ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1070.006×

44 examples

TechniqueUsed byProcedure example
T1070.006
Timestomp
MalwareBLINDINGCAN

BLINDINGCAN has modified file and directory timestamps.

T1070.006
Timestomp
MalwareNinja

Ninja can change or create the last access or write times.

T1070.006
Timestomp
MalwareStuxnet

Stuxnet extracts and writes driver files that match the times of other legitimate files.

T1070.006
Timestomp
MalwareSEASHARPEE

SEASHARPEE can timestomp files on victims using a Web shell.

T1070.006
Timestomp
MalwareTDTESS

After creating a new service for persistence, TDTESS sets the file creation time for the service to the creation time of the victim's legitimate svchost.exe file.

T1070.006
Timestomp
MalwareMisdat

Many Misdat samples were programmed using Borland Delphi, which will mangle the default PE compile timestamp of a file.

T1070.006
Timestomp
MalwareBankshot

Bankshot modifies the time of a file as specified by the control server.

T1070.006
Timestomp
MalwareUPSTYLE

UPSTYLE restores timestamps to original values following modification.

T1070.006
Timestomp
MalwareBOOKWORM

BOOKWORM has modified file timestamps from the export address table (EAT) to make it difficult to discern when the module was created.

T1070.006
Timestomp
MalwarePingPull

PingPull has the ability to timestomp a file.

T1070.006
Timestomp
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware can timestomp files for defense evasion and anti-forensics purposes.

T1070.006
Timestomp
MalwareInvisiMole

InvisiMole samples were timestomped by the authors by setting the PE timestamps to all zero values. InvisiMole also has a built-in command to modify file times.

T1070.006
Timestomp
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can time stomp its executable, previously dating it between 2010 to 2021.

T1070.006
Timestomp
MalwareChina Chopper

China Chopper's server component can change the timestamp of files.

T1070.006
Timestomp
MalwareKeyBoy

KeyBoy time-stomped its DLL in order to evade detection.

T1070.006
Timestomp
MalwarePOSHSPY

POSHSPY modifies timestamps of all downloaded executables to match a randomly selected file created prior to 2013.

T1070.006
Timestomp
MalwareMultiLayer Wiper

MultiLayer Wiper changes timestamps of overwritten files to either 1601.1.1 for NTFS filesystems, or 1980.1.1 for all other filesystems.

T1070.006
Timestomp
MalwareElise

Elise performs timestomping of a CAB file it creates.

T1070.006
Timestomp
MalwareGazer

For early Gazer versions, the compilation timestamp was faked.

T1070.006
Timestomp
Malware3PARA RAT

3PARA RAT has a command to set certain attributes such as creation/modification timestamps on files.

T1070.006
Timestomp
MalwareEVILNUM

EVILNUM has changed the creation date of files.

T1070.006
Timestomp
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can change the timestamp of specified filenames.

T1070.006
Timestomp
MalwareShamoon

Shamoon can change the modified time for files to evade forensic detection.

T1070.006
Timestomp
MalwareBPFDoor

BPFDoor uses the `utimes()` function to change the executable's timestamp.

T1070.006
Timestomp
MalwareAttor

Attor has manipulated the time of last access to files and registry keys after they have been created or modified.

T1070.006
Timestomp
MalwareNightClub

NightClub can modify the Creation, Access, and Write timestamps for malicious DLLs to match those of the genuine Windows DLL user32.dll.

T1070.006
Timestomp
MalwareDerusbi

The Derusbi malware supports timestomping.

T1070.006
Timestomp
MalwareKobalos

Kobalos can modify timestamps of replaced files, such as ssh with the added credential stealer or sshd used to deploy Kobalos.

T1070.006
Timestomp
MalwareHiddenFace

HiddenFace can alter timestamps for directory content on targeted machines.

T1070.006
Timestomp
MalwareOwaAuth

OwaAuth has a command to timestop a file or directory.

T1070.006
Timestomp
MalwareCobalt Strike

Cobalt Strike can timestomp any files or payloads placed on a target machine to help them blend in.

T1070.006
Timestomp
MalwareUSBStealer

USBStealer sets the timestamps of its dropper files to the last-access and last-write timestamps of a standard Windows library chosen on the system.

T1070.006
Timestomp
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D can use the touch -t command to change timestamps.

T1070.006
Timestomp
MalwareCyclops Blink

Cyclops Blink has the ability to use the Linux API function `utime` to change the timestamps of modified firmware update images.

T1070.006
Timestomp
MalwareMacMa

MacMa has the capability to create and modify file timestamps.

T1070.006
Timestomp
MalwareSPAWNCHIMERA

SPAWNCHIMERA has updated the timestamp using the `touch` command.

T1070.006
Timestomp
MalwareWinnti for Windows

Winnti for Windows can set the timestamps for its worker and service components to match that of cmd.exe.

T1070.006
Timestomp
MalwarePowerStallion

PowerStallion modifies the MAC times of its local log files to match that of the victim's desktop.ini file.

T1070.006
Timestomp
MalwaremetaMain

metaMain can change the `CreationTime`, `LastAccessTime`, and `LastWriteTime` file time attributes when executed with `SYSTEM` privileges.

T1070.006
Timestomp
MalwarePsylo

Psylo has a command to conduct timestomping by setting a specified file’s timestamps to match those of a system file in the System32 directory.

T1070.006
Timestomp
MalwareGelsemium

Gelsemium has the ability to perform timestomping of files on targeted systems.

T1070.006
Timestomp
MalwareBitPaymer

BitPaymer can modify the timestamp of an executable so that it can be identified and restored by the decryption tool.

T1070.006
Timestomp
MalwareFALLCHILL

FALLCHILL can modify file or directory timestamps.

T1070.006
Timestomp
ToolEmpire

Empire can timestomp any files or payloads placed on a target machine to help them blend in.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.