Real-world descriptions of how a group, tool or campaign used a technique.
143 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGreen Lambert | Green Lambert has been disguised as a Growl help file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePUNCHBUGGY | PUNCHBUGGY mimics filenames from %SYSTEM%\System32 to hide DLLs in %WINDIR% and/or %TEMP%. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGoldMax | GoldMax has used filenames that matched the system name, and appeared as a scheduled task impersonating systems management software within the corresponding ProgramData subfolder. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePlugX | PlugX has been disguised as legitimate Adobe and PotPlayer files. PlugX has also imitated legitimate software directories and file names through the creation and storage of a legitimate EXE and the malicious DLLs. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBisonal | Bisonal has renamed malicious code to `msacm32.dll` to hide within a legitimate library; earlier versions were disguised as `winhelp`. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareS-Type | S-Type may save itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRemsec | The Remsec loader implements itself with the name Security Support Provider, a legitimate Windows function. Various Remsec .exe files mimic legitimate file names used by Microsoft, Symantec, Kaspersky, Hewlett-Packard, and VMWare. Remsec also disguised malicious modules using similar filenames as custom network encryption software on victims. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareLightNeuron | LightNeuron has used filenames associated with Exchange and Outlook for binary and configuration files, such as |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCuba | Cuba has been disguised as legitimate 360 Total Security Antivirus and OpenVPN programs. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePureCrypter | PureCrypter has used multiple file names to appear legitimate such as firefox\firefox.exe, Google\chrome.exe, and Taskmgr.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareThiefQuest | ThiefQuest prepends a copy of itself to the beginning of an executable file while maintaining the name of the executable. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareFoggyWeb | FoggyWeb can be disguised as a Visual Studio file such as `Windows.Data.TimeZones.zh-PH.pri` to evade detection. Also, FoggyWeb's loader can mimic a genuine `dll` file that carries out the same import functions as the legitimate Windows `version.dll` file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareElise | If installing itself as a service fails, Elise instead writes itself as a file named svchost.exe saved in %APPDATA%\Microsoft\Network. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareLatrodectus | Latrodectus has been packed to appear as a component to Bitdefender’s kernel-mode driver, TRUFOS.SYS. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSaint Bot | Saint Bot has been disguised as a legitimate executable, including as Windows SDK. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareChaes | Chaes has used an unsigned, crafted DLL module named |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBundlore | Bundlore has disguised a malicious .app file as a Flash Player update. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareFooder | Fooder has frequently masqueraded as the Snake game, using strings such as “Welcome to snake Game” and mutexes such as “SNAKE_G.” |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareQUADAGENT | QUADAGENT used the PowerShell filenames |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTAINTEDSCRIBE | The TAINTEDSCRIBE main executable has disguised itself as Microsoft’s Narrator. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMetamorfo | Metamorfo has disguised an MSI file as the Adobe Acrobat Reader Installer and has masqueraded payloads as OneDrive, WhatsApp, or Spotify, for example. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePipeMon | PipeMon modules are stored on disk with seemingly benign names including use of a file extension associated with a popular word processor. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMagicRAT | MagicRAT stores configuration data in files and file paths mimicking legitimate operating system resources. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareKONNI | KONNI has created a shortcut called "Anti virus service.lnk" in an apparent attempt to masquerade as a legitimate file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareKGH_SPY | KGH_SPY has masqueraded as a legitimate Windows tool. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareIxeshe | Ixeshe has used registry values and file names associated with Adobe software, such as AcroRd32.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBlack Basta | The Black Basta dropper has mimicked an application for creating USB bootable drivers. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareNightClub | NightClub has chosen file names to appear legitimate including EsetUpdate-0117583943.exe for its dropper. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareStrelaStealer | StrelaStealer payloads have tailored filenames to include names identical to the name of the targeted organization or company. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGrandoreiro | Grandoreiro has named malicious browser extensions and update files to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareStarloader | Starloader has masqueraded as legitimate software update packages such as Adobe Acrobat Reader and Intel. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSibot | Sibot has downloaded a DLL to the |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTarrask | Tarrask has masqueraded as executable files such as `winupdate.exe`, `date.exe`, or `win.exe`. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGoBear | GoBear is installed through droppers masquerading as legitimate, signed software installers. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareShark | Shark binaries have been named `audioddg.pdb` and `Winlangdb.pdb` in order to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBazar | The Bazar loader has named malicious shortcuts "adobe" and mimicked communications software. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSUGARDUMP | SUGARDUMP has been named `CrashReporter.exe` to appear as a legitimate Mozilla executable. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRyuk | Ryuk has constructed legitimate appearing installation folder paths by calling |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareHermeticWiper | HermeticWiper has used the name `postgressql.exe` to mask a malicious payload. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePysa | Pysa has executed a malicious executable by naming it svchost.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareFinFisher | FinFisher renames one of its .dll files to uxtheme.dll in an apparent attempt to masquerade as a legitimate file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareOwaAuth | OwaAuth uses the filename owaauth.dll, which is a legitimate file that normally resides in |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSUNBURST | SUNBURST created VBScripts that were named after existing services or folders to blend into legitimate activities. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareREvil | REvil can mimic the names of known executables. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSamurai | Samurai has created the directory `%COMMONPROGRAMFILES%\Microsoft Shared\wmi\` to contain DLLs for loading successive stages. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareUSBStealer | USBStealer mimics a legitimate Russian program called USB Disk Security. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSUPERNOVA | SUPERNOVA has masqueraded as a legitimate SolarWinds DLL. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCyclops Blink | Cyclops Blink can rename its running process to |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareDaserf | Daserf uses file and folder names related to legitimate programs in order to blend in, such as HP, Intel, Adobe, and perflogs. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareDanBot | DanBot files have been named `UltraVNC.exe` and `WINVNC.exe` to appear as legitimate VNC tools. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.