FORENSIA

ATT&CK · T1027.005 · sub-technique

Indicator Removal from Tools

Tactics: stealth

About

Adversaries may remove indicators from tools if they believe their malicious tool was detected, quarantined, or otherwise curtailed. They can modify the tool by removing the indicator and using the updated version that is no longer detected by the target's defensive systems or subsequent targets that may use similar systems. A good example of this is when malware is detected with a file signature and quarantined by anti-virus software. An adversary who can determine that the malware was quarantined because of its file signature may modify the file to explicitly avoid that signature, and then re-use the malware.

Platforms: Linux, macOS, WindowsParent: T1027 Obfuscated Files or InformationMITRE ATT&CK ↗

Used by actors

7 known groups

Software

9 malware/tools implement this

Cobalt StrikeDaserfPowerSploitGravityRATInvisiMoleSUNBURSTWaterbearPenquinQakBot

Corpus indicators tagged with this technique

10 indicators in the corpus carry T1027.005.

IndicatorTypeFamilySevSrc
cve-2016-0638cvephishing851
fc4109f5dd1d30b65dd60e57dc639ac1d313bfa5241e36e61fbc4aabc1cda482sha256phishing807
ca024acead8f54cfe5b07ac4bdf7fceamd5phishing767
45.135.162.90ipphishing703
43.162.84.202ipphishing703
43.165.6.36ipphishing703
154.81.166.17ipphishing702
8.222.134.149ipphishing703
47.82.154.2ipphishing703
43.159.168.186ipphishing703