ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
MalwareMachete

Machete renamed payloads to masquerade as legitimate Google Chrome, Java, Dropbox, Adobe Reader and Python executables.

T1036.005
Match Legitimate Resource Name or Location
MalwareDUSTPAN

DUSTPAN is often disguised as a legitimate Windows binary such as `w3wp.exe` or `conn.exe`.

T1036.005
Match Legitimate Resource Name or Location
MalwarePUBLOAD

PUBLOAD has renamed malicious files to mimic legitimate file names such as adobe_wf.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareCANONSTAGER

CANONSTAGER has leveraged naming conventions of its malicious DLL to match legitimate services to include cnmpaui.dll which matches the legitimate executable cnmpaui.exe that is aligned with a Canon Ink Jet Printer Assistant Tool.

T1036.005
Match Legitimate Resource Name or Location
MalwareHexEval Loader

HexEval Loader has masqueraded and typosquatted as legitimate code repository packages and projects.

T1036.005
Match Legitimate Resource Name or Location
MalwareCuckoo Stealer

Cuckoo Stealer has copied and renamed itself to DumpMediaSpotifyMusicConverter.

T1036.005
Match Legitimate Resource Name or Location
MalwareInvisiMole

InvisiMole has disguised its droppers as legitimate software or documents, matching their original names and locations, and saved its files as mpr.dll in the Windows folder.

T1036.005
Match Legitimate Resource Name or Location
MalwareCLAIMLOADER

CLAIMLOADER has imitated legitimate software directories through the creation and storage of the EXE and DLL in `C:\ProgramData\` and the use of legitimate looking names of software.

T1036.005
Match Legitimate Resource Name or Location
MalwareQUIETEXIT

QUIETEXIT has attempted to change its name to `cron` upon startup. During incident response, QUIETEXIT samples have been identified that were renamed to blend in with other legitimate files.

T1036.005
Match Legitimate Resource Name or Location
MalwareRDAT

RDAT has masqueraded as VMware.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareSkidmap

Skidmap has created a fake rm binary to replace the legitimate Linux binary.

T1036.005
Match Legitimate Resource Name or Location
MalwareTRANSLATEXT

TRANSLATEXT has been named `GoogleTranslate.crx` to masquerade as a legitimate Chrome extension.

T1036.005
Match Legitimate Resource Name or Location
MalwareSameCoin

SameCoin has named files to appear legitimate such as "MicrosoftEdge.exe."

T1036.005
Match Legitimate Resource Name or Location
MalwareRaindrop

Raindrop was installed under names that resembled legitimate Windows file and directory names.

T1036.005
Match Legitimate Resource Name or Location
MalwareDoki

Doki has disguised a file as a Linux kernel module.

T1036.005
Match Legitimate Resource Name or Location
MalwareRustyWater

RustyWater has used reddit.exe as its file name and a Cloudflare logo.

T1036.005
Match Legitimate Resource Name or Location
MalwareFysbis

Fysbis has masqueraded as trusted software rsyncd and dbus-inotifier.

T1036.005
Match Legitimate Resource Name or Location
MalwareIcedID

IcedID has modified legitimate .dll files to include malicious code.

T1036.005
Match Legitimate Resource Name or Location
MalwareMarkiRAT

MarkiRAT can masquerade as update.exe and svehost.exe; it has also mimicked legitimate Telegram and Chrome files.

T1036.005
Match Legitimate Resource Name or Location
MalwareDarkComet

DarkComet has dropped itself onto victim machines with file names such as WinDefender.Exe and winupdate.exe in an apparent attempt to masquerade as a legitimate file.

T1036.005
Match Legitimate Resource Name or Location
MalwareDRATzarus

DRATzarus has been named `Flash.exe`, and its dropper has been named `IExplorer`.

T1036.005
Match Legitimate Resource Name or Location
MalwareSocGholish

SocGholish has been named `AutoUpdater.js` to mimic legitimate update files.

T1036.005
Match Legitimate Resource Name or Location
MalwareGreen Lambert

Green Lambert has been disguised as a Growl help file.

T1036.005
Match Legitimate Resource Name or Location
MalwarePUNCHBUGGY

PUNCHBUGGY mimics filenames from %SYSTEM%\System32 to hide DLLs in %WINDIR% and/or %TEMP%.

T1036.005
Match Legitimate Resource Name or Location
MalwareGoldMax

GoldMax has used filenames that matched the system name, and appeared as a scheduled task impersonating systems management software within the corresponding ProgramData subfolder.

T1036.005
Match Legitimate Resource Name or Location
MalwarePlugX

PlugX has been disguised as legitimate Adobe and PotPlayer files. PlugX has also imitated legitimate software directories and file names through the creation and storage of a legitimate EXE and the malicious DLLs.

