FORENSIA

ATT&CK · T1608.001 · sub-technique

Upload Malware

Tactics: resource-development

About

Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, and a variety of other malicious content. Adversaries may upload malware to support their operations, such as making a payload available to a victim network to enable Ingress Tool Transfer by placing it on an Internet accessible web server. Malware may be placed on infrastructure that was previously purchased/rented by the adversary (Acquire Infrastructure) or was otherwise compromised by them (Compromise Infrastructure). Malware can also be staged on web services, such as GitHub or Pastebin; hosted on the InterPlanetary File System (IPFS), where decentralized content storage makes the removal of malicious files difficult; or saved on the blockchain as smart contracts, which are resilient against takedowns that would affect traditional infrastructure. Adversaries may upload backdoored files, such as software packages, application binaries, virtual machine images, or container images, to third-party software stores, package libraries, extension marketplaces, or repositories (ex: GitHub, CNET, AWS Community AMIs, Docker Hub, PyPi, NPM). By chance encounter, victims may directly download/install these backdoored files via User Execution. Masquerading, including typosquatting legitimate software, may increase the chance of users mistakenly executing these files.

Corpus indicators tagged with this technique

998 indicators in the corpus carry T1608.001.

IndicatorTypeFamilySevSrc
cve-2022-47945cve851
23808e7638f7a00b1ef9b9f4ca524f8a46cf63be6f6b79fec8e4a3fd1cc82a1esha256supply_chain801
ec1cac2ada6726623b4bafb94c204c359ce7cdf5325909137fc0e6aef506783fsha256cryptojacking802
ab58a90eb3682c6dc3389cd700a64f68a19c0dac3d0fa8e3df97ae041f96d4e1sha256supply_chain801
d9f7ca9f93a7d188d51db308877b15d0beae932ca0bf4705384fbedf54b454c1sha256supply_chain801
5f3a9ebf7039097b3cdbca8609b5b68af07eeb1dbf716ba2817a97fc7c543854sha256supply_chain801
8e5546c83d764e1287b55cbe868a45344a6f0afa9782d798d03b2b7cfc53ec38hashphishing801
ec7b0bc82c00464d8e0a59bc19c585e2hashphishing801
9a2091e6625fc11cfd8f39c17aa271604e66322ee045028946274b988103e35bsha256supply_chain801
900ddb81d27e03967209fee4d17d13deb68eef0e1f10936eb520ca10575cb49esha256supply_chain801
d7747e7a3c782009f4ceb6e9c106115876386853929563b509da5258e3968d15sha256cryptojacking802
4fe8bec780537aa223406965415c1f85e83eec1f4e2181cf82e2a7b7516026e6hashphishing801
4d13f1136b13c871c65141b77ec7208488334ac4be511800196adcd328666305sha256supply_chain801
79c09e1ffb4804c14ff27d41ec08d4390455c92d65717be0aeeec2697297d76asha256supply_chain801
d5385526f2f3e52c7d96087611c6cd4e479bf61828400efdb3ca09406d981609sha256supply_chain801
45126b353f1636103da356121cd00b229b635b41b99d91166e6d7d9037482242sha256cryptojacking802
86819efe7319b664920ba2e1fd4b079a4e6b5eaaebeeb1adb2c1c8dc3c81ee0csha256cryptojacking802
129de16fe69763f767d8249279a2c4a1a6deafadd1a84563bd84b258ea010bffsha256cryptojacking802
e576a61e1a2ba71e764647bb2f0883c2f8fa4d591799c60d21a84230ee7a5b63sha256cryptojacking802
235a64e3520b1c2c27763122b303f78aee8d7c083dfd9f1eb936cd5174383609sha256cryptojacking802
a628ad47fe93ee7413cca90aeca8f9540bfcd5ccdbeb4d9914670b3ef66247f4sha256cryptojacking802
969b0bfd605aa2cddf353f3638b0dee26b1c2305600231e055fa6d7786a879fesha256cryptojacking802
e6e1049158ceb1971c61388349c81fa6047a7aecb4ff2089ef54a50dcc35dbc0sha256supply_chain801
810614290bdb14d2ddf10f65f8adc988a8272764f2a9e2c378e52fad162da344sha256cryptojacking802
a2e7989742c6b6436ebb47507881946e4f662080dff71d104eb9a9554f38af7asha256cryptojacking802
938054c6bb7dc737fce16513b2882808f199c2f892f808d439525a1650d49089sha256cryptojacking802
e73491065d86b1ad69229bb5d2019e08b947e11a2a57adf5c2d9a2b5d8f4acadsha256cryptojacking802
d95bba20f04687b0b821d4fc0a17137db8b9eda5fe3fb34da319abefc45fe0d1sha256cryptojacking802
011926de3d0cc2b970627b9bf0de003e731f8576602dff756d2ab54a9de61972sha256supply_chain801
e8c2618565aa31d7ffe909ebc99040bafcc0ea8df7f5d92fa673bb7ffacb14c9sha256supply_chain801

Showing the top 30 by severity of 998.