Ingress Tool Transfer

T1105

Technique.View on attack.mitre.org

About this technique

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

On Windows, adversaries may use various utilities to download tools, such as `copy`, `finger`, certutil, and PowerShell commands such as IEX(New-Object Net.WebClient).downloadString() and Invoke-WebRequest. On Linux and macOS systems, a variety of utilities also exist, such as `curl`, `scp`, `sftp`, `tftp`, `rsync`, `finger`, and `wget`. A number of these tools, such as `wget`, `curl`, and `scp`, also exist on ESXi. After downloading a file, a threat actor may attempt to verify its integrity by checking its hash value (e.g., via `certutil -hashfile`).

Adversaries may also abuse installers and package managers, such as `yum` or `winget`, to download tools to victim hosts. Adversaries have also abused file application features, such as the Windows `search-ms` protocol handler, to deliver malicious files to victims through remote file searches invoked by User Execution (typically after interacting with Phishing lures).

Files can also be transferred using various Web Services as well as native or otherwise present tools on the victim system. In some cases, adversaries may be able to leverage services that sync between a web-based and an on-premises client, such as Dropbox or OneDrive, to transfer files onto victim systems. For example, by compromising a cloud account and logging into the service's web portal, an adversary may be able to trigger an automatic syncing process that transfers the file onto the victim's machine.

Detection rules125

Rules on DetectionCode tagged with T1105.

Sigma73

RuleLevelLog source
Pandemic Registry Keycriticalwindows / registry_event
Curl Download And Execute Combinationhighwindows / process_creation
File Download And Execution Via IEExec.EXEhighwindows / process_creation
File Download From IP Based URL Via CertOC.EXEhighwindows / process_creation
File Download Using Notepad++ GUP Utilityhighwindows / process_creation
File Download Via Bitsadmin To A Suspicious Target Folderhighwindows / process_creation
File Download Via Windows Defender MpCmpRun.EXEhighwindows / process_creation
File Download with Headless Browserhighwindows / process_creation
File With Suspicious Extension Downloaded Via Bitsadminhighwindows / process_creation
Finger.EXE Executionhighwindows / process_creation
Legitimate Application Writing Files In Uncommon Locationhighwindows / file_event
Lolbas OneDriveStandaloneUpdater.exe Proxy Downloadhighwindows / registry_set
Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folderhighwindows / network_connection
Network Connection Initiated By IMEWDBLD.EXEhighwindows / network_connection
Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Locationhighwindows / network_connection

Splunk52

RuleTypeRiskData source
Any Powershell DownloadFileTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Any Powershell DownloadStringTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
BITSAdmin Download FileTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
CertUtil Download With URLCache and Split ArgumentsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
CertUtil Download With VerifyCtl and Split ArgumentsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Cisco Isovalent - Curl Execution With Insecure FlagsAnomalyNULLCisco Isovalent Process Exec
Cisco NVM - Suspicious File Download via Headless BrowserTTPNULLCisco Network Visibility Module Flow Data
Cisco NVM - Webserver Download From File Sharing WebsiteTTPNULLCisco Network Visibility Module Flow Data
Cisco Secure Firewall - Communication Over Suspicious PortsAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Cisco Secure Firewall - Connection to File Sharing DomainAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Cisco Secure Firewall - File Download Over Uncommon PortAnomalyNULLCisco Secure Firewall Threat Defense File Event
Cisco Secure Firewall - High EVE Threat ConfidenceAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Cisco Secure Firewall - Malware File DownloadedAnomalyNULLCisco Secure Firewall Threat Defense File Event
Cisco Secure Firewall - Repeated Malware DownloadsAnomalyNULLCisco Secure Firewall Threat Defense File Event
Cisco Secure Firewall - Snort Rule Triggered Across Multiple HostsAnomalyNULLCisco Secure Firewall Threat Defense Intrusion Event

