Title:File Creation Date Changed to Another Year Status:test Description:Attackers may change the file creation time of a backdoor to make it look like it was installed with the operating system.
Note that many processes legitimately change the creation time of a file; it does not necessarily indicate malicious activity.
References: -https://www.inversecos.com/2022/04/defence-evasion-technique-timestomping.html Author: frack113, Florian Roth (Nextron Systems) Date: 2022-08-12 modified:2022-10-25 Tags:
-'attack.t1070.006'
-'attack.defense-evasion'
Logsource:
category: file_change
product: windows
Detection: selection1: PreviousCreationUtcTime|startswith:
'2022' filter1: CreationUtcTime|startswith:
'2022' selection2: PreviousCreationUtcTime|startswith:
'202' filter2: CreationUtcTime|startswith:
'202' gen_filter_updates: - Image: - 'C:\Windows\system32\ProvTool.exe' - 'C:\Windows\System32\usocoreworker.exe' - 'C:\Windows\ImmersiveControlPanel\SystemSettings.exe' TargetFilename|startswith:'C:\ProgramData\USOPrivate\UpdateStore\'- TargetFilename|endswith: - '.tmp' - '.temp' gen_filter_tiworker: Image|startswith:
'C:\WINDOWS\' Image|endswith:
'\TiWorker.exe' TargetFilename|endswith:
'.cab' condition:(( selection1 and not filter1 ) or ( selection2 and not filter2 )) and not 1 of gen_filter* Falsepositives:
-Changes made to or by the local NTP service Level:high