ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1105×

403 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
MalwareTrickBot

TrickBot downloads several additional files and saves them to the victim's machine.

T1105
Ingress Tool Transfer
MalwarePowerDuke

PowerDuke has a command to download a file.

T1105
Ingress Tool Transfer
MalwareBLINDINGCAN

BLINDINGCAN has downloaded files to a victim machine.

T1105
Ingress Tool Transfer
MalwareWiarp

Wiarp creates a backdoor through which remote attackers can download files.

T1105
Ingress Tool Transfer
MalwareRCSession

RCSession has the ability to drop additional files to an infected machine.

T1105
Ingress Tool Transfer
MalwareQuietSieve

QuietSieve can download and execute payloads on a target host.

T1105
Ingress Tool Transfer
MalwareBumblebee

Bumblebee can download and execute additional payloads including through the use of a `Dex` command.

T1105
Ingress Tool Transfer
MalwareBRICKSTORM

BRICKSTORM has the ability to download files from the Adversaries C2 server to the compromised system.

T1105
Ingress Tool Transfer
MalwareAmadey

Amadey can download and execute files to further infect a host machine with additional malware.

T1105
Ingress Tool Transfer
MalwareNICECURL

NICECURL has the ability to download additional content onto an infected machine, e.g. by using `curl`.

T1105
Ingress Tool Transfer
MalwareOrz

Orz can download files onto the victim.

T1105
Ingress Tool Transfer
MalwareNOKKI

NOKKI has downloaded a remote module for execution.

T1105
Ingress Tool Transfer
MalwareBackdoor.Oldrea

Backdoor.Oldrea can download additional modules from C2.

T1105
Ingress Tool Transfer
MalwareDOGCALL

DOGCALL can download and execute additional payloads.

T1105
Ingress Tool Transfer
MalwareDowndelph

After downloading its main config file, Downdelph downloads multiple payloads from C2 servers.

T1105
Ingress Tool Transfer
MalwareSEASHARPEE

SEASHARPEE can download remote files onto victims.

T1105
Ingress Tool Transfer
MalwarePOWRUNER

POWRUNER can download or upload files from its C2 server.

T1105
Ingress Tool Transfer
MalwareTDTESS

TDTESS has a command to download and execute an additional file.

T1105
Ingress Tool Transfer
MalwareSharpStage

SharpStage has the ability to download and execute additional payloads via a DropBox API.

T1105
Ingress Tool Transfer
MalwareSardonic

Sardonic has the ability to upload additional malicious files to a compromised machine.

T1105
Ingress Tool Transfer
MalwareSmoke Loader

Smoke Loader downloads a new version of itself once it has installed. It also downloads additional plugins.

T1105
Ingress Tool Transfer
MalwareMisdat

Misdat is capable of downloading files from the C2.

T1105
Ingress Tool Transfer
MalwarereGeorg

reGeorg has the ability to download files to targeted systems.

T1105
Ingress Tool Transfer
MalwareEmissary

Emissary has the capability to download files from the C2 server.

T1105
Ingress Tool Transfer
MalwareExaramel for Linux

Exaramel for Linux has a command to download a file from and to a remote C2 server.

T1105
Ingress Tool Transfer
MalwareKEYMARBLE

KEYMARBLE can upload files to the victim’s machine and can download additional payloads.

T1105
Ingress Tool Transfer
MalwareTAMECAT

TAMECAT has used `wget` and `curl` to download additional content.

T1105
Ingress Tool Transfer
MalwarePS1

CostaBricks can download additional payloads onto a compromised host.

T1105
Ingress Tool Transfer
MalwareUrsnif

Ursnif has dropped payload and configuration files to disk. Ursnif has also been used to download and execute additional payloads.

T1105
Ingress Tool Transfer
MalwareCASTLETAP

CASTLETAP can transfer files to compromised network devices.

T1105
Ingress Tool Transfer
MalwareThreatNeedle

ThreatNeedle can download additional tools to enable lateral movement.

T1105
Ingress Tool Transfer
MalwareZLib

ZLib has the ability to download files.

T1105
Ingress Tool Transfer
MalwareRedLeaves

RedLeaves is capable of downloading a file from a specified URL.

T1105
Ingress Tool Transfer
MalwarePOWERSOURCE

POWERSOURCE has been observed being used to download TEXTMATE and the Cobalt Strike Beacon payload onto victims.

T1105
Ingress Tool Transfer
MalwareTsundere Botnet

Tsundere Botnet’s loader component has downloaded the zip file node-v18.17.0-win-x64.zip from the official Node.js website, as well as pm2, a Node.js process management tool.

T1105
Ingress Tool Transfer
MalwareFelismus

Felismus can download files from remote servers.

T1105
Ingress Tool Transfer
MalwareZeus Panda

Zeus Panda can download additional malware plug-in modules and execute them on the victim’s machine.

T1105
Ingress Tool Transfer
MalwareHavoc

Havoc has the ability to upload files to infected systems.

T1105
Ingress Tool Transfer
MalwareCARROTBAT

CARROTBAT has the ability to download and execute a remote file via certutil.

T1105
Ingress Tool Transfer
MalwareWEBC2

WEBC2 can download and execute a file.

T1105
Ingress Tool Transfer
MalwareInvisibleFerret

InvisibleFerret has downloaded “AnyDesk.exe” into the user’s home directory from the C2 server when checks for the service fail to identify its presence in the victim environment. InvisibleFerret has also been configured to download additional payloads using a command which calls to the /bow URI.

T1105
Ingress Tool Transfer
MalwareBankshot

Bankshot uploads files and secondary payloads to the victim's machine.

T1105
Ingress Tool Transfer
MalwareSharpDisco

SharpDisco has been used to download a Python interpreter to `C:\Users\Public\WinTN\WinTN.exe` as well as other plugins from external sources.

T1105
Ingress Tool Transfer
MalwareStrongPity

StrongPity can download files to specified targets.

T1105
Ingress Tool Transfer
MalwareHAPPYWORK

can download and execute a second-stage payload.

T1105
Ingress Tool Transfer
MalwarexCaon

xCaon has a command to download files to the victim's machine.

T1105
Ingress Tool Transfer
MalwarePLAINTEE

PLAINTEE has downloaded and executed additional plugins.

T1105
Ingress Tool Transfer
MalwarePony

Pony can download additional files onto the infected system.

T1105
Ingress Tool Transfer
MalwareNebulae

Nebulae can download files from C2.

T1105
Ingress Tool Transfer
MalwareAuditCred

AuditCred can download files and additional malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.