Real-world descriptions of how a group, tool or campaign used a technique.
403 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1105 Ingress Tool Transfer |
MalwareAstaroth | Astaroth uses certutil and BITSAdmin to download additional malware. |
| T1105 Ingress Tool Transfer |
MalwareQakBot | QakBot has the ability to download additional components and malware. |
| T1105 Ingress Tool Transfer |
MalwareDOWNIISSA | DOWNIISSA can download files to the compromised host. |
| T1105 Ingress Tool Transfer |
MalwareCookieMiner | CookieMiner can download additional scripts from a web server. |
| T1105 Ingress Tool Transfer |
MalwareHancitor | Hancitor has the ability to download additional files from C2. |
| T1105 Ingress Tool Transfer |
MalwareGelsemium | Gelsemium can download additional plug-ins to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwarejRAT | jRAT can download and execute files. |
| T1105 Ingress Tool Transfer |
MalwareHelminth | Helminth can download additional files. |
| T1105 Ingress Tool Transfer |
MalwareBBK | BBK has the ability to download files from C2 to the infected host. |
| T1105 Ingress Tool Transfer |
MalwareOSX/Shlayer | OSX/Shlayer can download payloads, and extract bytes from files. OSX/Shlayer uses the |
| T1105 Ingress Tool Transfer |
MalwareDenis | Denis deploys additional backdoors and hacking tools to the system. |
| T1105 Ingress Tool Transfer |
MalwareWaterbear | Waterbear can receive and load executables from remote C2 servers. |
| T1105 Ingress Tool Transfer |
MalwareVasport | Vasport can download files. |
| T1105 Ingress Tool Transfer |
MalwareJSS Loader | JSS Loader has the ability to download malicious executables to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareLizar | Lizar can download additional plugins, files, and tools. |
| T1105 Ingress Tool Transfer |
MalwareDtrack | Dtrack’s can download and upload a file to the victim’s computer. |
| T1105 Ingress Tool Transfer |
MalwareH1N1 | H1N1 contains a command to download and execute a file from a remotely hosted URL using WinINet HTTP requests. |
| T1105 Ingress Tool Transfer |
MalwareSeth-Locker | Seth-Locker has the ability to download and execute files on a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareLoudMiner | LoudMiner used SCP to update the miner from the C2. |
| T1105 Ingress Tool Transfer |
MalwareAzorult | Azorult can download and execute additional files. Azorult has also downloaded a ransomware payload called Hermes. |
| T1105 Ingress Tool Transfer |
MalwareZox | Zox can download files to a compromised machine. |
| T1105 Ingress Tool Transfer |
MalwareUPPERCUT | UPPERCUT can download and upload files to and from the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareStrifeWater | StrifeWater can download updates and auxiliary modules. |
| T1105 Ingress Tool Transfer |
MalwareMivast | Mivast has the capability to download and execute .exe files. |
| T1105 Ingress Tool Transfer |
MalwareHiddenWasp | HiddenWasp downloads a tar compressed archive from a download server to the system. |
| T1105 Ingress Tool Transfer |
MalwareWarzoneRAT | WarzoneRAT can download and execute additional files. |
| T1105 Ingress Tool Transfer |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has downloaded files onto a victim machine. |
| T1105 Ingress Tool Transfer |
MalwareXORIndex Loader | XORIndex Loader has been used to download a malicious payload to include BeaverTail. |
| T1105 Ingress Tool Transfer |
MalwareSmall Sieve | Small Sieve has the ability to download files. |
| T1105 Ingress Tool Transfer |
ToolRemoteUtilities | RemoteUtilities can upload and download files to and from a target machine. |
| T1105 Ingress Tool Transfer |
Toolcertutil | certutil can be used to download files from a given URL. |
| T1105 Ingress Tool Transfer |
ToolShimRatReporter | ShimRatReporter had the ability to download additional payloads. |
| T1105 Ingress Tool Transfer |
ToolSliver | Sliver can download additional content and files from the Sliver server to the client residing on the victim machine using the |
| T1105 Ingress Tool Transfer |
ToolSILENTTRINITY | SILENTTRINITY can load additional files and tools, including Mimikatz. |
| T1105 Ingress Tool Transfer |
ToolEmpire | Empire can upload and download to and from a victim machine. |
| T1105 Ingress Tool Transfer |
ToolCSPY Downloader | CSPY Downloader can download additional tools to a compromised host. |
| T1105 Ingress Tool Transfer |
ToolCARROTBALL | CARROTBALL has the ability to download and install a remote payload. |
| T1105 Ingress Tool Transfer |
ToolBITSAdmin | BITSAdmin can be used to create BITS Jobs to upload and/or download files. |
| T1105 Ingress Tool Transfer |
ToolAsyncRAT | AsyncRAT has the ability to download files including over SFTP. |
| T1105 Ingress Tool Transfer |
ToolBrute Ratel C4 | Brute Ratel C4 can download files to compromised hosts. |
| T1105 Ingress Tool Transfer |
ToolRemcos | Remcos can upload and download files to and from the victim’s machine. |
| T1105 Ingress Tool Transfer |
ToolMCMD | MCMD can upload additional files to a compromised host. |
| T1105 Ingress Tool Transfer |
ToolDonut | Donut can download and execute previously staged shellcode payloads. |
| T1105 Ingress Tool Transfer |
Toolcmd | cmd can be used to copy files to/from a remotely connected external system. |
| T1105 Ingress Tool Transfer |
Toolesentutl | esentutl can be used to copy files from a given URL. |
| T1105 Ingress Tool Transfer |
ToolKoadic | Koadic can download additional files and tools. |
| T1105 Ingress Tool Transfer |
ToolPupy | Pupy can upload and download to/from a victim machine. |
| T1105 Ingress Tool Transfer |
Toolftp | ftp may be abused by adversaries to transfer tools or files from an external system into a compromised environment. |
| T1105 Ingress Tool Transfer |
ToolQuasarRAT | QuasarRAT can download files to the victim’s machine and execute them. |
| T1105 Ingress Tool Transfer |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to download additional payloads to targeted systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.