FORENSIA

ATT&CK · T1218

System Binary Proxy Execution

Tactics: stealth

About

Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system. Binaries signed with trusted digital certificates can typically execute on Windows systems protected by digital signature validation. Several Microsoft signed binaries that are default on Windows installations can be used to proxy execution of other files or commands. Similarly, on Linux systems adversaries may abuse trusted binaries such as <code>split</code> to proxy execution of malicious commands.

Platforms: Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

2 known groups

Software

0 malware/tools implement this

None mapped.

Corpus indicators tagged with this technique

386 indicators in the corpus carry T1218.

IndicatorTypeFamilySevSrc
fad482ded2e25ce9e1dd3d3ecc3227af714bdfbbde04347dbc1b21d6a3670405hashsupply_chain802
00d979bdb1b29b2859f2120580f101f40e8e13de0b3b7bc29675e2c31098a03chashphishing803
3d8e5092a9852b61d8d45bd3c7e2d99907fcaa9a8fd3fe3b9efcbc9255947606sha256phishing803
dde03348075512796241389dfea5560c20a3d2a2eac95c894e7bbed5e85a0acchashsupply_chain802
5407cda7d3a75e7b1e030b1f33337a56f293578ffa8b3ae19c671051ed314290hashsupply_chain802
7986bbaee8940da11ce089383521ab420c443ab7b15ed42aed91fd31ce833896hashsupply_chain802
37e065585c573ecc082aacbfd31564ebhashphishing803
ced6b0f4441085bb9c54a32da9ab4ba14c6e21daf6e34fd61d54923f87baacd0hashphishing803
92005051ae314d61074ed94a52e76b1c3e21e7f0e8c1d1fdd497a006ce45fa61hashsupply_chain802
aa124a4b4df12b34e74ee7f6c683b2ebec4ce9a8edcf9be345823b4fdcf5d868hashsupply_chain802
55d6238b01a177e25eb7d53c943f3abea64ec073hashphishing802
975cf719a576788055ca2a6b7b44aaed36c27a8676ea8d50b25a9f935eaf9d79sha256phishing803
ee4f710c68bc2214febeb0127ccb5e111e1a4d01f6d4503efd22a88fb1464606sha256phishing803
daa335553542dea9666a83b3f49e85b51193a39e809fd899bfcbc2d35fcc0c3esha256phishing803
61e9d76f07334843df561fe4bac449fb6fdaed5e5eb91480bded225f3d265c5fhashphishing802
3d510977d60a44322f88100b515f06cb5ed83babc64247068d1a489595faa6c5sha256phishing801
07cd03e2082bcb0b890cc59ce4c770d1a095ac6f1ae9cf999f5542555c56f841sha256phishing801
b032d4ec4e24714f59e853da9b6e63794aacdbcbhashphishing803
6c6cbed6aad96564ed87094785be07a1hashphishing802
256f595afb005303a693fe26a03f9fce6d47b225bfc2300e418f5f80a89089d2sha256phishing803
0e1a306ac4b6770dbc8cb194021a9f32e9a726478db2e39084d4baa892c69521sha256phishing803
670384fafb23140d96f2f8fe04a13fc8cc8e2a6e5e8c973e39b58d103c5fea92sha256phishing801
b90988400cced319d260c4937f334ecc364785ed5c593cd2139965e62ca58173sha256phishing801
e20b35a8c30e076cdd0e1df05ba1ff2e418dbd39a674f084787cc0af2fda9e95sha256phishing801
7ffd8ab8cad744263a4f16c8e96da8b8c38818b480dbeaec91e4224ac70b7ec1sha256phishing803
4f12ec57cca013dce1a5bcaf11ddf5d85fc2ecbc52afb9e61e4154d1be2d9ef3sha256phishing803
c884b1e59bad0101ecf86bd1b5b9e0e2819d5c4d1bd6eac7d76da61db06baa73sha256phishing803
97e74ad16c88b4b07722b5ad42dba95d837b6bdb9fa1193615f42fb34af5684fsha256phishing803
31f27fdc14505e0cebe360579e1ba0326762cbe0948e50b5f920da51fdef1b51hashphishing803
01b43dad62e56164771db696827a30aehashphishing804

Showing the top 30 by severity of 386.