Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Command and Control/ T1105

T1105Ingress Tool Transfer

T1105 — Ingress Tool Transfer is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 214 detection use cases covering it and 117 threat-intel articles citing it.

Command and Control
View on the matrix → Filter Detection Library MITRE official spec ↗
214Use cases
117Articles
0Sub-techniques
1Tactic

Use cases covering this technique (214)

[WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Internal delivery · alerting DSPDD [WEEKLY] Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Internal delivery · alerting DSΣP [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) Internal exploit · alerting DSPDDCS [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes Internal install · alerting DSPDD [WEEKLY] Install-Time npm/Bun Lifecycle Execution Beaconing Out Within Minutes Internal install · alerting DSΣPDDCS [WEEKLY] Internet-facing server process spawns interpreter then beacons to first-seen external host within 5 minutes Internal install · alerting DSPDD [WEEKLY] Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internal install · alerting DSΣPDD [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Internal exploit · alerting DSΣPDD [WEEKLY] npm/node-gyp Install-Hook Spawn Chained to Outbound Egress Internal install · alerting DSΣPDDCS [WEEKLY] Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime Internal install · alerting DSΣPDD [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install Internal install · alerting DSPDD [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Internal exploit · alerting DSΣPDD [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host Internal exploit · alerting DSPDD Microsoft Intune Device Health Scripts ESCU actions · hunting P Microsoft Intune Mobile Apps ESCU actions · hunting P BITSAdmin Download File ESCU actions · alerting P Cisco Isovalent - Curl Execution With Insecure Flags ESCU actions · hunting P Cisco NVM - Suspicious File Download via Headless Browser ESCU actions · alerting P Cisco NVM - Webserver Download From File Sharing Website ESCU actions · alerting P Curl Execution with Percent Encoded URL ESCU actions · hunting P Detect Certify Command Line Arguments ESCU actions · alerting P Download Files Using Telegram ESCU actions · alerting P File Download or Read to Pipe Execution ESCU actions · alerting P Linux Curl Upload File ESCU actions · alerting P Linux Ingress Tool Transfer Hunting ESCU actions · hunting P Linux Ingress Tool Transfer with Curl ESCU actions · hunting P Living Off The Land Detection ESCU actions · alerting P Log4Shell CVE-2021-44228 Exploitation ESCU actions · alerting P LOLBAS With Network Traffic ESCU actions · alerting P PowerShell Script Block With URL Chain ESCU actions · alerting P PowerShell WebRequest Using Memory Stream ESCU actions · alerting P Suspicious Curl Network Connection ESCU actions · alerting P Windows Cabinet File Extraction Via Expand ESCU actions · alerting P Windows Curl Download to Suspicious Path ESCU actions · alerting P Windows Curl Upload to Remote Destination ESCU actions · alerting P Windows DLL Module Loaded in Temp Dir ESCU actions · hunting P Windows DNS Query Request To TinyUrl ESCU actions · hunting P