ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1105×

403 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
MalwareCallMe

CallMe has the capability to download a file to the victim from the C2 server.

T1105
Ingress Tool Transfer
MalwareCloudDuke

CloudDuke downloads and executes additional malware from either a Web address or a Microsoft OneDrive account.

T1105
Ingress Tool Transfer
MalwareEgregor

Egregor has the ability to download files from its C2 server.

T1105
Ingress Tool Transfer
MalwarePoetRAT

PoetRAT has the ability to copy files and download/upload files into C2 channels using FTP and HTTPS.

T1105
Ingress Tool Transfer
MalwareCHOPSTICK

CHOPSTICK is capable of performing remote file transmission.

T1105
Ingress Tool Transfer
MalwareFELIXROOT

FELIXROOT downloads and uploads files to and from the victim’s machine.

T1105
Ingress Tool Transfer
MalwareZxShell

ZxShell has a command to transfer files from a remote host.

T1105
Ingress Tool Transfer
MalwareRIFLESPINE

RIFLESPINE can download and execute files.

T1105
Ingress Tool Transfer
MalwareSLIGHTPULSE

RAPIDPULSE can transfer files to and from compromised hosts.

T1105
Ingress Tool Transfer
MalwareNDiskMonitor

NDiskMonitor can download and execute a file from given URL.

T1105
Ingress Tool Transfer
MalwareCoinTicker

CoinTicker executes a Python script to download its second stage.

T1105
Ingress Tool Transfer
MalwareDDKONG

DDKONG downloads and uploads files on the victim’s machine.

T1105
Ingress Tool Transfer
MalwarePenquin

Penquin can execute the command code do_download to retrieve remote files from C2.

T1105
Ingress Tool Transfer
MalwareBabyShark

BabyShark has downloaded additional files from the C2.

T1105
Ingress Tool Transfer
MalwareCannon

Cannon can download a payload for execution.

T1105
Ingress Tool Transfer
Malwarebuild_downer

build_downer has the ability to download files from C2 to the infected host.

T1105
Ingress Tool Transfer
MalwareMelcoz

Melcoz has the ability to download additional files to a compromised host.

T1105
Ingress Tool Transfer
MalwareWinnti for Windows

The Winnti for Windows dropper can place malicious payloads on targeted systems.

T1105
Ingress Tool Transfer
MalwarePowerPunch

PowerPunch can download payloads from adversary infrastructure.

T1105
Ingress Tool Transfer
MalwareBONDUPDATER

BONDUPDATER can download or upload files from its C2 server.

T1105
Ingress Tool Transfer
MalwareKinsing

Kinsing has downloaded additional lateral movement scripts from C2.

T1105
Ingress Tool Transfer
MalwareMeteor

Meteor has the ability to download additional files for execution on the victim's machine.

T1105
Ingress Tool Transfer
MalwarenjRAT

njRAT can download files to the victim’s machine. APT-C-36 has used modified versions of njRAT to enable the download of .NET assemblies.

T1105
Ingress Tool Transfer
MalwareZIPLINE

ZIPLINE can download files to be saved on the compromised system.

T1105
Ingress Tool Transfer
MalwareTURNEDUP

TURNEDUP is capable of downloading additional files.

T1105
Ingress Tool Transfer
MalwareChChes

ChChes is capable of downloading files, including additional modules.

T1105
Ingress Tool Transfer
MalwareANDROMEDA

ANDROMEDA can download additional payloads from C2.

T1105
Ingress Tool Transfer
MalwareShai-Hulud

Shai-Hulud has downloaded packages from code repositories. Shai-Hulud has also downloaded and executed the secrets-discovery tool TruffleHog to gather sensitive data.

T1105
Ingress Tool Transfer
MalwareJPIN

JPIN can download files and upgrade itself.

T1105
Ingress Tool Transfer
MalwareVIRTUALPITA

VIRTUALPITA has the ability to upload and download files.

T1105
Ingress Tool Transfer
MalwaremetaMain

metaMain can download files onto compromised systems.

T1105
Ingress Tool Transfer
MalwareSideTwist

SideTwist has the ability to download additional files.

T1105
Ingress Tool Transfer
MalwareKOCTOPUS

KOCTOPUS has executed a PowerShell command to download a file to the system.

T1105
Ingress Tool Transfer
MalwareMechaFlounder

MechaFlounder has the ability to upload and download files to and from a compromised host.

T1105
Ingress Tool Transfer
MalwarePsylo

Psylo has a command to download a file to the system from its C2 server.

T1105
Ingress Tool Transfer
MalwareHTTPBrowser

HTTPBrowser is capable of writing a file to the compromised system from the C2 server.

T1105
Ingress Tool Transfer
MalwareMis-Type

Mis-Type has downloaded additional malware and files onto a compromised host.

T1105
Ingress Tool Transfer
MalwareXCSSET

XCSSET downloads browser specific AppleScript modules using a constructed URL with the curl command, https://" & domain & "/agent/scripts/" & moduleName & ".applescript.

T1105
Ingress Tool Transfer
MalwareDisco

Disco can download files to targeted systems via SMB.

T1105
Ingress Tool Transfer
MalwareDipsind

Dipsind can download remote files.

T1105
Ingress Tool Transfer
MalwareOctopus

Octopus can download additional files and tools onto the victim’s machine.

T1105
Ingress Tool Transfer
MalwareSoreFang

SoreFang can download additional payloads from C2.

T1105
Ingress Tool Transfer
MalwareIndustroyer

Industroyer downloads a shellcode payload from a remote C2 server and loads it into memory.

T1105
Ingress Tool Transfer
MalwareKevin

Kevin can download files to the compromised host.

T1105
Ingress Tool Transfer
MalwareAgent Tesla

Agent Tesla can download additional files for execution on the victim’s machine.

T1105
Ingress Tool Transfer
MalwarePasam

Pasam creates a backdoor through which remote attackers can upload files.

T1105
Ingress Tool Transfer
MalwarePOWERSTATS

POWERSTATS can retrieve and execute additional PowerShell payloads from the C2 server.

T1105
Ingress Tool Transfer
MalwareBADNEWS

BADNEWS is capable of downloading additional files through C2 channels, including a new version of itself.

T1105
Ingress Tool Transfer
MalwareLinfo

Linfo creates a backdoor through which remote attackers can download files onto compromised hosts.

T1105
Ingress Tool Transfer
MalwareShadowPad

ShadowPad has downloaded code from a C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.