ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1070.006×

11 examples

TechniqueUsed byProcedure example
T1070.006
Timestomp
GroupAPT38

APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.

T1070.006
Timestomp
GroupKimsuky

Kimsuky has manipulated timestamps for creation or compilation dates to defeat anti-forensics.

T1070.006
Timestomp
GroupAPT32

APT32 has used scheduled task raw XML with a backdated timestamp of June 2, 2016. The group has also set the creation time of the files dropped by the second stage of the exploit to match the creation time of kernel32.dll. Additionally, APT32 has used a random value to modify the timestamp of the file storing the clientID.

T1070.006
Timestomp
GroupMustang Panda

Mustang Panda has modified file timestamps from the export address table (EAT) in malware to make it difficult to identify creation times.

T1070.006
Timestomp
GroupRocke

Rocke has changed the time stamp of certain files.

T1070.006
Timestomp
GroupUNC3886

UNC3886 has used scripts to timestomp ESXi hosts prior to installing malicious vSphere Installation Bundles (VIBs).

T1070.006
Timestomp
GroupAPT29

APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory.

T1070.006
Timestomp
GroupChimera

Chimera has used a Windows version of the Linux touch command to modify the date and time stamp on DLLs.

T1070.006
Timestomp
GroupAPT28

APT28 has performed timestomping on victim files.

T1070.006
Timestomp
GroupAPT5

APT5 has modified file timestamps.

T1070.006
Timestomp
GroupLazarus Group

Several Lazarus Group malware families use timestomping, including modifying the last write timestamp of a specified Registry key to a random date, as well as copying the timestamp for legitimate .exe files (such as calc.exe or mspaint.exe) to its dropped files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.