ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1036.005×

143 examples

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
MalwareEKANS

EKANS has been disguised as update.exe to appear as a valid executable.

T1036.005
Match Legitimate Resource Name or Location
MalwareBLINDINGCAN

BLINDINGCAN has attempted to hide its payload by using legitimate file names such as "iconcache.db".

T1036.005
Match Legitimate Resource Name or Location
MalwareNinja

Ninja has used legitimate looking filenames for its loader including update.dll and x64.dll.

T1036.005
Match Legitimate Resource Name or Location
MalwareBumblebee

Bumblebee has named component DLLs "RapportGP.dll" to match those used by the security company Trusteer.

T1036.005
Match Legitimate Resource Name or Location
MalwareBRICKSTORM

BRICKSTORM has appeared to resemble legitimate processes to include the vCenter process `vami-http`. BRICKSTORM has also leveraged legitimate names of VMware vSphere platform such as `vmsrc` or `vmware-sphere`.

T1036.005
Match Legitimate Resource Name or Location
MalwareNOKKI

NOKKI is written to %LOCALAPPDATA%\MicroSoft Updatea\svServiceUpdate.exe prior being executed in a new process in an apparent attempt to masquerade as a legitimate folder and file.

T1036.005
Match Legitimate Resource Name or Location
MalwareRotaJakiro

RotaJakiro has used the filename `systemd-daemon` in an attempt to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
MalwareChinoxy

Chinoxy has used the name `eoffice.exe` in attempt to appear as a legitimate file.

T1036.005
Match Legitimate Resource Name or Location
MalwareMisdat

Misdat saves itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary.

T1036.005
Match Legitimate Resource Name or Location
MalwareUrsnif

Ursnif has used strings from legitimate system files and existing folders for its file, folder, and Registry entry names.

T1036.005
Match Legitimate Resource Name or Location
MalwareThreatNeedle

ThreatNeedle chooses its payload creation path from a randomly selected service name from netsvc.

T1036.005
Match Legitimate Resource Name or Location
MalwareZLib

ZLib mimics the resource version information of legitimate Realtek Semiconductor, Nvidia, or Synaptics modules.

T1036.005
Match Legitimate Resource Name or Location
MalwareTsundere Botnet

Tsundere Botnet has disguised its MSI installer as a fake installer for popular games and software.

T1036.005
Match Legitimate Resource Name or Location
MalwareFelismus

Felismus has masqueraded as legitimate Adobe Content Management System files.

T1036.005
Match Legitimate Resource Name or Location
MalwareStrongPity

StrongPity has been bundled with legitimate software installation files for disguise.

T1036.005
Match Legitimate Resource Name or Location
MalwareNebulae

Nebulae uses functions named StartUserModeBrowserInjection and StopUserModeBrowserInjection indicating that it's trying to imitate chrome_frame_helper.dll.

T1036.005
Match Legitimate Resource Name or Location
MalwareTONESHELL

TONESHELL has renamed malicious files to mimic legitimate file names and file extensions. TONESHELL has also masqueraded as legitimate file names to include LogMeIn.dll.

T1036.005
Match Legitimate Resource Name or Location
MalwareRainyDay

RainyDay has used names to mimic legitimate software including "vmtoolsd.exe" to spoof Vmtools.

T1036.005
Match Legitimate Resource Name or Location
MalwareAppleSeed

AppleSeed has the ability to rename its payload to ESTCommon.dll to masquerade as a DLL belonging to ESTsecurity.

T1036.005
Match Legitimate Resource Name or Location
MalwareNETWIRE

NETWIRE has masqueraded as legitimate software including TeamViewer and macOS Finder.

T1036.005
Match Legitimate Resource Name or Location
MalwareTinyTurla

TinyTurla has been deployed as `w64time.dll` to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
MalwarePyDCrypt

PyDCrypt has dropped DCSrv under the `svchost.exe` name to disk.

T1036.005
Match Legitimate Resource Name or Location
MalwareJ-magic

J-magic can rename itself as “[nfsiod 0]” to masquerade as the local Network File System (NFS) asynchronous I/O server.

T1036.005
Match Legitimate Resource Name or Location
MalwareOLDBAIT

OLDBAIT installs itself in %ALLUSERPROFILE%\\Application Data\Microsoft\MediaPlayer\updatewindws.exe; the directory name is missing a space and the file name is missing the letter "o."

