raccoon Stealer downloads various library files enabling interaction with various data stores and structures to facilitate follow-on information theft.

T1105
Ingress Tool Transfer
MalwareDaserf

Daserf can download remote files.

T1105
Ingress Tool Transfer
MalwareCardinal RAT

Cardinal RAT can download and execute additional payloads.

T1105
Ingress Tool Transfer
MalwareDanBot

DanBot can download additional files to a targeted system.

T1105
Ingress Tool Transfer
MalwareBISCUIT

BISCUIT has a command to download a file from the C2 server.

T1105
Ingress Tool Transfer
MalwareCalisto

Calisto has the capability to upload and download files to the victim's machine.

T1105
Ingress Tool Transfer
MalwareSolar

Solar has the ability to download and execute files.

T1105
Ingress Tool Transfer
MalwarePisloader

Pisloader has a command to upload a file to the victim machine.

T1105
Ingress Tool Transfer
MalwareGoldenSpy

GoldenSpy constantly attempts to download and execute files from the remote C2, including GoldenSpy itself if not found on the system.

T1105
Ingress Tool Transfer
MalwareGold Dragon

Gold Dragon can download additional components from the C2 server.

T1105
Ingress Tool Transfer
MalwareRGDoor

RGDoor uploads and downloads files to and from the victim’s machine.

T1105
Ingress Tool Transfer
MalwareNeo-reGeorg

Neo-reGeorg has the ability to download files to targeted systems.

T1105
Ingress Tool Transfer
MalwareAshTag

The AshTag stager component can retrieve and execute the main payload.

T1105
Ingress Tool Transfer
MalwareCarberp

Carberp can download and execute new plugins from the C2 server.

T1105
Ingress Tool Transfer
MalwareRevenge RAT

Revenge RAT has the ability to upload and download files.

T1105
Ingress Tool Transfer
MalwareMacMa

MacMa has downloaded additional files, including an exploit for used privilege escalation.

T1105
Ingress Tool Transfer
MalwareFunnyDream

FunnyDream can download additional files onto a compromised host.

T1105
Ingress Tool Transfer
MalwareMore_eggs

More_eggs can download and launch additional payloads.

T1105
Ingress Tool Transfer
MalwareSysUpdate

SysUpdate has the ability to download files to a compromised host.

T1105
Ingress Tool Transfer
MalwareOutSteel

OutSteel can download files from its C2 server.

T1105
Ingress Tool Transfer
MalwareBackConfig

BackConfig can download and execute additional payloads on a compromised host.

T1105
Ingress Tool Transfer
MalwareKwampirs

Kwampirs downloads additional files from C2 servers.

T1105
Ingress Tool Transfer
MalwareNerex

Nerex creates a backdoor through which remote attackers can download files onto a compromised host.

T1105
Ingress Tool Transfer
MalwareBoomBox

BoomBox has the ability to download next stage malware components to a compromised system.

T1105
Ingress Tool Transfer
MalwareWIREFIRE

WIREFIRE has the ability to download files to compromised devices.

T1105
Ingress Tool Transfer
MalwareKessel

Kessel can download additional modules from the C2 server.

T1105
Ingress Tool Transfer
MalwareGrimAgent

GrimAgent has the ability to download and execute additional payloads.

T1105
Ingress Tool Transfer
MalwareSTEADYPULSE

STEADYPULSE can add lines to a Perl script on a targeted server to import additional Perl modules.

T1105
Ingress Tool Transfer
MalwarePHASEJAM

PHASEJAM has the ability to upload files onto the compromised appliance.

T1105
Ingress Tool Transfer
MalwareYAHOYAH

YAHOYAH uses HTTP GET requests to download other files that are executed in memory.

T1105
Ingress Tool Transfer
MalwareLokibot

Lokibot downloaded several staged items onto the victim's machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.