Windows File Download Via CertUtil ESCU actions · alerting P Windows File Download Via PowerShell ESCU actions · hunting P Windows Ingress Tool Transfer Using Explorer ESCU actions · hunting P Windows Ldifde Directory Object Behavior ESCU actions · alerting P Windows Process Execution From RDP Share ESCU actions · hunting P Windows SQL Spawning CertUtil ESCU actions · alerting P Windows SSH Proxy Command ESCU actions · hunting P Windows Suspicious Defender Update Activity in INetCache ESCU actions · hunting P WinRAR Spawning Shell Application ESCU actions · alerting P Cisco Secure Firewall - Communication Over Suspicious Ports ESCU actions · hunting P Cisco Secure Firewall - Connection to File Sharing Domain ESCU actions · hunting P Cisco Secure Firewall - File Download Over Uncommon Port ESCU actions · hunting P Cisco Secure Firewall - High EVE Threat Confidence ESCU actions · hunting P Cisco Secure Firewall - Malware File Downloaded ESCU actions · hunting P Cisco Secure Firewall - Repeated Malware Downloads ESCU actions · hunting P Cisco Secure Firewall - Snort Rule Triggered Across Multiple Hosts ESCU actions · hunting P Cisco Secure Firewall - Wget or Curl Download ESCU actions · hunting P Juniper Networks Remote Code Execution Exploit Detection ESCU actions · alerting P Any Powershell DownloadFile ESCU actions · alerting P Any Powershell DownloadString ESCU actions · alerting P CertUtil Download With URLCache and Split Arguments ESCU actions · alerting P CertUtil Download With VerifyCtl and Split Arguments ESCU actions · alerting P Curl Download and Bash Execution ESCU actions · alerting P Wget Download and Bash Execution ESCU actions · alerting P Windows CertUtil Download With URL Argument ESCU actions · alerting P [LLM] Backdoor payload written to /app by shell/downloader after Ruflo RCE Bespoke install · hunting DSΣPDDCS [LLM] File read/write/delete/rename performed by a goshs process (SFTP data access) Bespoke actions · hunting DSPDDCS [LLM] Tengu botnet C2 / IPFS beacon to 64.89.163.8 on TCP 9931 and 8080 Bespoke c2 · hunting DSΣPDDCS [LLM] Payload or JSP web shell written by the TeamCity server process — CVE-2026-63077 Bespoke install · hunting DSΣPDDCS [LLM] curl/wget/nc spawned by n8n/Node reaching external hosts (post-escape C2/exfil) Bespoke c2 · hunting DSPDDCS [LLM] Cruciferra loader side-load DLLs and Remcos logs.dat drop Bespoke install · alerting DSΣPDDCS [LLM] Browser-assembled SourTrade executable dropped with campaign-domain origin (MotW) Bespoke install · hunting DSPDDCS [LLM] SourTrade ServiceWorker build-instruction fetch (/config + /sw.js on campaign domains) Bespoke delivery · hunting DSΣP [LLM] Java (fat-JAR) outbound fetch of remote JAR / SSRF egress to public IP (CVE-2026 Bespoke c2 · hunting DSPDDCS [LLM] BlueNoroff typosquatted Zoom/Teams infrastructure network contact Bespoke delivery · alerting DSΣPDDCS [LLM] Callback to Hermes operator staging/C2 infrastructure (VShell / ShadowPad / Hades) Bespoke c2 · hunting DSΣPDDCS [LLM] TAG-195 ClickFix OCX payload executed via regsvr32 (TinyEgg install) Bespoke install · alerting DSΣPDDCS [LLM] msaRAT: curl.exe downloading MSI payload into ProgramData Bespoke delivery · alerting DSΣPDDCS [LLM] Financial_report.bat dropper downloaded from ClickUp attachment host