ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1036.005×

143 examples

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
MalwareCalisto

Calisto's installation file is an unsigned DMG image under the guise of Intego’s security solution for mac.

T1036.005
Match Legitimate Resource Name or Location
MalwareGoldenSpy

GoldenSpy's setup file installs initial executables under the folder %WinDir%\System32\PluginManager.

T1036.005
Match Legitimate Resource Name or Location
MalwareRamsay

Ramsay has masqueraded as a 7zip installer.

T1036.005
Match Legitimate Resource Name or Location
MalwareAshTag

AshTag has masqueraded as a legitimate VisualServer utility.

T1036.005
Match Legitimate Resource Name or Location
MalwareCarberp

Carberp has masqueraded as Windows system file names, as well as "chkntfs.exe" and "syscron.exe".

T1036.005
Match Legitimate Resource Name or Location
MalwareSUNSPOT

SUNSPOT was identified on disk with a filename of taskhostsvc.exe and it created an encrypted log file at C:\Windows\Temp\vmware-vmdmp.log.

T1036.005
Match Legitimate Resource Name or Location
MalwareOutSteel

OutSteel attempts to download and execute Saint Bot to a statically-defined location attempting to mimic svchost: %TEMP%\\svjhost.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareBackConfig

BackConfig has hidden malicious payloads in %USERPROFILE%\Adobe\Driver\dwg\ and mimicked the legitimate DHCP service binary.

T1036.005
Match Legitimate Resource Name or Location
MalwarePowGoop

PowGoop has used a DLL named Goopdate.dll to impersonate a legitimate Google update file.

T1036.005
Match Legitimate Resource Name or Location
MalwareLAMEHUG

LAMEHUG payloads have been disguised with legitimate looking filenames including AI_generator_uncensored_Canvas_PRO_v0.9.exe and AI_image_generator_v0.95.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareInnaputRAT

InnaputRAT variants have attempted to appear legitimate by using the file names SafeApp.exe and NeutralApp.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareLookBack

LookBack has a C2 proxy tool that masquerades as GUP.exe, which is software used by Notepad++.

T1036.005
Match Legitimate Resource Name or Location
MalwarePenquin

Penquin has mimicked the Cron binary to hide itself on compromised systems.

T1036.005
Match Legitimate Resource Name or Location
MalwareWinnti for Windows

A Winnti for Windows implant file was named ASPNET_FILTER.DLL, mimicking the legitimate ASP.NET ISAPI filter DLL with the same name.

T1036.005
Match Legitimate Resource Name or Location
MalwareTroll Stealer

Troll Stealer is typically installed via a dropper file that masquerades as a legitimate security program installation file.

T1036.005
Match Legitimate Resource Name or Location
MalwareChChes

ChChes copies itself to an .exe file with a filename that is likely intended to imitate Norton Antivirus but has several letters reversed (e.g. notron.exe).

T1036.005
Match Legitimate Resource Name or Location
MalwareANDROMEDA

ANDROMEDA has been installed to `C:\Temp\TrustedInstaller.exe` to mimic a legitimate Windows installer service.

T1036.005
Match Legitimate Resource Name or Location
MalwareIceApple

IceApple .NET assemblies have used `App_Web_` in their file names to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
MalwareShai-Hulud

Shai-Hulud has masqueraded as a legitimate Bun installer.

T1036.005
Match Legitimate Resource Name or Location
MalwareVIRTUALPITA

VIRTUALPITA samples have been found in `/usr/libexec/setconf/ksmd` and `/usr/bin/ksmd`, named to spoof the legitimate Kernel Same-Page Merging Daemon binary.

T1036.005
Match Legitimate Resource Name or Location
MalwareKOCTOPUS

KOCTOPUS has been disguised as legitimate software programs associated with the travel and airline industries.

T1036.005
Match Legitimate Resource Name or Location
MalwareMechaFlounder

MechaFlounder has been downloaded as a file named lsass.exe, which matches the legitimate Windows file.

T1036.005
Match Legitimate Resource Name or Location
MalwareHTTPBrowser

HTTPBrowser's installer contains a malicious file named navlu.dll to decrypt and run the RAT. navlu.dll is also the name of a legitimate Symantec DLL.

T1036.005
Match Legitimate Resource Name or Location
MalwareMis-Type

Mis-Type saves itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary.

T1036.005
Match Legitimate Resource Name or Location
MalwareOctopus

Octopus has been disguised as legitimate programs, such as Java and Telegram Messenger.

T1036.005
Match Legitimate Resource Name or Location
MalwareQilin

Qilin has named its payload file TeamViewer_Host_Setup to disguise itself as a legitimate TeamViewer file.

T1036.005
Match Legitimate Resource Name or Location
MalwareBADNEWS

BADNEWS attempts to hide its payloads using legitimate filenames.

T1036.005
Match Legitimate Resource Name or Location
MalwareGoopy

Goopy has impersonated the legitimate goopdate.dll, which was dropped on the target system with a legitimate GoogleUpdate.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareGelsemium

Gelsemium has named malicious binaries `serv.exe`, `winprint.dll`, and `chrome_elf.dll` and has set its persistence in the Registry with the key value Chrome Update to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
MalwareOSX/Shlayer

OSX/Shlayer can masquerade as a Flash Player update.

T1036.005
Match Legitimate Resource Name or Location
MalwareDtrack

One of Dtrack can hide in replicas of legitimate programs like OllyDbg, 7-Zip, and FileZilla.

T1036.005
Match Legitimate Resource Name or Location
MalwareStrifeWater

StrifeWater has been named `calc.exe` to appear as a legitimate calculator program.

T1036.005
Match Legitimate Resource Name or Location
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has mimicked the names of known executables, such as mediaplayer.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareXORIndex Loader

XORIndex Loader has leveraged legitimate package names to mimic frequently utilized tools to entice victims to download and execute malicious payloads.

T1036.005
Match Legitimate Resource Name or Location
MalwareSmall Sieve

Small Sieve can use variations of Microsoft and Outlook spellings, such as "Microsift", in its file names to avoid detection.

T1036.005
Match Legitimate Resource Name or Location
MalwareHermeticWizard

HermeticWizard has been named `exec_32.dll` to mimic a legitimate MS Outlook .dll.

T1036.005
Match Legitimate Resource Name or Location
ToolShimRatReporter

ShimRatReporter spoofed itself as AlphaZawgyl_font.exe, a specialized Unicode font.

T1036.005
Match Legitimate Resource Name or Location
ToolPcShare

PcShare has been named `wuauclt.exe` to appear as the legitimate Windows Update AutoUpdate Client.

T1036.005
Match Legitimate Resource Name or Location
ToolBrute Ratel C4

Brute Ratel C4 has used a payload file named OneDrive.update to appear benign.

T1036.005
Match Legitimate Resource Name or Location
ToolMCMD

MCMD has been named Readme.txt to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has installed a backdoor named sysmon.py on targeted systems.

T1036.005
Match Legitimate Resource Name or Location
MalwareMini Shai-Hulud

Mini Shai-Hulud has leveraged a user-agent string that mimics a standard git client to avoid detection within network logs.

T1036.005
Match Legitimate Resource Name or Location
MalwareCanisterWorm

CanisterWorm has mimicked legitimate PostgreSQL components (pgmon, pglog, and .pg_state) to masquerade malicious files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.