Indicator Removal from Tools

T1027.005

Sub-technique of T1027 Obfuscated Files or Information.View on attack.mitre.org

About this technique

Adversaries may remove indicators from tools if they believe their malicious tool was detected, quarantined, or otherwise curtailed. They can modify the tool by removing the indicator and using the updated version that is no longer detected by the target's defensive systems or subsequent targets that may use similar systems.

A good example of this is when malware is detected with a file signature and quarantined by anti-virus software. An adversary who can determine that the malware was quarantined because of its file signature may modify the file to explicitly avoid that signature, and then re-use the malware.

Detection rules6

Rules on DetectionCode tagged with T1027.005.

Sigma4

RuleLevelLog source
HackTool - CrackMapExec PowerShell Obfuscationhighwindows / process_creation
PUA - DefenderCheck Executionhighwindows / process_creation
Potential Secure Deletion with SDeletemediumwindows / NULL
PUA - Potential PE Metadata Tamper Using Rceditmediumwindows / process_creation

Splunk2

RuleTypeRiskData source
Powershell Creating Thread MutexTTPNULLPowershell Script Block Logging 4104
Powershell Enable SMB1Protocol FeatureTTPNULLPowershell Script Block Logging 4104

Groups7

Software9

Campaigns2

Procedure examples18

Groups7

Used byProcedure example
GroupAPT3

APT3 has been known to remove indicators of compromise from tools.

GroupDeep Panda

Deep Panda has updated and modified its malware, resulting in different hash values that evade detection.

GroupGALLIUM

GALLIUM ensured each payload had a unique hash, including by using different types of packers.

GroupOilRig

OilRig has tested malware samples to determine AV detection and subsequently modified the samples to ensure AV evasion.

GroupPatchwork

Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes.

GroupTurla

Based on comparison of Gazer versions, Turla made an effort to obfuscate strings in the malware that could be used as IoCs, including the mutex name and named pipe.

GroupUNC3886

UNC3886 has replaced atomic indicators mentioned in threat intelligence publications, sometimes as quickly as under a week after release.

Software9

Used byProcedure example
MalwareCobalt Strike

Cobalt Strike includes a capability to modify the Beacon payload to eliminate known signatures or unpacking methods.

MalwareDaserf

Analysis of Daserf has shown that it regularly undergoes technical improvements to evade anti-virus detection.

MalwareGravityRAT

The author of GravityRAT submitted samples to VirusTotal for testing, showing that the author modified the code to try to hide the DDE object in a different part of the document.

MalwareInvisiMole

InvisiMole has undergone regular technical improvements in an attempt to evade detection.

MalwarePenquin

Penquin can remove strings from binaries.

ToolPowerSploit

PowerSploit's Find-AVSignature AntivirusBypass module can be used to locate single byte anti-virus signatures.

MalwareQakBot

QakBot can make small changes to itself in order to change its checksum and hash value.

MalwareSUNBURST

SUNBURST source code used generic variable names and pre-obfuscated strings, and was likely sanitized of developer comments before being added to SUNSPOT.

View all 9 software examples

Campaigns2

Used byProcedure example
CampaignOperation Wocao

During Operation Wocao, threat actors edited variable names within the Impacket suite to avoid automated detection.

CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles modified files based on the open-source project cryptcat in an apparent attempt to decrease anti-virus detection rates.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.