Skip to content
Threat Feed

Tag

Ingress-Tool-Transfer

7 briefs RSS
high advisory

Web Server Outbound Connections to File Sharing Services

Attackers compromise web servers (Apache, Nginx, Tomcat, PHP) and leverage them to make unexpected outbound network connections to public file-sharing or content hosting services, indicating post-exploitation activity for ingress tool transfer and further compromise.

Apache HTTP Server +3 post-exploitation ingress-tool-transfer webshell web-server c2 windows
1r 2t 26i
high threat

Suspicious File Download From File Sharing Domain Via Curl.EXE

A high-severity threat involves the abuse of `curl.exe` on Windows systems to download potentially malicious files from various public file-sharing and content delivery network (CDN) domains, a technique observed in campaigns by threat actors such as FIN7, leading to further system compromise.

FIN7 +2 curl download file-sharing ingress-tool-transfer windows threat-hunting
1r 3t 36i
high advisory

Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE

This brief details the use of the legitimate Windows utility `certutil.exe` by various threat actors to download malicious files from public file-sharing and code-hosting websites, facilitating further compromise and evasion on targeted systems.

Windows lolbin defense-evasion ingress-tool-transfer
1r 2t 35i
high advisory

Suspicious Download From File-Sharing Website Via Bitsadmin

This threat brief details the detection of adversaries leveraging the legitimate Windows Background Intelligent Transfer Service (BITSAdmin) utility to download malicious payloads from suspicious file-sharing and cloud storage domains, a technique commonly employed by ransomware groups and APTs for ingress tool transfer and stealthy execution.

living-off-the-land lolbas payload-delivery ingress-tool-transfer command-and-control windows
1r 4t 35i
high advisory

BITS Transfer Job Downloads from File Sharing Domains

Adversaries leverage the Windows Background Intelligent Transfer Service (BITS) to download malicious payloads from legitimate file-sharing and cloud storage domains, enabling stealthy ingress of tools and malware onto compromised systems, a technique observed in campaigns by ransomware groups and nation-state actors.

persistence execution defense-evasion ingress-tool-transfer windows
1r 3t
medium advisory

MpCmdRun.exe Used for Remote File Download

Attackers are abusing the Windows Defender MpCmdRun.exe utility to download remote files, potentially delivering malware or offensive tools into compromised systems.

Windows Defender command-and-control ingress-tool-transfer windows mpcmdrun
2r 1t
medium advisory

Remote File Download via Desktopimgdownldr Utility

The rule detects the use of desktopimgdownldr.exe to download remote files, which is an abuse of a signed utility often used as an alternative to certutil for transferring malicious tools or malware into a compromised environment.

Windows command-and-control ingress-tool-transfer
2r 1t