Real-world descriptions of how a group, tool or campaign used a technique.
44 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1070.006 Timestomp |
MalwareBLINDINGCAN | BLINDINGCAN has modified file and directory timestamps. |
| T1070.006 Timestomp |
MalwareNinja | Ninja can change or create the last access or write times. |
| T1070.006 Timestomp |
MalwareStuxnet | Stuxnet extracts and writes driver files that match the times of other legitimate files. |
| T1070.006 Timestomp |
MalwareSEASHARPEE | SEASHARPEE can timestomp files on victims using a Web shell. |
| T1070.006 Timestomp |
MalwareTDTESS | After creating a new service for persistence, TDTESS sets the file creation time for the service to the creation time of the victim's legitimate svchost.exe file. |
| T1070.006 Timestomp |
MalwareMisdat | Many Misdat samples were programmed using Borland Delphi, which will mangle the default PE compile timestamp of a file. |
| T1070.006 Timestomp |
MalwareBankshot | Bankshot modifies the time of a file as specified by the control server. |
| T1070.006 Timestomp |
MalwareUPSTYLE | UPSTYLE restores timestamps to original values following modification. |
| T1070.006 Timestomp |
MalwareBOOKWORM | BOOKWORM has modified file timestamps from the export address table (EAT) to make it difficult to discern when the module was created. |
| T1070.006 Timestomp |
MalwarePingPull | PingPull has the ability to timestomp a file. |
| T1070.006 Timestomp |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware can timestomp files for defense evasion and anti-forensics purposes. |
| T1070.006 Timestomp |
MalwareInvisiMole | InvisiMole samples were timestomped by the authors by setting the PE timestamps to all zero values. InvisiMole also has a built-in command to modify file times. |
| T1070.006 Timestomp |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can time stomp its executable, previously dating it between 2010 to 2021. |
| T1070.006 Timestomp |
MalwareChina Chopper | China Chopper's server component can change the timestamp of files. |
| T1070.006 Timestomp |
MalwareKeyBoy | KeyBoy time-stomped its DLL in order to evade detection. |
| T1070.006 Timestomp |
MalwarePOSHSPY | POSHSPY modifies timestamps of all downloaded executables to match a randomly selected file created prior to 2013. |
| T1070.006 Timestomp |
MalwareMultiLayer Wiper | MultiLayer Wiper changes timestamps of overwritten files to either 1601.1.1 for NTFS filesystems, or 1980.1.1 for all other filesystems. |
| T1070.006 Timestomp |
MalwareElise | Elise performs timestomping of a CAB file it creates. |
| T1070.006 Timestomp |
MalwareGazer | For early Gazer versions, the compilation timestamp was faked. |
| T1070.006 Timestomp |
Malware3PARA RAT | 3PARA RAT has a command to set certain attributes such as creation/modification timestamps on files. |
| T1070.006 Timestomp |
MalwareEVILNUM | EVILNUM has changed the creation date of files. |
| T1070.006 Timestomp |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can change the timestamp of specified filenames. |
| T1070.006 Timestomp |
MalwareShamoon | Shamoon can change the modified time for files to evade forensic detection. |
| T1070.006 Timestomp |
MalwareBPFDoor | BPFDoor uses the `utimes()` function to change the executable's timestamp. |
| T1070.006 Timestomp |
MalwareAttor | Attor has manipulated the time of last access to files and registry keys after they have been created or modified. |
| T1070.006 Timestomp |
MalwareNightClub | NightClub can modify the Creation, Access, and Write timestamps for malicious DLLs to match those of the genuine Windows DLL user32.dll. |
| T1070.006 Timestomp |
MalwareDerusbi | The Derusbi malware supports timestomping. |
| T1070.006 Timestomp |
MalwareKobalos | Kobalos can modify timestamps of replaced files, such as |
| T1070.006 Timestomp |
MalwareHiddenFace | HiddenFace can alter timestamps for directory content on targeted machines. |
| T1070.006 Timestomp |
MalwareOwaAuth | OwaAuth has a command to timestop a file or directory. |
| T1070.006 Timestomp |
MalwareCobalt Strike | Cobalt Strike can timestomp any files or payloads placed on a target machine to help them blend in. |
| T1070.006 Timestomp |
MalwareUSBStealer | USBStealer sets the timestamps of its dropper files to the last-access and last-write timestamps of a standard Windows library chosen on the system. |
| T1070.006 Timestomp |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D can use the |
| T1070.006 Timestomp |
MalwareCyclops Blink | Cyclops Blink has the ability to use the Linux API function `utime` to change the timestamps of modified firmware update images. |
| T1070.006 Timestomp |
MalwareMacMa | MacMa has the capability to create and modify file timestamps. |
| T1070.006 Timestomp |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has updated the timestamp using the `touch` command. |
| T1070.006 Timestomp |
MalwareWinnti for Windows | Winnti for Windows can set the timestamps for its worker and service components to match that of cmd.exe. |
| T1070.006 Timestomp |
MalwarePowerStallion | PowerStallion modifies the MAC times of its local log files to match that of the victim's desktop.ini file. |
| T1070.006 Timestomp |
MalwaremetaMain | metaMain can change the `CreationTime`, `LastAccessTime`, and `LastWriteTime` file time attributes when executed with `SYSTEM` privileges. |
| T1070.006 Timestomp |
MalwarePsylo | Psylo has a command to conduct timestomping by setting a specified file’s timestamps to match those of a system file in the System32 directory. |
| T1070.006 Timestomp |
MalwareGelsemium | Gelsemium has the ability to perform timestomping of files on targeted systems. |
| T1070.006 Timestomp |
MalwareBitPaymer | BitPaymer can modify the timestamp of an executable so that it can be identified and restored by the decryption tool. |
| T1070.006 Timestomp |
MalwareFALLCHILL | FALLCHILL can modify file or directory timestamps. |
| T1070.006 Timestomp |
ToolEmpire | Empire can timestomp any files or payloads placed on a target machine to help them blend in. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.