Timestomp

T1070.006

Sub-technique of T1070 Indicator Removal.View on attack.mitre.org

About this technique

Adversaries may modify file time attributes to hide new files or changes to existing files. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change times), often to mimic files that are in the same folder and blend malicious files with legitimate files.

In Windows systems, both the `$STANDARD_INFORMATION` (`$SI`) and `$FILE_NAME` (`$FN`) attributes record times in a Master File Table (MFT) file. `$SI` (dates/time stamps) is displayed to the end user, including in the File System view, while `$FN` is dealt with by the kernel.

Modifying the `$SI` attribute is the most common method of timestomping because it can be modified at the user level using API calls. `$FN` timestomping, however, typically requires interacting with the system kernel or moving or renaming a file.

Adversaries modify timestamps on files so that they do not appear conspicuous to forensic investigators or file analysis tools. In order to evade detections that rely on identifying discrepancies between the `$SI` and `$FN` attributes, adversaries may also engage in “double timestomping” by modifying times on both attributes simultaneously.

In Linux systems and on ESXi servers, threat actors may attempt to perform timestomping using commands such as `touch -a -m -t <timestamp> <filename>` (which sets access and modification times to a specific value) or `touch -r <filename> <filename>` (which sets access and modification times to match those of another file).

Timestomping may be used along with file name Masquerading to hide malware and tools.

Detection rules7

Rules on DetectionCode tagged with T1070.006.

Sigma6

RuleLevelLog source
File Creation Date Changed to Another Yearhighwindows / file_change
File Time Attribute Changemediummacos / process_creation
File Time Attribute Change - Linuxmediumlinux / NULL
Powershell Timestompmediumwindows / ps_script
Touch Suspicious Service Filemediumlinux / process_creation
Unauthorized System Time Modificationlowwindows / NULL

Splunk1

RuleTypeRiskData source
ESXi System Clock ManipulationTTPNULLVMWare ESXi Syslog

Groups11

Software44

Show 20 more

Campaigns3

Procedure examples58

Groups11

Used byProcedure example
GroupAPT28

APT28 has performed timestomping on victim files.

GroupAPT29

APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory.

GroupAPT32

APT32 has used scheduled task raw XML with a backdated timestamp of June 2, 2016. The group has also set the creation time of the files dropped by the second stage of the exploit to match the creation time of kernel32.dll. Additionally, APT32 has used a random value to modify the timestamp of the file storing the clientID.

GroupAPT38

APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.

GroupAPT5

APT5 has modified file timestamps.

GroupChimera

Chimera has used a Windows version of the Linux touch command to modify the date and time stamp on DLLs.

GroupKimsuky

Kimsuky has manipulated timestamps for creation or compilation dates to defeat anti-forensics.

GroupLazarus Group

Several Lazarus Group malware families use timestomping, including modifying the last write timestamp of a specified Registry key to a random date, as well as copying the timestamp for legitimate .exe files (such as calc.exe or mspaint.exe) to its dropped files.

View all 11 groups examples

Software44

Used byProcedure example
Malware3PARA RAT

3PARA RAT has a command to set certain attributes such as creation/modification timestamps on files.

MalwareAttor

Attor has manipulated the time of last access to files and registry keys after they have been created or modified.

MalwareBankshot

Bankshot modifies the time of a file as specified by the control server.

MalwareBitPaymer

BitPaymer can modify the timestamp of an executable so that it can be identified and restored by the decryption tool.

MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware can timestomp files for defense evasion and anti-forensics purposes.

MalwareBLINDINGCAN

BLINDINGCAN has modified file and directory timestamps.

MalwareBOOKWORM

BOOKWORM has modified file timestamps from the export address table (EAT) to make it difficult to discern when the module was created.

MalwareBPFDoor

BPFDoor uses the `utimes()` function to change the executable's timestamp.

View all 44 software examples

Campaigns3

Used byProcedure example
CampaignC0032

During the C0032 campaign, TEMP.Veles used timestomping to modify the $STANDARD_INFORMATION attribute on tools.

CampaignCutting Edge

During Cutting Edge, threat actors changed timestamps of multiple files on compromised Ivanti Secure Connect VPNs to conceal malicious activity.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 modified timestamps of backdoors to match legitimate Windows files.

References6

  1. Double Timestomping Open source
    Matthew Dunwoody. (2022, April 28). I have seen double-timestomping ITW, including by APT29. Stay sharp out there.. Retrieved June 20, 2024.
  2. Inversecos Linux Timestomping Open source
    inversecos. (2022, August 4). Detecting Linux Anti-Forensics: Timestomping. Retrieved March 26, 2025.
  3. Inversecos Timestomping 2022 Open source
    Lina Lau. (2022, April 28). Defence Evasion Technique: Timestomping Detection – NTFS Forensics. Retrieved September 30, 2024.
  4. Juniper Networks ESXi Backdoor 2022 Open source
    Asher Langton. (2022, December 9). A Custom Python Backdoor for VMWare ESXi Servers. Retrieved March 26, 2025.
  5. Magnet Forensics Open source
    Magnet Forensics. (2020, August 24). Expose Evidence of Timestomping with the NTFS Timestamp Mismatch Artifact. Retrieved June 20, 2024.
  6. WindowsIR Anti-Forensic Techniques Open source
    Carvey, H. (2013, July 23). HowTo: Determine/Detect the use of Anti-Forensics Techniques. Retrieved June 3, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.