Groups88

Show 64 more

Software403

Show 379 more
BazarBBKBeaverTailBendyBearBISCUITBisonalBITSAdminBlackMouldBLINDINGCANBLUELIGHTBonadanBONDUPDATERBoomBoxBoxCaonBribaBRICKSTORMBrute Ratel C4build_downerBumblebeeBundloreBUSHWALKCalistoCallMeCaminhoCanisterWormCannonCarberpCardinal RATCARROTBALLCARROTBATCASTLETAPCaterpillar WebShellcertutilChaesCharmPowerChChesCHIMNEYSWEEPChina ChopperCHOPSTICKChrommmeCloudDukecmdCobalt StrikeCoinTickerConfickerCookieMinerCORESHELLCostaBricksCreepyDriveCrimsonCryptoisticCSPY DownloaderCubaCyclops BlinkDaclsDanBotDarkCometDarkGateDarkTortillaDaserfDDKONGDEATHRANSOMDenisDiavolDipsindDiscoDnsSystemDOGCALLDokiDonutdown_newDowndelphDOWNIISSADRATzarusDropBookDrovorubDtrackDUSTTRAPDyreEcipekacEgregorEliseEmissaryEmotetEmpireesentutlEvilBunnyEVILNUMExaramel for LinuxExplosiveFelismusFELIXROOTFlagproFlawedAmmyyFoggyWebftpFunnyDreamFYAntiGazerGelsemiumgh0st RATGlassWormGold DragonGoldenSpyGoldMaxGootloaderGrandoreiroGreyEnergyGrimAgentGuLoaderH1N1HancitorHannotogHAPPYWORKHavocHelminthHexEval LoaderHi-ZorHiddenFaceHiddenWaspHikitHildegardHOPLIGHTHotCroissantHTTPBrowserHTTPTroyHydraqHyperBroIcedIDIMAPLoaderIndustroyerInvisibleFerretInvisiMoleIxesheJavaliJHUHUGITJPINjRATJSS LoaderKARAEKasidetKazuarKerrdownKesselKevinKeyBoyKEYMARBLEKGH_SPYKinsingKivarsKoadicKOCTOPUSKONNIKwampirsLatrodectusLightNeuronLightSpyLinfoLiteDukeLitePowerLizarLODEINFOLokibotLoudMinerLOWBALLLuciferMacheteMacMamacOS.OSAMinerMafaldaMagicRATMarkiRATMCMDMechaFlounderMelcozmetaMainMetamorfoMeteorMicropsiaMilanMini Shai-HuludMiniDukeMis-TypeMisdatMivastMobileOrderMoleNetMongallMore_eggsMosquitoMuddyViperNanHaiShuNanoCoreNavRATNDiskMonitorNebulaeNeo-reGeorgNeoichorNerexNetwalkerNETWIRENICECURLNidiranNightClubnjRATNOKKIOctopusODAgentOilBoosterOilCheckOkrumOopsIEOrzOSX_OCEANLOTUS.DOSX/ShlayerOutSteelP.A.S. WebshellP8RATPandoraPasamPenquinPeppyPHASEJAMPHPsertPipeMonPisloaderPLAINTEEPLEADPlugXPoetRATPoisonIvyPolyglotDukePonyPOSHSPYPowerDukePowerExchangePowerLessPowerPunchPOWERSOURCEPOWERSTATSPOWRUNERPS1PsyloPteranodonPUBLOADPUNCHBUGGYPupyPureCrypterQakBotQuasarRATQuietSieveRaccoon StealerRainyDayRARSTONERaspberry RobinRATANKBARCSessionRDATRedLeavesRedLine StealerRegDukereGeorgRemcosRemoteCMDRemoteUtilitiesRemsecRevenge RATREvilRGDoorRIFLESPINERogueRobinROKRATRTMS-TypeSaint BotSakulaSampleCheck5000SamuraiSardonicSDBbotSeaDukeSeasaltSEASHARPEEServHelperSeth-LockerShadowPadShai-HuludShamoonSharkSharpDiscoSharpStageSHARPSTATSShimRatShimRatReporterSHUTTERSPEEDSibotSideTwistSILENTTRINITYSkidmapSLIGHTPULSESliverSLOTHFULMEDIASLOWDRIFTSmall SieveSmoke LoaderSMOKEDHAMSnip3SocGholishSodaMasterSolarSombRATSoreFangSpeakUpSpicaSpicyOmeletteSQLRatSquirrelwaffleSTEADYPULSEStoneDrillStrelaStealerStrifeWaterStrongPitySUNBURSTSVCReadySystemBCSysUpdateTaidoorTAINTEDSCRIBETAMECATTDTESSTeamPCP Cloud StealerThiefQuestThreatNeedleTinyTurlaTomirisTONESHELLTrickBotTrojan.KaraganyTSCookieTsundere BotnetTurianTURNEDUPTYPEFRAMEUBoatRATUnknown LoggerUPPERCUTUroburosUrsnifValakVaporRageVasportVBShowerVERMINVIRTUALPITAVolgmerWarzoneRATWaterbearWEBC2WellMailWellMessWhisperGateWiarpWinnti for LinuxWinnti for WindowsWIREFIREWoody RATXbashxCaonXCSSETXORIndex LoaderYAHOYAHZebrocyZeroTZeus PandaZIPLINEZLibZoxZxShellZxxZ

