ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1105×

403 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
MalwareAstaroth

Astaroth uses certutil and BITSAdmin to download additional malware.

T1105
Ingress Tool Transfer
MalwareQakBot

QakBot has the ability to download additional components and malware.

T1105
Ingress Tool Transfer
MalwareDOWNIISSA

DOWNIISSA can download files to the compromised host.

T1105
Ingress Tool Transfer
MalwareCookieMiner

CookieMiner can download additional scripts from a web server.

T1105
Ingress Tool Transfer
MalwareHancitor

Hancitor has the ability to download additional files from C2.

T1105
Ingress Tool Transfer
MalwareGelsemium

Gelsemium can download additional plug-ins to a compromised host.

T1105
Ingress Tool Transfer
MalwarejRAT

jRAT can download and execute files.

T1105
Ingress Tool Transfer
MalwareHelminth

Helminth can download additional files.

T1105
Ingress Tool Transfer
MalwareBBK

BBK has the ability to download files from C2 to the infected host.

T1105
Ingress Tool Transfer
MalwareOSX/Shlayer

OSX/Shlayer can download payloads, and extract bytes from files. OSX/Shlayer uses the curl -fsL "$url" >$tmp_path command to download malicious payloads into a temporary directory.

T1105
Ingress Tool Transfer
MalwareDenis

Denis deploys additional backdoors and hacking tools to the system.

T1105
Ingress Tool Transfer
MalwareWaterbear

Waterbear can receive and load executables from remote C2 servers.

T1105
Ingress Tool Transfer
MalwareVasport

Vasport can download files.

T1105
Ingress Tool Transfer
MalwareJSS Loader

JSS Loader has the ability to download malicious executables to a compromised host.

T1105
Ingress Tool Transfer
MalwareLizar

Lizar can download additional plugins, files, and tools.

T1105
Ingress Tool Transfer
MalwareDtrack

Dtrack’s can download and upload a file to the victim’s computer.

T1105
Ingress Tool Transfer
MalwareH1N1

H1N1 contains a command to download and execute a file from a remotely hosted URL using WinINet HTTP requests.

T1105
Ingress Tool Transfer
MalwareSeth-Locker

Seth-Locker has the ability to download and execute files on a compromised host.

T1105
Ingress Tool Transfer
MalwareLoudMiner

LoudMiner used SCP to update the miner from the C2.

T1105
Ingress Tool Transfer
MalwareAzorult

Azorult can download and execute additional files. Azorult has also downloaded a ransomware payload called Hermes.

T1105
Ingress Tool Transfer
MalwareZox

Zox can download files to a compromised machine.

T1105
Ingress Tool Transfer
MalwareUPPERCUT

UPPERCUT can download and upload files to and from the victim’s machine.

T1105
Ingress Tool Transfer
MalwareStrifeWater

StrifeWater can download updates and auxiliary modules.

T1105
Ingress Tool Transfer
MalwareMivast

Mivast has the capability to download and execute .exe files.

T1105
Ingress Tool Transfer
MalwareHiddenWasp

HiddenWasp downloads a tar compressed archive from a download server to the system.

T1105
Ingress Tool Transfer
MalwareWarzoneRAT

WarzoneRAT can download and execute additional files.

T1105
Ingress Tool Transfer
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has downloaded files onto a victim machine.

T1105
Ingress Tool Transfer
MalwareXORIndex Loader

XORIndex Loader has been used to download a malicious payload to include BeaverTail.

T1105
Ingress Tool Transfer
MalwareSmall Sieve

Small Sieve has the ability to download files.

T1105
Ingress Tool Transfer
ToolRemoteUtilities

RemoteUtilities can upload and download files to and from a target machine.

T1105
Ingress Tool Transfer
Toolcertutil

certutil can be used to download files from a given URL.

T1105
Ingress Tool Transfer
ToolShimRatReporter

ShimRatReporter had the ability to download additional payloads.

T1105
Ingress Tool Transfer
ToolSliver

Sliver can download additional content and files from the Sliver server to the client residing on the victim machine using the upload command.

T1105
Ingress Tool Transfer
ToolSILENTTRINITY

SILENTTRINITY can load additional files and tools, including Mimikatz.

T1105
Ingress Tool Transfer
ToolEmpire

Empire can upload and download to and from a victim machine.

T1105
Ingress Tool Transfer
ToolCSPY Downloader

CSPY Downloader can download additional tools to a compromised host.

T1105
Ingress Tool Transfer
ToolCARROTBALL

CARROTBALL has the ability to download and install a remote payload.

T1105
Ingress Tool Transfer
ToolBITSAdmin

BITSAdmin can be used to create BITS Jobs to upload and/or download files.

T1105
Ingress Tool Transfer
ToolAsyncRAT

AsyncRAT has the ability to download files including over SFTP.

T1105
Ingress Tool Transfer
ToolBrute Ratel C4

Brute Ratel C4 can download files to compromised hosts.

T1105
Ingress Tool Transfer
ToolRemcos

Remcos can upload and download files to and from the victim’s machine.

T1105
Ingress Tool Transfer
ToolMCMD

MCMD can upload additional files to a compromised host.

T1105
Ingress Tool Transfer
ToolDonut

Donut can download and execute previously staged shellcode payloads.

T1105
Ingress Tool Transfer
Toolcmd

cmd can be used to copy files to/from a remotely connected external system.

T1105
Ingress Tool Transfer
Toolesentutl

esentutl can be used to copy files from a given URL.

T1105
Ingress Tool Transfer
ToolKoadic

Koadic can download additional files and tools.

T1105
Ingress Tool Transfer
ToolPupy

Pupy can upload and download to/from a victim machine.

T1105
Ingress Tool Transfer
Toolftp

ftp may be abused by adversaries to transfer tools or files from an external system into a compromised environment.

T1105
Ingress Tool Transfer
ToolQuasarRAT

QuasarRAT can download files to the victim’s machine and execute them.

T1105
Ingress Tool Transfer
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has the ability to download additional payloads to targeted systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.