Bespoke delivery · alerting DSΣPDDCS [LLM] Hidden PowerShell pulls installer.exe from pixeldrain.com to %Temp% (self-deleting dropper) Bespoke install · alerting DSΣPDDCS [LLM] Network/DNS contact to Q2 2026 campaign infrastructure (pixeldrain payload + ClickUp dropper hosts) Bespoke c2 · alerting DSΣPDDCS [LLM] msaRAT delivery: curl.exe fetching fake Windows-update MSI to ProgramData over HTTP Bespoke delivery · alerting DSΣPDDCS [LLM] Unsanctioned RMM trio deployment: Endpoint Central, Mesh Agent, Tactical RMM Bespoke c2 · hunting DSPDDCS [LLM] SleeperGem: ruby process C2 contact to Forgejo host git.disroot.org Bespoke c2 · alerting DSΣPCS [LLM] SleeperGem payload drop: native binary written to hidden ~/.local/share/gcm/ Bespoke install · alerting DSΣPDDCS [LLM] Ruby/gem process downloading payload from git.disroot.org (SleeperGem) Bespoke delivery · alerting DSΣPDDCS [LLM] New PHP file written into WordPress web root by a web daemon — wp2shell web shell drop Bespoke install · hunting DSΣPDDCS [LLM] rundll32 loading DLL from remote WebDAV @ssl GUID share with ordinal export (ACR Stealer) Bespoke install · alerting DSΣPDDCS [LLM] Endpoint traffic to ACR Stealer C2 / dead-drop domains Bespoke c2 · alerting DSΣPDDCS [LLM] In-memory WLDR PowerShell C2 implant (fileless, no -File, unusual parent) Bespoke c2 · hunting DSPDDCS [LLM] Connection to known UAT-11795 Starland RAT C2 / distribution domains Bespoke c2 · alerting DSΣPDDCS [LLM] HelloProxy C2-handler artifact: tesh4RPC.txt written to C:\Users\Public Bespoke c2 · alerting DSΣPDDCS [LLM] Second-stage sync.js dropped under OS 'NodeJS' masquerade directory Bespoke install · alerting DSΣPDDCS [LLM] Node.js retrieving Miasma second stage from IPFS gateway (specific CIDs) Bespoke delivery · alerting DSΣPDDCS [LLM] CI runner egress to MiniRAT C2 89.36.224.5 (Velora SDK backdoor) Bespoke c2 · hunting DSΣPDDCS [LLM] npm/node lifecycle script fetching Bun runtime from github.com/oven-sh/bun Bespoke install · alerting DSΣPDDCS [LLM] TuxBot/Akiru known ELF sample execution and drop (SHA256 pivot) Bespoke install · hunting DSΣPCS [LLM] Miasma/AsyncAPI first-stage: node spawns detached 'node -e' downloader referencing IPFS/sync.js Bespoke delivery · alerting DSΣPDDCS [LLM] Miasma stage-2 dropped: sync.js written to per-user NodeJS data directory Bespoke install · alerting DSΣPDDCS [LLM] Miasma stage-2 executed: node runs sync.js from NodeJS data directory Bespoke install · alerting DSΣPDDCS [LLM] Miasma M-RED-TEAM HTTP C2 beacon to 85.137.53.71 Bespoke c2 · hunting DSΣPDDCS [LLM] plain-crypto-js postinstall RAT dropper spawns downloader (axios/Sapphire Sleet) Bespoke install · alerting DSΣPDDCS [LLM] axios RAT dropped artifacts: renamed PowerShell wt.exe + campaign 6202033 files Bespoke install · alerting DSΣPDDCS [LLM] File Browser hook-auth RCE follow-on: reverse shell / egress tooling under filebrowser (CVE-2026-54088) Bespoke c2 · alerting DSΣPCS [LLM] YesWiki webshell drop — web-server process writes new .php file into webroot Bespoke install · alerting DSΣPDDCS [LLM] Talos prevalent-malware SHA256 execution (UAT-7810 telemetry batch) Bespoke install · hunting DSΣPDDCS [LLM] PromptSpy Android GenAI malware C2/distribution domain contact (mgardownload.com, m-mgarg.com) Bespoke c2 · alerting