Sub-technique of T1036 Masquerading.View on attack.mitre.org
Adversaries may rename legitimate / system utilities to try to evade security mechanisms concerning the usage of those utilities. Security monitoring and control mechanisms may be in place for legitimate utilities adversaries are capable of abusing, including both built-in binaries and tools such as PSExec, AutoHotKey, and IronPython. It may be possible to bypass those security mechanisms by renaming the utility prior to utilization (ex: rename rundll32.exe). An alternative case occurs when a legitimate utility is copied or moved to a different directory and renamed to avoid detections based on these utilities executing from non-standard paths.
Rules on DetectionCode tagged with T1036.003.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Execution of File with Multiple Extensions | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Execution of File With Spaces Before Extension | TTP | NULL | Sysmon EventID 1 |
| Suspicious Copy on System32 | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Suspicious microsoft workflow compiler rename | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Suspicious msbuild path | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Suspicious MSBuild Rename | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Suspicious Rundll32 Rename | Hunting | NULL | Sysmon EventID 1 |
| System Processes Run From Unexpected Locations | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows DotNet Binary in Non Standard Path | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows InstallUtil in Non Standard Path | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows LOLBAS Executed As Renamed File | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Renamed Powershell Execution | TTP | NULL | Sysmon EventID 1 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT32 | APT32 has moved and renamed pubprn.vbs to a .txt file to avoid detection. |
| GroupAPT38 | APT38 has renamed system utilities, such as `rundll32.exe` and `mshta.exe`, to avoid detection. |
| GroupDaggerfly | Daggerfly used a renamed version of rundll32.exe, such as "dbengin.exe" located in the `ProgramData\Microsoft\PlayReady` directory, to proxy malicious DLL execution. |
| GroupGALLIUM | GALLIUM used a renamed cmd.exe file to evade detection. |
| GroupLazarus Group | Lazarus Group has renamed system utilities such as |
| GroupmenuPass | menuPass has renamed certutil and moved it to a different location on the system to avoid detection based on use of the tool. |
| Used by | Procedure example |
|---|---|
| MalwareCozyCar | The CozyCar dropper has masqueraded a copy of the infected system's rundll32.exe executable that was moved to the malware's install directory and renamed according to a predefined configuration file. |
| MalwareDarkGate | DarkGate executes a Windows Batch script during installation that creases a randomly-named directory in the |
| MalwareKevin | Kevin has renamed an image of `cmd.exe` with a random name followed by a `.tmpl` extension. |
| MalwarePHASEJAM | PHASEJAM has renamed the file `/home/bin/remotedebug` to `remotedebug.bak`, allowing the threats actors to write a malicious `/home/bin/remotedebug` shell script. |
| MalwareStrelaStealer | StrelaStealer has used a renamed, legitimate `msinfo32.exe` executable to sideload the StrelaStealer payload during initial installation. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.