T1036.005
Match Legitimate Resource Name or Location
MalwareBad Rabbit

Bad Rabbit has masqueraded as a Flash Player installer through the executable file install_flash_player.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareSslMM

To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut.

T1036.005
Match Legitimate Resource Name or Location
MalwareSTATICPLUGIN

STATICPLUGIN has leveraged naming conventions that match legitimate services to include AdobePlugins.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareTEARDROP

TEARDROP files had names that resembled legitimate Window file and directory names.

T1036.005
Match Legitimate Resource Name or Location
MalwareMachete

Machete renamed payloads to masquerade as legitimate Google Chrome, Java, Dropbox, Adobe Reader and Python executables.

T1036.005
Match Legitimate Resource Name or Location
MalwareDUSTPAN

DUSTPAN is often disguised as a legitimate Windows binary such as `w3wp.exe` or `conn.exe`.

T1036.005
Match Legitimate Resource Name or Location
MalwarePUBLOAD

PUBLOAD has renamed malicious files to mimic legitimate file names such as adobe_wf.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareCANONSTAGER

CANONSTAGER has leveraged naming conventions of its malicious DLL to match legitimate services to include cnmpaui.dll which matches the legitimate executable cnmpaui.exe that is aligned with a Canon Ink Jet Printer Assistant Tool.

T1036.005
Match Legitimate Resource Name or Location
MalwareHexEval Loader

HexEval Loader has masqueraded and typosquatted as legitimate code repository packages and projects.

T1036.005
Match Legitimate Resource Name or Location
MalwareCuckoo Stealer

Cuckoo Stealer has copied and renamed itself to DumpMediaSpotifyMusicConverter.

T1036.005
Match Legitimate Resource Name or Location
MalwareInvisiMole

InvisiMole has disguised its droppers as legitimate software or documents, matching their original names and locations, and saved its files as mpr.dll in the Windows folder.

T1036.005
Match Legitimate Resource Name or Location
MalwareCLAIMLOADER

CLAIMLOADER has imitated legitimate software directories through the creation and storage of the EXE and DLL in `C:\ProgramData\` and the use of legitimate looking names of software.

T1036.005
Match Legitimate Resource Name or Location
MalwareQUIETEXIT

QUIETEXIT has attempted to change its name to `cron` upon startup. During incident response, QUIETEXIT samples have been identified that were renamed to blend in with other legitimate files.

T1036.005
Match Legitimate Resource Name or Location
MalwareRDAT

RDAT has masqueraded as VMware.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareSkidmap

Skidmap has created a fake rm binary to replace the legitimate Linux binary.

T1036.005
Match Legitimate Resource Name or Location
MalwareTRANSLATEXT

TRANSLATEXT has been named `GoogleTranslate.crx` to masquerade as a legitimate Chrome extension.

T1036.005
Match Legitimate Resource Name or Location
MalwareSameCoin

SameCoin has named files to appear legitimate such as "MicrosoftEdge.exe."

T1036.005
Match Legitimate Resource Name or Location
MalwareRaindrop

Raindrop was installed under names that resembled legitimate Windows file and directory names.

T1036.005
Match Legitimate Resource Name or Location
MalwareDoki

Doki has disguised a file as a Linux kernel module.

T1036.005
Match Legitimate Resource Name or Location
MalwareRustyWater

RustyWater has used reddit.exe as its file name and a Cloudflare logo.

T1036.005
Match Legitimate Resource Name or Location
MalwareFysbis

Fysbis has masqueraded as trusted software rsyncd and dbus-inotifier.

T1036.005
Match Legitimate Resource Name or Location
MalwareIcedID

IcedID has modified legitimate .dll files to include malicious code.

T1036.005
Match Legitimate Resource Name or Location
MalwareMarkiRAT

MarkiRAT can masquerade as update.exe and svehost.exe; it has also mimicked legitimate Telegram and Chrome files.

T1036.005
Match Legitimate Resource Name or Location
MalwareDarkComet

DarkComet has dropped itself onto victim machines with file names such as WinDefender.Exe and winupdate.exe in an apparent attempt to masquerade as a legitimate file.

T1036.005
Match Legitimate Resource Name or Location
MalwareDRATzarus

DRATzarus has been named `Flash.exe`, and its dropper has been named `IExplorer`.

T1036.005
Match Legitimate Resource Name or Location
MalwareSocGholish

SocGholish has been named `AutoUpdater.js` to mimic legitimate update files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.