DSΣPDDCS [LLM] PromptSpy dropper APK sample hash landing on monitored endpoint Bespoke delivery · hunting DSΣP [LLM] DOGLEASH ELF payload download from UAT-7810 servers on Linux/embedded devices Bespoke install · hunting DSΣPDDCS [LLM] Outbound egress from shell/downloader child of a Python (Langroid) process Bespoke c2 · hunting DSPCS [LLM] GitHub Actions runner outbound to gist.githubusercontent.com (tj-actions/changed-files CVE-2025-30066) Bespoke c2 · hunting DSΣPDDCS [LLM] 9router chain: node fetches tailscale.com/install.sh then spawns sudo -S sh within seconds Bespoke exploit · alerting DSPCS [LLM] curl/wget child of 9router node fetching tailscale.com/install.sh (probe or exploit delivery) Bespoke delivery · hunting DSΣPDDCS [LLM] PurpleFox fileless infection: remote MSI via msiexec + reflective PE injection Bespoke install · alerting DSΣPDDCS [LLM] LoLBin abuse: certutil decode/urlcache, bitsadmin transfer, wmic process-call-create Bespoke install · hunting DSΣPDDCS [LLM] Jackson Maven typosquat C2 — beacon to fasterxml.org / 103.127.243.82 Bespoke c2 · alerting DSΣPDDCS [LLM] Java/Spring drops & runs svchosts.exe (svchost masquerade) — Jackson typosquat implant Bespoke install · alerting DSΣPDDCS [LLM] Bun v1.3.13 runtime pulled from GitHub Releases during npm install (Phantom Gyp staging) Bespoke c2 · alerting DSΣP [LLM] Outbound connection to CL-STA-1062 / TinyRCT C2 and tool-staging infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] Gamaredon dead-drop C&C resolution via Telegra.ph and GoFile from script hosts Bespoke c2 · alerting DSΣPDDCS [LLM] cluw macOS stealer shell dropper fetching payload from ClawHavoc/AMOS C2 IP Bespoke install · hunting DSΣPCS [LLM] OpenClaw paste-site (rentry.co/glot.io) curl-pipe-bash semantic-hijack dropper Bespoke delivery · hunting DSΣPCS [LLM] macOS.Gaslight self-staged standalone CPython 3.10.18 fetch (astral-sh python-build-standalone) Bespoke install · alerting DSΣPCS [LLM] easy-day-js Mastra dropper C2 callout to 23.254.164.92 / .123 Bespoke c2 · hunting DSΣPDDCS [LLM] Hades on-import payload: Python process spawning Bun JavaScript runtime Bespoke c2 · alerting DSΣPDDCS [LLM] Sapphire Sleet easy-day-js RAT C2 beacon to Hostwinds 23.254.164.92 / 23.254.164.123 Bespoke c2 · hunting DSΣPDDCS [LLM] easy-day-js postinstall dropper spawning node.exe with C2 IP passed as argument Bespoke install · alerting DSΣPDDCS [LLM] Node.js writing a random 24-hex-char .js dropper to the OS temp directory Bespoke install · hunting DSΣPDDCS [LLM] Node dropper fetches second stage from Hostwinds raw IP 23.254.164.92:8000 Bespoke delivery · alerting DSΣPDDCS [LLM] axios RAT Windows payload drop (6202033.vbs/.ps1, ProgramData\wt) during npm install Bespoke install · alerting DSΣPDDCS [LLM] Shai-Hulud npm preinstall Bun bootstrap (setup_bun.js / bun_environment.js) Bespoke install · alerting DSΣPDDCS [LLM] GlassWorm Stage-2 C2 beacon to Vultr-hosted command-and-control IPs Bespoke c2 · hunting DSΣPDDCS [LLM] Scripting interpreter downloads Bun v1.3.14 runtime from oven-sh GitHub releases Bespoke delivery · hunting DSPCS [LLM] Miasma loader fetches standalone Bun v1.3.13 from oven-sh GitHub releases during install Bespoke install · alerting DSΣPDDCS [LLM] Downloader or shell child of npm/pip install (postinstall RAT loader) Bespoke install · alerting DSΣPDDCS [LLM] Bun runtime download to /tmp from a node process during npm install Bespoke delivery · alerting DSPDDCS [LLM] Egress to typosquatted C2 flipboxstudio.info (Laravel-Lang Composer SC) Bespoke c2 · alerting DSΣPDDCS [LLM] PHP CLI drops hidden /tmp dropper artefacts (Laravel-Lang autoload payload) Bespoke install · alerting DSΣPDDCS [LLM] axios RAT C2 callout to sfrclak.com / 142.11.206.73:8000 Bespoke c2 · alerting DSΣPDDCS [LLM] Laravel-Lang stealer file drop in .laravel_locale temp directory Bespoke install · alerting DSΣPDDCS [LLM] cscript.exe launching .vbs from .laravel_locale temp directory Bespoke install · alerting DSΣPDDCS [LLM] Stealer or VBS launcher dropped into .laravel_locale temp directory Bespoke install · alerting DSΣPDDCS [LLM] VS Code/Cursor extension host fetches dropper from nrwl/nx orphan commit on GitHub Bespoke install · hunting DSΣPDDCS [LLM] VS Code child process fetching payload from nrwl/nx orphan commit (Nx Console v18.95.0 dropper) Bespoke install · alerting DSΣPDDCS [LLM] WormFrp / Webworm Amazon S3 staging bucket access (wamanharipethe / whpjewellers) Bespoke actions · alerting DSΣPDDCS [LLM] TeamPCP rope.pyz Dropper Fetch from check.git-service.com C2 Bespoke c2 · hunting DSΣPDDCS [LLM] TeamPCP rope.pyz Dropper Infection Markers on Linux Bespoke install · alerting DSΣPDDCS [LLM] C2 / payload-host resolution to check.git-service.com (durabletask worm) Bespoke c2 · alerting DSΣPCS [LLM] Kubernetes propagation via kubectl staged in /tmp (kubectl exec / get secrets) Bespoke actions · alerting DSΣPDDCS [LLM] Malicious node-ipc package landed on disk under node_modules Bespoke delivery · hunting DSΣPDDCS [LLM] Bun runtime fetched from github.com/oven-sh/bun during npm install (Bitwarden CLI hijack) Bespoke delivery · alerting DSPDDCS [LLM] Python child process executing lightning _runtime/start.py bootstrapper Bespoke install · alerting DSΣPDD [LLM] Mini Shai-Hulud payload file drop: setup.mjs/execution.js by hash & size in node_modules Bespoke install · hunting DSΣPDD [LLM] Qinglong cryptominer payload download from file.551911.xyz Bespoke delivery · alerting DSΣPDDCS [LLM] Hidden .fullgc cryptominer binary written to /ql/data/db/ Bespoke install · alerting DSΣPDDCS [LLM] GPT-Proxy backdoor C2 / Stage-2 download (sync.geeker.indevs.in, gibunxi4201/kube-node-diag) Bespoke c2 · alerting DSΣPDD [LLM] Outbound connection to Velora DEX npm supply-chain C2 89.36.224.5 Bespoke c2 · alerting DSΣPDDCS [LLM] node process spawning bash/curl chain to fetch Velora DEX install.sh dropper Bespoke delivery · alerting DSΣPDDCS [LLM] macOS file write of profiler binary to com.apple.Terminal masquerade path Bespoke install · alerting DSΣPDDCS [LLM] Malicious axios or plain-crypto-js package files written to node_modules Bespoke delivery · hunting DSΣPDDCS [LLM] hackerbot-claw payload host: DNS/HTTP egress to hackmoltrepeat.com (C2 + exfil) Bespoke c2 · alerting DSΣPDDCS [LLM] hackerbot-claw second-stage download: curl -sSfL pipe-bash from hackmoltrepeat.com/molt Bespoke install · alerting DSΣPDDCS [LLM] Outbound fetch of attacker-controlled autoimport VSIX from ColossusQuailPray GitHub release Bespoke delivery · alerting DSΣPDD [LLM] IoliteLabs VSCode extension