Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1070.004 File Deletion |
MalwareStrifeWater | StrifeWater can self delete to cover its tracks. |
| T1070.004 File Deletion |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has deleted itself and the 'index.dat' file on a compromised machine to remove recent Internet history from the system. |
| T1070.004 File Deletion |
MalwareFALLCHILL | FALLCHILL can delete malware and associated artifacts from the victim. |
| T1070.004 File Deletion |
ToolSILENTTRINITY | SILENTTRINITY can remove files from the compromised host. |
| T1070.004 File Deletion |
ToolPcShare | PcShare has deleted its files and components from a compromised host. |
| T1070.004 File Deletion |
ToolCSPY Downloader | CSPY Downloader has the ability to self delete. |
| T1070.004 File Deletion |
ToolRemcos | Remcos can delete files and folders from victim machines. |
| T1070.004 File Deletion |
ToolImminent Monitor | Imminent Monitor has deleted files related to its dynamic debugger feature. |
| T1070.004 File Deletion |
Toolcmd | cmd can be used to delete files from the file system. |
| T1070.004 File Deletion |
ToolSDelete | SDelete deletes data in a way that makes it unrecoverable. |
| T1070.004 File Deletion |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to remove all staged files after exfiltration. |
| T1070.004 File Deletion |
MalwareMini Shai-Hulud | Mini Shai-Hulud has deleted all artifacts to include gathered credential archives to reduce disk persistence and detection. |
| T1070.004 File Deletion |
MalwareCanisterWorm | CanisterWorm has deleted itself after execution. |
| T1070.004 File Deletion |
MalwareZeroCleare | ZeroCleare has the ability to uninstall the RawDisk driver and delete the `rwdsk` file on disk. |
| T1070.005 Network Share Connection Removal |
GroupThreat Group-3390 | Threat Group-3390 has detached network shares after exfiltrating files, likely to evade detection. |
| T1070.005 Network Share Connection Removal |
MalwareRobbinHood | RobbinHood disconnects all network shares from the computer with the command |
| T1070.005 Network Share Connection Removal |
MalwareDUSTTRAP | DUSTTRAP can remove network shares from infected systems. |
| T1070.005 Network Share Connection Removal |
MalwareInvisiMole | InvisiMole can disconnect previously connected remote drives. |
| T1070.005 Network Share Connection Removal |
ToolNet | The |
| T1070.006 Timestomp |
CampaignCutting Edge | During Cutting Edge, threat actors changed timestamps of multiple files on compromised Ivanti Secure Connect VPNs to conceal malicious activity. |
| T1070.006 Timestomp |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used timestomping to modify the |
| T1070.006 Timestomp |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 modified timestamps of backdoors to match legitimate Windows files. |
| T1070.006 Timestomp |
GroupAPT38 | APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host. |
| T1070.006 Timestomp |
GroupKimsuky | Kimsuky has manipulated timestamps for creation or compilation dates to defeat anti-forensics. |
| T1070.006 Timestomp |
GroupAPT32 | APT32 has used scheduled task raw XML with a backdated timestamp of June 2, 2016. The group has also set the creation time of the files dropped by the second stage of the exploit to match the creation time of kernel32.dll. Additionally, APT32 has used a random value to modify the timestamp of the file storing the clientID. |
| T1070.006 Timestomp |
GroupMustang Panda | Mustang Panda has modified file timestamps from the export address table (EAT) in malware to make it difficult to identify creation times. |
| T1070.006 Timestomp |
GroupRocke | Rocke has changed the time stamp of certain files. |
| T1070.006 Timestomp |
GroupUNC3886 | UNC3886 has used scripts to timestomp ESXi hosts prior to installing malicious vSphere Installation Bundles (VIBs). |
| T1070.006 Timestomp |
GroupAPT29 | APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. |
| T1070.006 Timestomp |
GroupChimera | Chimera has used a Windows version of the Linux |
| T1070.006 Timestomp |
GroupAPT28 | APT28 has performed timestomping on victim files. |
| T1070.006 Timestomp |
GroupAPT5 | APT5 has modified file timestamps. |
| T1070.006 Timestomp |
GroupLazarus Group | Several Lazarus Group malware families use timestomping, including modifying the last write timestamp of a specified Registry key to a random date, as well as copying the timestamp for legitimate .exe files (such as calc.exe or mspaint.exe) to its dropped files. |
| T1070.006 Timestomp |
MalwareBLINDINGCAN | BLINDINGCAN has modified file and directory timestamps. |
| T1070.006 Timestomp |
MalwareNinja | Ninja can change or create the last access or write times. |
| T1070.006 Timestomp |
MalwareStuxnet | Stuxnet extracts and writes driver files that match the times of other legitimate files. |
| T1070.006 Timestomp |
MalwareSEASHARPEE | SEASHARPEE can timestomp files on victims using a Web shell. |
| T1070.006 Timestomp |
MalwareTDTESS | After creating a new service for persistence, TDTESS sets the file creation time for the service to the creation time of the victim's legitimate svchost.exe file. |
| T1070.006 Timestomp |
MalwareMisdat | Many Misdat samples were programmed using Borland Delphi, which will mangle the default PE compile timestamp of a file. |
| T1070.006 Timestomp |
MalwareBankshot | Bankshot modifies the time of a file as specified by the control server. |
| T1070.006 Timestomp |
MalwareUPSTYLE | UPSTYLE restores timestamps to original values following modification. |
| T1070.006 Timestomp |
MalwareBOOKWORM | BOOKWORM has modified file timestamps from the export address table (EAT) to make it difficult to discern when the module was created. |
| T1070.006 Timestomp |
MalwarePingPull | PingPull has the ability to timestomp a file. |
| T1070.006 Timestomp |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware can timestomp files for defense evasion and anti-forensics purposes. |
| T1070.006 Timestomp |
MalwareInvisiMole | InvisiMole samples were timestomped by the authors by setting the PE timestamps to all zero values. InvisiMole also has a built-in command to modify file times. |
| T1070.006 Timestomp |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can time stomp its executable, previously dating it between 2010 to 2021. |
| T1070.006 Timestomp |
MalwareChina Chopper | China Chopper's server component can change the timestamp of files. |
| T1070.006 Timestomp |
MalwareKeyBoy | KeyBoy time-stomped its DLL in order to evade detection. |
| T1070.006 Timestomp |
MalwarePOSHSPY | POSHSPY modifies timestamps of all downloaded executables to match a randomly selected file created prior to 2013. |
| T1070.006 Timestomp |
MalwareMultiLayer Wiper | MultiLayer Wiper changes timestamps of overwritten files to either 1601.1.1 for NTFS filesystems, or 1980.1.1 for all other filesystems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.