ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1036.005×

143 examples

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
MalwareGreen Lambert

Green Lambert has been disguised as a Growl help file.

T1036.005
Match Legitimate Resource Name or Location
MalwarePUNCHBUGGY

PUNCHBUGGY mimics filenames from %SYSTEM%\System32 to hide DLLs in %WINDIR% and/or %TEMP%.

T1036.005
Match Legitimate Resource Name or Location
MalwareGoldMax

GoldMax has used filenames that matched the system name, and appeared as a scheduled task impersonating systems management software within the corresponding ProgramData subfolder.

T1036.005
Match Legitimate Resource Name or Location
MalwarePlugX

PlugX has been disguised as legitimate Adobe and PotPlayer files. PlugX has also imitated legitimate software directories and file names through the creation and storage of a legitimate EXE and the malicious DLLs.

T1036.005
Match Legitimate Resource Name or Location
MalwareBisonal

Bisonal has renamed malicious code to `msacm32.dll` to hide within a legitimate library; earlier versions were disguised as `winhelp`.

T1036.005
Match Legitimate Resource Name or Location
MalwareS-Type

S-Type may save itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary.

T1036.005
Match Legitimate Resource Name or Location
MalwareRemsec

The Remsec loader implements itself with the name Security Support Provider, a legitimate Windows function. Various Remsec .exe files mimic legitimate file names used by Microsoft, Symantec, Kaspersky, Hewlett-Packard, and VMWare. Remsec also disguised malicious modules using similar filenames as custom network encryption software on victims.

T1036.005
Match Legitimate Resource Name or Location
MalwareLightNeuron

LightNeuron has used filenames associated with Exchange and Outlook for binary and configuration files, such as winmail.dat.

T1036.005
Match Legitimate Resource Name or Location
MalwareCuba

Cuba has been disguised as legitimate 360 Total Security Antivirus and OpenVPN programs.

T1036.005
Match Legitimate Resource Name or Location
MalwarePureCrypter

PureCrypter has used multiple file names to appear legitimate such as firefox\firefox.exe, Google\chrome.exe, and Taskmgr.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareThiefQuest

ThiefQuest prepends a copy of itself to the beginning of an executable file while maintaining the name of the executable.

T1036.005
Match Legitimate Resource Name or Location
MalwareFoggyWeb

FoggyWeb can be disguised as a Visual Studio file such as `Windows.Data.TimeZones.zh-PH.pri` to evade detection. Also, FoggyWeb's loader can mimic a genuine `dll` file that carries out the same import functions as the legitimate Windows `version.dll` file.

T1036.005
Match Legitimate Resource Name or Location
MalwareElise

If installing itself as a service fails, Elise instead writes itself as a file named svchost.exe saved in %APPDATA%\Microsoft\Network.

T1036.005
Match Legitimate Resource Name or Location
MalwareLatrodectus

Latrodectus has been packed to appear as a component to Bitdefender’s kernel-mode driver, TRUFOS.SYS.

T1036.005
Match Legitimate Resource Name or Location
MalwareSaint Bot

Saint Bot has been disguised as a legitimate executable, including as Windows SDK.

T1036.005
Match Legitimate Resource Name or Location
MalwareChaes

Chaes has used an unsigned, crafted DLL module named hha.dll that was designed to look like a legitimate 32-bit Windows DLL.

T1036.005
Match Legitimate Resource Name or Location
MalwareBundlore

Bundlore has disguised a malicious .app file as a Flash Player update.

T1036.005
Match Legitimate Resource Name or Location
MalwareFooder

Fooder has frequently masqueraded as the Snake game, using strings such as “Welcome to snake Game” and mutexes such as “SNAKE_G.”

T1036.005
Match Legitimate Resource Name or Location
MalwareQUADAGENT

QUADAGENT used the PowerShell filenames Office365DCOMCheck.ps1 and SystemDiskClean.ps1.

T1036.005
Match Legitimate Resource Name or Location
MalwareTAINTEDSCRIBE

The TAINTEDSCRIBE main executable has disguised itself as Microsoft’s Narrator.

T1036.005
Match Legitimate Resource Name or Location
MalwareMetamorfo

Metamorfo has disguised an MSI file as the Adobe Acrobat Reader Installer and has masqueraded payloads as OneDrive, WhatsApp, or Spotify, for example.

T1036.005
Match Legitimate Resource Name or Location
MalwarePipeMon

PipeMon modules are stored on disk with seemingly benign names including use of a file extension associated with a popular word processor.

T1036.005
Match Legitimate Resource Name or Location
MalwareMagicRAT

MagicRAT stores configuration data in files and file paths mimicking legitimate operating system resources.