dropper: VS Code child process reaching rraghh.com / oortt.com C2 Bespoke delivery · alerting DSΣPDD [LLM] IoliteLabs IOC sweep: rraghh.com / oortt.com hostnames + campaign file hashes Bespoke c2 · hunting DSΣPDD [LLM] Outbound connection to TeamPCP C2 83.142.209.203 / ringtone.wav stego payload fetch Bespoke c2 · alerting DSΣPDDCS [LLM] WAV-disguised stager pull from TeamPCP loader 83.142.209.203:8080 Bespoke delivery · hunting DSΣPDDCS [LLM] PowerShell masquerading as Windows Terminal at %PROGRAMDATA%\wt.exe (Axios RAT Windows stage) Bespoke install · alerting DSΣPDDCS [LLM] Linux Python RAT orphaned via nohup python3 /tmp/ld.py (Axios npm payload) Bespoke install · alerting DSΣPDDCS [LLM] axios RAT artifact dropped: com.apple.act.mond / wt.exe / ld.py with known SHA256 Bespoke install · alerting DSΣPDD [LLM] TeamPCP C2 egress to 83.142.209.203:8080 (telnyx WAV-stego dropper) Bespoke c2 · hunting DSΣPDDCS [LLM] TeamPCP WAV-stego payload drop (hangup.wav / ringtone.wav) Bespoke delivery · alerting DSPDDCS [LLM] gofile.io archive download by browser followed by extracted-EXE execution within 30 minutes Bespoke install · alerting DS [LLM] ForceMemo: Node.js v22.9.0 spawned by Python from user home directory Bespoke install · alerting DSΣPDD [LLM] Bash-spawned curl to xygeni-action C2 nip.io endpoint with /b/in /b/q /b/r path on CI runner Bespoke c2 · alerting DSΣPDDCS [LLM] Cloudflare-tunnel curl-piped Python stager (kamikaze.sh / kube.py) Bespoke delivery · alerting DSΣPDDCS [LLM] CanisterWorm persistence: pglog/pg_state/internal-monitor systemd unit and /tmp/pglog drop Bespoke install · alerting DSΣPDDCS [LLM] GlassWorm Stage-3 RAT installation under %APPDATA%\QtCvyfVWKH\index.js Bespoke install · alerting DSΣPDDCS [LLM] VSCode/VSCodium spawning shell or curl to raw.githubusercontent.com/BlokTrooper Bespoke delivery · alerting DSΣPDDCS [LLM] VSCode-family host fetching from raw.githubusercontent.com/BlokTrooper/extension path Bespoke delivery · hunting DSΣPDDCS [LLM] Glassworm side-staged Node.js runtime under %APPDATA%\_node_x86 / _node_x64 Bespoke install · alerting DSΣPDD [LLM] DRILLAPP variant 2: Edge launched with --remote-debugging-port=9222 for CDP-based file download Bespoke c2 · alerting DSΣPDDCS [LLM] Cacheract memdump.py download/execution on CI runner or developer host Bespoke install · alerting DSΣPDD [LLM] Scavenger loader/install.js dropped into node_modules (known SHA256 or filename match) Bespoke delivery · hunting DSΣPDD [LLM] tj-actions/changed-files compromise: self-hosted runner egress to nikitastupin memdump gist (CVE-2025-30066) Bespoke delivery · hunting DSΣPDD [LLM] Endpoint contact with attacker C2 setup-service.com (OpenClaw skill stager) Bespoke c2 · alerting DSΣPDDCS [LLM] Pastebin-piping stager retrieved from rentry.co/openclaw-core (macOS/Linux ClawHub skill) Bespoke delivery · alerting DSPDDCS [LLM] Download of openclawcore-1.0.3.zip from denboss99 GitHub release (Windows OpenClaw skill payload) Bespoke delivery · alerting DSΣPDDCS [LLM] AI coding agent spawns remote fetch-and-execute (curl | bash / curl | source) Bespoke install · alerting DSΣPDDCS [LLM] Executable dropped into C:\inetpub\pub\ shared directory Bespoke delivery · alerting DSΣPDDCS [LLM] LittleDaemon / DaemonicLogistics update-hijack