T1036.005 Match Legitimate Resource Name or Location — ATT&CK Technique
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation. This may be done by placing an executable in a commonly trusted directory (ex: under System32) or giving it the name of a legitimate, trusted program (ex: `svchost.exe`). Alternatively, a Windows Registry key may be given a close approximation to a key used by a legitimate program. In containerized environments, a threat actor may create a resource in a trusted namespace or one that matches the naming convention of a container pod or cluster.
Detection coverage (27)
- RedSun - TieringEngineService.exe Staged in RS-Prefixed Temp Dir critical
- RedSun - TieringEngineService.exe Detected as EICAR Test File critical
- RedSun - Conhost.exe Spawned by TieringEngineService.exe high
- Creation Of Pod In System Namespace medium
- Flash Player Update from Suspicious Location high
- Files With System DLL Name In Unsuspected Locations medium
- Files With System Process Name In Unsuspected Locations medium
- Suspicious Files in Default GPO Folder medium
- Unsigned .node File Loaded medium
- Potential MsiExec Masquerading high
- Suspicious Scheduled Task Creation via Masqueraded XML File medium
- Scheduled Task Creation Masquerading as System Processes high
- Windows Processes Suspicious Parent Directory low
- Suspicious Process Masquerading As SvcHost.EXE high
- Uncommon Svchost Command Line Parameter high
- Uncommon Svchost Parent Process medium
- Potential Binary Impersonating Sysinternals Tools medium
- Lazarus System Binary Masquerading high
- Attacker Tools On Endpoint
- Exploit for CVE-2015-1641 critical
- Windows LOLBAS Executed Outside Expected Path
- Windows MSC EvilTwin Directory Path Manipulation
- Windows Process Execution From ProgramData
- Windows Process Execution in Temp Dir
- Windows Suspicious Process File Path
- Greenbug Espionage Group Indicators critical
- Small Sieve Malware File Indicator Creation high
Malware using this technique
- EKANS
- BLINDINGCAN
- Ninja
- Bumblebee
- BRICKSTORM
- NOKKI
- PipeMon
- MagicRAT
- RotaJakiro
- Chinoxy
- Misdat
- Ursnif
- ThreatNeedle
- ZLib
- Tsundere Botnet
- Felismus
- StrongPity
- Nebulae
- TONESHELL
- RainyDay
- AppleSeed
- NETWIRE
- TinyTurla
- PyDCrypt
- J-magic
- OLDBAIT
- Bad Rabbit
- SslMM
- STATICPLUGIN
- TEARDROP
- Machete
- DUSTPAN
- PureCrypter
- PUBLOAD
- CANONSTAGER
- HexEval Loader
- Cuckoo Stealer
- CLAIMLOADER
- QUIETEXIT
- RDAT
- Skidmap
- TRANSLATEXT
- SameCoin
- Raindrop
- Doki
- IcedID
- MarkiRAT
- DarkComet
- DRATzarus
- Daserf
Threat actors using this technique
- Void Manticore
- PROMETHIUM
- WIRTE
- Evil Corp
- SideCopy
- Mustard Tempest
- Kimsuky
- admin@338
- Volt Typhoon
- Patchwork
- APT41
- APT10
- APT32
- MuddyWater
- Naikon
- Gamaredon Group
- Storm-1811
- TeamTNT
- FIN7
- Sandworm Team
- Machete
- Sidewinder
- APT35
- Mustang Panda
- APT39
- TA2541
- Akira
- OilRig
- Carbanak
- Tropic Trooper
- Aquatic Panda
- Ferocious Kitten
- APT15
- APT1
- Blue Mockingbird
- Turla
- Poseidon Group
- RedCurl
- APT29
- Chimera
- BRONZE BUTLER
- BackdoorDiplomacy
- Darkhotel
- Ember Bear
- ToddyCat
- Whitefly
- LuminousMoth
- APT28
- APT42
- APT5