Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMachete | Machete renamed payloads to masquerade as legitimate Google Chrome, Java, Dropbox, Adobe Reader and Python executables. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareDUSTPAN | DUSTPAN is often disguised as a legitimate Windows binary such as `w3wp.exe` or `conn.exe`. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePUBLOAD | PUBLOAD has renamed malicious files to mimic legitimate file names such as adobe_wf.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCANONSTAGER | CANONSTAGER has leveraged naming conventions of its malicious DLL to match legitimate services to include cnmpaui.dll which matches the legitimate executable cnmpaui.exe that is aligned with a Canon Ink Jet Printer Assistant Tool. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareHexEval Loader | HexEval Loader has masqueraded and typosquatted as legitimate code repository packages and projects. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCuckoo Stealer | Cuckoo Stealer has copied and renamed itself to DumpMediaSpotifyMusicConverter. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareInvisiMole | InvisiMole has disguised its droppers as legitimate software or documents, matching their original names and locations, and saved its files as mpr.dll in the Windows folder. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCLAIMLOADER | CLAIMLOADER has imitated legitimate software directories through the creation and storage of the EXE and DLL in `C:\ProgramData\` and the use of legitimate looking names of software. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareQUIETEXIT | QUIETEXIT has attempted to change its name to `cron` upon startup. During incident response, QUIETEXIT samples have been identified that were renamed to blend in with other legitimate files. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRDAT | RDAT has masqueraded as VMware.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSkidmap | Skidmap has created a fake |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTRANSLATEXT | TRANSLATEXT has been named `GoogleTranslate.crx` to masquerade as a legitimate Chrome extension. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSameCoin | SameCoin has named files to appear legitimate such as "MicrosoftEdge.exe." |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRaindrop | Raindrop was installed under names that resembled legitimate Windows file and directory names. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareDoki | Doki has disguised a file as a Linux kernel module. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRustyWater | RustyWater has used reddit.exe as its file name and a Cloudflare logo. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareFysbis | Fysbis has masqueraded as trusted software rsyncd and dbus-inotifier. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareIcedID | IcedID has modified legitimate .dll files to include malicious code. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMarkiRAT | MarkiRAT can masquerade as |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareDarkComet | DarkComet has dropped itself onto victim machines with file names such as WinDefender.Exe and winupdate.exe in an apparent attempt to masquerade as a legitimate file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareDRATzarus | DRATzarus has been named `Flash.exe`, and its dropper has been named `IExplorer`. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSocGholish | SocGholish has been named `AutoUpdater.js` to mimic legitimate update files. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGreen Lambert | Green Lambert has been disguised as a Growl help file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePUNCHBUGGY | PUNCHBUGGY mimics filenames from %SYSTEM%\System32 to hide DLLs in %WINDIR% and/or %TEMP%. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGoldMax | GoldMax has used filenames that matched the system name, and appeared as a scheduled task impersonating systems management software within the corresponding ProgramData subfolder. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePlugX | PlugX has been disguised as legitimate Adobe and PotPlayer files. PlugX has also imitated legitimate software directories and file names through the creation and storage of a legitimate EXE and the malicious DLLs. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBisonal | Bisonal has renamed malicious code to `msacm32.dll` to hide within a legitimate library; earlier versions were disguised as `winhelp`. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareS-Type | S-Type may save itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRemsec | The Remsec loader implements itself with the name Security Support Provider, a legitimate Windows function. Various Remsec .exe files mimic legitimate file names used by Microsoft, Symantec, Kaspersky, Hewlett-Packard, and VMWare. Remsec also disguised malicious modules using similar filenames as custom network encryption software on victims. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareLightNeuron | LightNeuron has used filenames associated with Exchange and Outlook for binary and configuration files, such as |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCuba | Cuba has been disguised as legitimate 360 Total Security Antivirus and OpenVPN programs. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePureCrypter | PureCrypter has used multiple file names to appear legitimate such as firefox\firefox.exe, Google\chrome.exe, and Taskmgr.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareThiefQuest | ThiefQuest prepends a copy of itself to the beginning of an executable file while maintaining the name of the executable. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareFoggyWeb | FoggyWeb can be disguised as a Visual Studio file such as `Windows.Data.TimeZones.zh-PH.pri` to evade detection. Also, FoggyWeb's loader can mimic a genuine `dll` file that carries out the same import functions as the legitimate Windows `version.dll` file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareElise | If installing itself as a service fails, Elise instead writes itself as a file named svchost.exe saved in %APPDATA%\Microsoft\Network. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareLatrodectus | Latrodectus has been packed to appear as a component to Bitdefender’s kernel-mode driver, TRUFOS.SYS. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSaint Bot | Saint Bot has been disguised as a legitimate executable, including as Windows SDK. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareChaes | Chaes has used an unsigned, crafted DLL module named |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBundlore | Bundlore has disguised a malicious .app file as a Flash Player update. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareFooder | Fooder has frequently masqueraded as the Snake game, using strings such as “Welcome to snake Game” and mutexes such as “SNAKE_G.” |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareQUADAGENT | QUADAGENT used the PowerShell filenames |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTAINTEDSCRIBE | The TAINTEDSCRIBE main executable has disguised itself as Microsoft’s Narrator. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMetamorfo | Metamorfo has disguised an MSI file as the Adobe Acrobat Reader Installer and has masqueraded payloads as OneDrive, WhatsApp, or Spotify, for example. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePipeMon | PipeMon modules are stored on disk with seemingly benign names including use of a file extension associated with a popular word processor. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMagicRAT | MagicRAT stores configuration data in files and file paths mimicking legitimate operating system resources. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareKONNI | KONNI has created a shortcut called "Anti virus service.lnk" in an apparent attempt to masquerade as a legitimate file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareKGH_SPY | KGH_SPY has masqueraded as a legitimate Windows tool. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareIxeshe | Ixeshe has used registry values and file names associated with Adobe software, such as AcroRd32.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBlack Basta | The Black Basta dropper has mimicked an application for creating USB bootable drivers. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareNightClub | NightClub has chosen file names to appear legitimate including EsetUpdate-0117583943.exe for its dropper. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.