URL pattern (popup_4.2.0.2246.dll, /update/updateInfo.bzp, /update/file6.bdat, /update/file2. Bespoke delivery · alerting DSΣP [LLM] DaemonicLogistics fake-Tencent payload drop (logo.gif at %PROGRAMDATA%\Tencent\QQUpdateMgr\UpdateFiles) Bespoke install · alerting DSΣP [LLM] Scavenger Loader DLL (node-gyp.dll) written inside node_modules of CVE-2025-54313 packages Bespoke delivery · alerting DSΣPDDCS [LLM] ScreenConnect MSI sideload from lmfao.su (Solidity Language post-exploit RAT install) Bespoke install · alerting DSΣPDDCS [LLM] Self-hosted GitHub Action runner downloads memdump.py from compromised gist (CVE-2025-30066) Bespoke delivery · alerting DSΣPDDCS [LLM] Outbound fetch of file.sh via attacker-controlled commit d8daa0b... on raw.githubusercontent.com Bespoke c2 · alerting DSΣPDDCS [LLM] Log4Shell outbound JNDI callback from Java process to LDAP/RMI (CVE-2021-44228) Bespoke c2 · alerting DSΣPDDCS [LLM] Vulnerable Moq 4.20.0 or Devlooped.SponsorLink NuGet package landed on endpoint Bespoke delivery · alerting DSΣPDDCS [LLM] JVM outbound fetch of remote class/JAR to public host — URLClassLoader gadget Bespoke delivery · hunting DSPDDCS [LLM] Java process outbound LDAP/RMI to fetch remote class — SnakeYAML JNDI gadget Bespoke c2 · alerting DSΣPDDCS [LLM] Python child-of-python making download-and-exec egress to non-PyPI host Bespoke c2 · hunting DSΣPDDCS [LLM] Lockfile injection: npm/yarn fetching dependencies from GitHub gist/repo instead of the registry Bespoke delivery · hunting DSΣPDDCS [LLM] npm/yarn install-script (postinstall) spawning download LOLBins for secret theft / payload fetch Bespoke exploit · hunting DSΣPDDCS [LLM] Python interpreter drops EXE sourced from Discord CDN (cyphers/stealthpy PyPI malware) Bespoke delivery · alerting DSΣPDDCS [LLM] gxm-reference second-stage backdoor C2 to 82.196.7.23 / 82.196.15.238 (/callbackupload) Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound connection to Spring4Shell Mirai staging IPs (107.174.133.167 / 194.31.98.186) Bespoke c2 · hunting DSΣPDDCSCW [LLM] PHP/web-server process writes .php into dompdf font cache (malicious font staged) Bespoke install · hunting DSΣPCS [LLM] Java process making outbound LDAP/RMI callout to public host (JNDI egress) Bespoke c2 · hunting DSΣPDDCS [LLM] Java process outbound LDAP/RMI egress (CVE-2021-44832 remote JNDI data source load) Bespoke exploit · alerting DSΣPDDCS [LLM] Log4Shell JNDI class fetch: java process outbound to LDAP/RMI ports Bespoke c2 · alerting DSΣPDDCS [LLM] Java process making outbound LDAP/RMI connection (Log4Shell second-stage class fetch) Bespoke delivery · hunting DSΣPDDCS [LLM] Java process outbound to LDAP/RMI/DNS callback port — Log4Shell JNDI fetch Bespoke c2 · alerting DSΣPDDCS [LLM] Java process outbound LDAP/RMI to public IP (Log4Shell JNDI callback) Bespoke c2 · hunting DSΣPDDCS [LLM] Attacker-staged .session deserialization payload written outside Tomcat's session store Bespoke delivery · hunting DSΣPDDCS [LLM] ImageMagick convert lineage egress to public IP (url() delegate / netcat reverse shell) Bespoke c2 · hunting DSΣPCS [LLM] strong_password 0.0.7 backdoor: Ruby app server fetches second-stage payload from pastebin.com/raw/xa456PFt Bespoke c2 · alerting DSΣPCS

Articles citing this technique (117)