Campaigns29

Show 5 more

Procedure examples520

Groups88

Used byProcedure example
GroupAjax Security Team

Ajax Security Team has used Wrapper/Gholee, custom-developed malware, which downloaded additional malware to the infected system.

GroupAndariel

Andariel has downloaded additional tools and malware onto compromised hosts.

GroupAPT-C-36

APT-C-36 has downloaded binary data from a specified domain after the malicious document is opened.

GroupAPT18

APT18 can upload a file to the victim’s machine.

GroupAPT28

APT28 has downloaded additional files, including by using a first-stage downloader to contact the C2 server to obtain the second-stage implant.

GroupAPT29

APT29 has downloaded additional tools and malware onto compromised networks.

GroupAPT3

APT3 has a tool that can copy files to remote machines.

GroupAPT32

APT32 has added JavaScript to victim websites to download additional frameworks that profile and compromise website visitors.

View all 88 groups examples

Software403

Used byProcedure example
MalwareABK

ABK has the ability to download files from C2.

MalwareAction RAT

Action RAT has the ability to download additional payloads onto an infected machine.

MalwareAgent Tesla

Agent Tesla can download additional files for execution on the victim’s machine.

MalwareAgent.btz

Agent.btz attempts to download an encrypted binary from a specified domain.

MalwareAmadey

Amadey can download and execute files to further infect a host machine with additional malware.

MalwareAnchor

Anchor can download additional payloads.

MalwareANDROMEDA

ANDROMEDA can download additional payloads from C2.

MalwareAria-body

Aria-body has the ability to download additional payloads from C2.

View all 403 software examples

Campaigns29

Used byProcedure example
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team pushed additional malicious tools onto an infected system to steal user credentials, move laterally, and destroy data.

Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries downloaded malicious payloads to the victim server.

CampaignAPT41 DUST

APT41 DUST involved execution of `certutil.exe` via web shell to download the DUSTPAN dropper.

CampaignC0010

During C0010, UNC3890 actors downloaded tools and malware onto a compromised host.

CampaignC0015

During C0015, the threat actors downloaded additional tools and files onto a compromised network.

CampaignC0017

During C0017, APT41 downloaded malicious payloads onto compromised systems.

CampaignC0018

During C0018, the threat actors downloaded additional tools, such as Mimikatz and Sliver, as well as Cobalt Strike and AvosLocker ransomware onto the victim network.

CampaignC0021

During C0021, the threat actors downloaded additional tools and files onto victim machines.

View all 29 campaigns examples

References5

  1. Dropbox Malware Sync Open source
    David Talbot. (2013, August 21). Dropbox and Similar Services Can Sync Malware. Retrieved May 31, 2023.
  2. Google Cloud Threat Intelligence COSCMICENERGY 2023 Open source
    COSMICENERGY: New OT Malware Possibly Related To Russian Emergency Response Exercises. (2023, May 25). Ken Proska, Daniel Kapellmann Zafra, Keith Lunden, Corey Hildebrandt, Rushikesh Nandedkar, Nathan Brubaker. Retrieved March 18, 2025.
  3. PTSecurity Cobalt Dec 2016 Open source
    Positive Technologies. (2016, December 16). Cobalt Snatch. Retrieved October 9, 2018.
  4. T1105: Trellix_search-ms Open source
    Mathanraj Thangaraju, Sijo Jacob. (2023, July 26). Beyond File Search: A Novel Method for Exploiting the "search-ms" URI Protocol Handler. Retrieved March 15, 2024.
  5. t1105_lolbas Open source
    LOLBAS. (n.d.). LOLBAS Mapped to T1105. Retrieved March 11, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.