FORENSIA

ATT&CK · T1564.001 · sub-technique

Hidden Files and Directories

Tactics: stealth

About

Adversaries may set files and directories to be hidden to evade detection mechanisms. To prevent normal users from accidentally changing special files on a system, most operating systems have the concept of a ‘hidden’ file. These files don’t show up when a user browses the file system with a GUI or when using normal commands on the command line. Users must explicitly ask to show the hidden files either via a series of Graphical User Interface (GUI) prompts or with command line switches (<code>dir /a</code> for Windows and <code>ls –a</code> for Linux and macOS). On Linux and Mac, users can mark specific files as hidden simply by putting a “.” as the first character in the file or folder name. Files and folders that start with a period, ‘.’, are by default hidden from being viewed in the Finder application and standard command-line utilities like “ls”. Users must specifically change settings to have these files viewable. Files on macOS can also be marked with the UF_HIDDEN flag which prevents them from being seen in Finder.app, but still allows them to be seen in Terminal.app. On Windows, users can mark specific files as hidden by using the attrib.exe binary. Many applications create these hidden files and folders to store information so that it doesn’t clutter up the user’s workspace. For example, SSH utilities create a .ssh folder that’s hidden and contains the user’s known hosts and keys. Additionally, adversaries may name files in a manner that would allow the file to be hidden such as naming a file only a “space” character. Adversaries can use this to their advantage to hide files and folders anywhere on the system and evading a typical user or system analysis that does not incorporate investigation of hidden files.

Platforms: Linux, macOS, WindowsParent: T1564 Hide ArtifactsMITRE ATT&CK ↗

Used by actors

12 known groups

Software

45 malware/tools implement this

PlugXIxesheKomplexNETWIREInvisiMoleQuasarRATCalistoFruitFlyiKittenMacSpyAgent TeslaMicropsiaOSX_OCEANLOTUS.DWannaCryCoinTickerOSX/ShlayerMachetePoetRATImminent MonitorAttorOkrumLokibotRising SunLoudMinerBackConfigCarberpDaclsSLOTHFULMEDIAExplosiveAppleJeusThiefQuestWastedLockerEnvyScoutQakBotXCSSETClamblingSysUpdateccf32COATHANGERDarkGateCuckoo StealerattribREPTILEHIUPANCLAIMLOADER

Corpus indicators tagged with this technique

507 indicators in the corpus carry T1564.001.

IndicatorTypeFamilySevSrc
63ac85195b73753333316a889cf5880fhash801
372f19a45d0eb4c8c52117c6ae2bb8040a91bc72be8670623f957a18c2166985sha256phishing8051
02bb20455cc592a69c080abac770ce90hash801
2c6f05f1f309d89b2236e6c8b59c88f9hash801
b6a77b7892ef22d6afd91eb980a3f3d8hashcryptojacking802
a14bed1c46ba7406d5240e979251ccd394dfe3b5hashcryptojacking802
d42aecf76fb1531cd5b7139e669910b2fd82a90b7e11448128e226775bf5d42ehashcryptojacking802
1fc5e6458316277fae8272cbe9f3dfc86b681635hashcryptojacking802
0ba93109757776a44de9d8c88baa4963hash801
887ec87e4a19759cad25d4bc0956d2b965d3041dhash801
e84b1e2c432b2394c403b524b8361ffa9923a022eb05215f1dc811bc167c3c5ehashcryptojacking802
69315b7a1c4bf5ee56cba1de29d1761ehashcryptojacking802
c5a53c02d531c5e46f9cc2fc0afbb88dhashcryptojacking802
107b5aa3c4ef30b9b832e0a10b1efb1dcf433158bc6af8d890d66c0c9ed50d21sha256801
e4ccb2328c06710a7f0254cb6315e1b106396b0ff525f9cf3eada6e85d285c1csha256801
b5da6ffa5f85aa5016fbc02a3122361c85d21192c45df9544099d13e6ff84c36hashcryptojacking802
41f581f7d2c09ab0edfea850b9db506fhashcryptojacking802
50eda29bfbeeb8b0429718447725016ahashcryptojacking802
9758e76b601798a30d903bf05052a53df80451e5c156548ce9da828f608b6470sha256801
ce62d1b6116f34f9ba815db1e2016d2ahashcryptojacking802
221a39856b37e3c682f62427f1e6b965b36a2405764689c914672770a01a1fa9sha256801
31037a42ca048e06e69a78f55bc2eff5hash801
a37f6403fbf28fa0b48863287f4c5a5dhashcryptojacking802
bd46890121106b43f0c01ab82629400chashcryptojacking802
5d253cc263851ec68c0a988bf86afbb3e9f0b491hashcryptojacking802
93b3d3925ccc201ab0f16017153a79ef05b8f5c2hashcryptojacking802
462af0a3a9094d44c30cc65544ec1171a62365cff09e67f5e87e061a3d604bd0hashcryptojacking802
579a82dde4425d95e20a22171be0a37702c833fdca6e5e04f69099a025863136hashcryptojacking802
89930bd18e0f9c9c98dfb1662cb87aa98348e87164ab62b1f39e86ebf2ce24cbhashcryptojacking802
66442f2457eca8f47385b1fb2c6fcab8hash801

Showing the top 30 by severity of 507.