Real-world descriptions of how a group, tool or campaign used a technique.
143 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
MalwareEKANS | EKANS has been disguised as |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBLINDINGCAN | BLINDINGCAN has attempted to hide its payload by using legitimate file names such as "iconcache.db". |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareNinja | Ninja has used legitimate looking filenames for its loader including update.dll and x64.dll. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBumblebee | Bumblebee has named component DLLs "RapportGP.dll" to match those used by the security company Trusteer. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBRICKSTORM | BRICKSTORM has appeared to resemble legitimate processes to include the vCenter process `vami-http`. BRICKSTORM has also leveraged legitimate names of VMware vSphere platform such as `vmsrc` or `vmware-sphere`. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareNOKKI | NOKKI is written to %LOCALAPPDATA%\MicroSoft Updatea\svServiceUpdate.exe prior being executed in a new process in an apparent attempt to masquerade as a legitimate folder and file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRotaJakiro | RotaJakiro has used the filename `systemd-daemon` in an attempt to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareChinoxy | Chinoxy has used the name `eoffice.exe` in attempt to appear as a legitimate file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMisdat | Misdat saves itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareUrsnif | Ursnif has used strings from legitimate system files and existing folders for its file, folder, and Registry entry names. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareThreatNeedle | ThreatNeedle chooses its payload creation path from a randomly selected service name from netsvc. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareZLib | ZLib mimics the resource version information of legitimate Realtek Semiconductor, Nvidia, or Synaptics modules. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTsundere Botnet | Tsundere Botnet has disguised its MSI installer as a fake installer for popular games and software. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareFelismus | Felismus has masqueraded as legitimate Adobe Content Management System files. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareStrongPity | StrongPity has been bundled with legitimate software installation files for disguise. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareNebulae | Nebulae uses functions named |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTONESHELL | TONESHELL has renamed malicious files to mimic legitimate file names and file extensions. TONESHELL has also masqueraded as legitimate file names to include LogMeIn.dll. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRainyDay | RainyDay has used names to mimic legitimate software including "vmtoolsd.exe" to spoof Vmtools. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareAppleSeed | AppleSeed has the ability to rename its payload to ESTCommon.dll to masquerade as a DLL belonging to ESTsecurity. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareNETWIRE | NETWIRE has masqueraded as legitimate software including TeamViewer and macOS Finder. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTinyTurla | TinyTurla has been deployed as `w64time.dll` to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePyDCrypt | PyDCrypt has dropped DCSrv under the `svchost.exe` name to disk. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareJ-magic | J-magic can rename itself as “[nfsiod 0]” to masquerade as the local Network File System (NFS) asynchronous I/O server. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareOLDBAIT | OLDBAIT installs itself in |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBad Rabbit | Bad Rabbit has masqueraded as a Flash Player installer through the executable file |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSslMM | To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSTATICPLUGIN | STATICPLUGIN has leveraged naming conventions that match legitimate services to include AdobePlugins.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTEARDROP | TEARDROP files had names that resembled legitimate Window file and directory names. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMachete | Machete renamed payloads to masquerade as legitimate Google Chrome, Java, Dropbox, Adobe Reader and Python executables. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareDUSTPAN | DUSTPAN is often disguised as a legitimate Windows binary such as `w3wp.exe` or `conn.exe`. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePUBLOAD | PUBLOAD has renamed malicious files to mimic legitimate file names such as adobe_wf.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCANONSTAGER | CANONSTAGER has leveraged naming conventions of its malicious DLL to match legitimate services to include cnmpaui.dll which matches the legitimate executable cnmpaui.exe that is aligned with a Canon Ink Jet Printer Assistant Tool. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareHexEval Loader | HexEval Loader has masqueraded and typosquatted as legitimate code repository packages and projects. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCuckoo Stealer | Cuckoo Stealer has copied and renamed itself to DumpMediaSpotifyMusicConverter. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareInvisiMole | InvisiMole has disguised its droppers as legitimate software or documents, matching their original names and locations, and saved its files as mpr.dll in the Windows folder. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCLAIMLOADER | CLAIMLOADER has imitated legitimate software directories through the creation and storage of the EXE and DLL in `C:\ProgramData\` and the use of legitimate looking names of software. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareQUIETEXIT | QUIETEXIT has attempted to change its name to `cron` upon startup. During incident response, QUIETEXIT samples have been identified that were renamed to blend in with other legitimate files. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRDAT | RDAT has masqueraded as VMware.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSkidmap | Skidmap has created a fake |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTRANSLATEXT | TRANSLATEXT has been named `GoogleTranslate.crx` to masquerade as a legitimate Chrome extension. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSameCoin | SameCoin has named files to appear legitimate such as "MicrosoftEdge.exe." |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRaindrop | Raindrop was installed under names that resembled legitimate Windows file and directory names. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareDoki | Doki has disguised a file as a Linux kernel module. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRustyWater | RustyWater has used reddit.exe as its file name and a Cloudflare logo. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareFysbis | Fysbis has masqueraded as trusted software rsyncd and dbus-inotifier. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareIcedID | IcedID has modified legitimate .dll files to include malicious code. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMarkiRAT | MarkiRAT can masquerade as |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareDarkComet | DarkComet has dropped itself onto victim machines with file names such as WinDefender.Exe and winupdate.exe in an apparent attempt to masquerade as a legitimate file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareDRATzarus | DRATzarus has been named `Flash.exe`, and its dropper has been named `IExplorer`. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSocGholish | SocGholish has been named `AutoUpdater.js` to mimic legitimate update files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.