FORENSIA

ATT&CK · T1070.006 · sub-technique

Timestomp

Tactics: stealth

About

Adversaries may modify file time attributes to hide new files or changes to existing files. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change times), often to mimic files that are in the same folder and blend malicious files with legitimate files. In Windows systems, both the `$STANDARD_INFORMATION` (`$SI`) and `$FILE_NAME` (`$FN`) attributes record times in a Master File Table (MFT) file. `$SI` (dates/time stamps) is displayed to the end user, including in the File System view, while `$FN` is dealt with by the kernel. Modifying the `$SI` attribute is the most common method of timestomping because it can be modified at the user level using API calls. `$FN` timestomping, however, typically requires interacting with the system kernel or moving or renaming a file. Adversaries modify timestamps on files so that they do not appear conspicuous to forensic investigators or file analysis tools. In order to evade detections that rely on identifying discrepancies between the `$SI` and `$FN` attributes, adversaries may also engage in “double timestomping” by modifying times on both attributes simultaneously. In Linux systems and on ESXi servers, threat actors may attempt to perform timestomping using commands such as `touch -a -m -t <timestamp> <filename>` (which sets access and modification times to a specific value) or `touch -r <filename> <filename>` (which sets access and modification times to match those of another file). Timestomping may be used along with file name Masquerading to hide malware and tools.

Platforms: ESXi, Linux, macOS, WindowsParent: T1070 Indicator RemovalMITRE ATT&CK ↗

Used by actors

11 known groups

Software

44 malware/tools implement this

China ChopperDerusbi3PARA RATOwaAuthPsyloEliseMisdatUSBStealerShamoonWinnti for WindowsPOSHSPYCobalt StrikeTDTESSGazerFALLCHILLSEASHARPEEBankshotInvisiMoleOSX_OCEANLOTUS.DEmpireKeyBoyPowerStallionAttorBLINDINGCANEVILNUMBitPaymerTAINTEDSCRIBEStuxnetKobalosGelsemiumCyclops BlinkMacMaPingPullmetaMainNightClubNinjaMultiLayer WiperCHIMNEYSWEEPBPFDoorUPSTYLEBlackByte 2.0 RansomwareBOOKWORMHiddenFaceSPAWNCHIMERA

Corpus indicators tagged with this technique

115 indicators in the corpus carry T1070.006.

IndicatorTypeFamilySevSrc
5002eca748205d544618e3bd2dedc223hash801
452259dc297f56cf22c7932e8fbcefe821ef9c3127134074fae585f89355d397hash801
4f0593e8e0e8fac49429e9b45ebf7fa1hash801
dad708e050632a4280cabf98ac1376b7hash801
1d94fbe9cab21278cc3f104bea334d08hash801
4044e4b6471c9de7b0a4ba37d9d9df9ahash801
b7cd06c71465038b658a6dc1f273a507hash801
01f1eb07125db5de0c2362afc777aa015f136feabd769628f01d01ac6472646chash801
c7f38cbb99c8b74fa0465293feeba700hash801
d43fdaa1f0ee09d7e5f0f94ee9df7b6chash801
6c39900d77dcba158e1d27c7619cb06dhash801
1c47c63e5ed25060d95359c57c77b107hash801
20209b3a32769afc6a75694b8d8839ddhash801
3b1aba44dd3d9b6339b6f56e2f42034bhash801
0ba93109757776a44de9d8c88baa4963hash801
7f16449cd0c4862d1eadf8a5742bf09ahash801
9d9ac85765e4a818a3ccabe2cf4fef82hash801
993f4c0cadbc769a4b0ed62a918db58dhash801
a2c6e01001c62f6198e31a9d603977c6hash802
887ec87e4a19759cad25d4bc0956d2b965d3041dhash801
02bb20455cc592a69c080abac770ce90hash801
31037a42ca048e06e69a78f55bc2eff5hash801
b82936f37648518425c7d3cf9e09eaffa41d7cdb3840f6a40287e3a108880f7bsha256802
2c6f05f1f309d89b2236e6c8b59c88f9hash801
05d188f071d097f5b6bd8138749b4b14hash801
1a3cc75466ffb1971482f7abf7aabc3fhash801
686213cc11d36af764de824801bced9366dfca3823fe0d51b752f74149bcf1f4sha256ransomware801
66442f2457eca8f47385b1fb2c6fcab8hash801
63ac85195b73753333316a889cf5880fhash801
50c74b468c217776b8890b841baefec8b196b14083a7873a9201c838a8e4c90ahash801

Showing the top 30 by severity of 115.