T1036.005
Match Legitimate Resource Name or Location
MalwareBisonal

Bisonal has renamed malicious code to `msacm32.dll` to hide within a legitimate library; earlier versions were disguised as `winhelp`.

T1036.005
Match Legitimate Resource Name or Location
MalwareS-Type

S-Type may save itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary.

T1036.005
Match Legitimate Resource Name or Location
MalwareRemsec

The Remsec loader implements itself with the name Security Support Provider, a legitimate Windows function. Various Remsec .exe files mimic legitimate file names used by Microsoft, Symantec, Kaspersky, Hewlett-Packard, and VMWare. Remsec also disguised malicious modules using similar filenames as custom network encryption software on victims.

T1036.005
Match Legitimate Resource Name or Location
MalwareLightNeuron

LightNeuron has used filenames associated with Exchange and Outlook for binary and configuration files, such as winmail.dat.

T1036.005
Match Legitimate Resource Name or Location
MalwareCuba

Cuba has been disguised as legitimate 360 Total Security Antivirus and OpenVPN programs.

T1036.005
Match Legitimate Resource Name or Location
MalwarePureCrypter

PureCrypter has used multiple file names to appear legitimate such as firefox\firefox.exe, Google\chrome.exe, and Taskmgr.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareThiefQuest

ThiefQuest prepends a copy of itself to the beginning of an executable file while maintaining the name of the executable.

T1036.005
Match Legitimate Resource Name or Location
MalwareFoggyWeb

FoggyWeb can be disguised as a Visual Studio file such as `Windows.Data.TimeZones.zh-PH.pri` to evade detection. Also, FoggyWeb's loader can mimic a genuine `dll` file that carries out the same import functions as the legitimate Windows `version.dll` file.

T1036.005
Match Legitimate Resource Name or Location
MalwareElise

If installing itself as a service fails, Elise instead writes itself as a file named svchost.exe saved in %APPDATA%\Microsoft\Network.

T1036.005
Match Legitimate Resource Name or Location
MalwareLatrodectus

Latrodectus has been packed to appear as a component to Bitdefender’s kernel-mode driver, TRUFOS.SYS.

T1036.005
Match Legitimate Resource Name or Location
MalwareSaint Bot

Saint Bot has been disguised as a legitimate executable, including as Windows SDK.

T1036.005
Match Legitimate Resource Name or Location
MalwareChaes

Chaes has used an unsigned, crafted DLL module named hha.dll that was designed to look like a legitimate 32-bit Windows DLL.

T1036.005
Match Legitimate Resource Name or Location
MalwareBundlore

Bundlore has disguised a malicious .app file as a Flash Player update.

T1036.005
Match Legitimate Resource Name or Location
MalwareFooder

Fooder has frequently masqueraded as the Snake game, using strings such as “Welcome to snake Game” and mutexes such as “SNAKE_G.”

T1036.005
Match Legitimate Resource Name or Location
MalwareQUADAGENT

QUADAGENT used the PowerShell filenames Office365DCOMCheck.ps1 and SystemDiskClean.ps1.

T1036.005
Match Legitimate Resource Name or Location
MalwareTAINTEDSCRIBE

The TAINTEDSCRIBE main executable has disguised itself as Microsoft’s Narrator.

T1036.005
Match Legitimate Resource Name or Location
MalwareMetamorfo

Metamorfo has disguised an MSI file as the Adobe Acrobat Reader Installer and has masqueraded payloads as OneDrive, WhatsApp, or Spotify, for example.

T1036.005
Match Legitimate Resource Name or Location
MalwarePipeMon

PipeMon modules are stored on disk with seemingly benign names including use of a file extension associated with a popular word processor.

T1036.005
Match Legitimate Resource Name or Location
MalwareMagicRAT

MagicRAT stores configuration data in files and file paths mimicking legitimate operating system resources.

T1036.005
Match Legitimate Resource Name or Location
MalwareKONNI

KONNI has created a shortcut called "Anti virus service.lnk" in an apparent attempt to masquerade as a legitimate file.

T1036.005
Match Legitimate Resource Name or Location
MalwareKGH_SPY

KGH_SPY has masqueraded as a legitimate Windows tool.

T1036.005
Match Legitimate Resource Name or Location
MalwareIxeshe

Ixeshe has used registry values and file names associated with Adobe software, such as AcroRd32.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareBlack Basta

The Black Basta dropper has mimicked an application for creating USB bootable drivers.

T1036.005
Match Legitimate Resource Name or Location
MalwareNightClub

NightClub has chosen file names to appear legitimate including EsetUpdate-0117583943.exe for its dropper.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.