T1036.005
Match Legitimate Resource Name or Location
MalwareKONNI

KONNI has created a shortcut called "Anti virus service.lnk" in an apparent attempt to masquerade as a legitimate file.

T1036.005
Match Legitimate Resource Name or Location
MalwareKGH_SPY

KGH_SPY has masqueraded as a legitimate Windows tool.

T1036.005
Match Legitimate Resource Name or Location
MalwareIxeshe

Ixeshe has used registry values and file names associated with Adobe software, such as AcroRd32.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareBlack Basta

The Black Basta dropper has mimicked an application for creating USB bootable drivers.

T1036.005
Match Legitimate Resource Name or Location
MalwareNightClub

NightClub has chosen file names to appear legitimate including EsetUpdate-0117583943.exe for its dropper.

T1036.005
Match Legitimate Resource Name or Location
MalwareStrelaStealer

StrelaStealer payloads have tailored filenames to include names identical to the name of the targeted organization or company.

T1036.005
Match Legitimate Resource Name or Location
MalwareGrandoreiro

Grandoreiro has named malicious browser extensions and update files to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
MalwareStarloader

Starloader has masqueraded as legitimate software update packages such as Adobe Acrobat Reader and Intel.

T1036.005
Match Legitimate Resource Name or Location
MalwareSibot

Sibot has downloaded a DLL to the C:\windows\system32\drivers\ folder and renamed it with a .sys extension.

T1036.005
Match Legitimate Resource Name or Location
MalwareTarrask

Tarrask has masqueraded as executable files such as `winupdate.exe`, `date.exe`, or `win.exe`.

T1036.005
Match Legitimate Resource Name or Location
MalwareGoBear

GoBear is installed through droppers masquerading as legitimate, signed software installers.

T1036.005
Match Legitimate Resource Name or Location
MalwareShark

Shark binaries have been named `audioddg.pdb` and `Winlangdb.pdb` in order to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
MalwareBazar

The Bazar loader has named malicious shortcuts "adobe" and mimicked communications software.

T1036.005
Match Legitimate Resource Name or Location
MalwareSUGARDUMP

SUGARDUMP has been named `CrashReporter.exe` to appear as a legitimate Mozilla executable.

T1036.005
Match Legitimate Resource Name or Location
MalwareRyuk

Ryuk has constructed legitimate appearing installation folder paths by calling GetWindowsDirectoryW and then inserting a null byte at the fourth character of the path. For Windows Vista or higher, the path would appear as C:\Users\Public.

T1036.005
Match Legitimate Resource Name or Location
MalwareHermeticWiper

HermeticWiper has used the name `postgressql.exe` to mask a malicious payload.

T1036.005
Match Legitimate Resource Name or Location
MalwarePysa

Pysa has executed a malicious executable by naming it svchost.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareFinFisher

FinFisher renames one of its .dll files to uxtheme.dll in an apparent attempt to masquerade as a legitimate file.

T1036.005
Match Legitimate Resource Name or Location
MalwareOwaAuth

OwaAuth uses the filename owaauth.dll, which is a legitimate file that normally resides in %ProgramFiles%\Microsoft\Exchange Server\ClientAccess\Owa\Auth\; the malicious file by the same name is saved in %ProgramFiles%\Microsoft\Exchange Server\ClientAccess\Owa\bin\.

T1036.005
Match Legitimate Resource Name or Location
MalwareSUNBURST

SUNBURST created VBScripts that were named after existing services or folders to blend into legitimate activities.

T1036.005
Match Legitimate Resource Name or Location
MalwareREvil

REvil can mimic the names of known executables.

T1036.005
Match Legitimate Resource Name or Location
MalwareSamurai

Samurai has created the directory `%COMMONPROGRAMFILES%\Microsoft Shared\wmi\` to contain DLLs for loading successive stages.

T1036.005
Match Legitimate Resource Name or Location
MalwareUSBStealer

USBStealer mimics a legitimate Russian program called USB Disk Security.

T1036.005
Match Legitimate Resource Name or Location
MalwareSUPERNOVA

SUPERNOVA has masqueraded as a legitimate SolarWinds DLL.

T1036.005
Match Legitimate Resource Name or Location
MalwareCyclops Blink

Cyclops Blink can rename its running process to [kworker:0/1] to masquerade as a Linux kernel thread. Cyclops Blink has also named RC scripts used for persistence after WatchGuard artifacts.

T1036.005
Match Legitimate Resource Name or Location
MalwareDaserf

Daserf uses file and folder names related to legitimate programs in order to blend in, such as HP, Intel, Adobe, and perflogs.

T1036.005
Match Legitimate Resource Name or Location
MalwareDanBot

DanBot files have been named `UltraVNC.exe` and `WINVNC.exe` to appear as legitimate VNC tools.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.