FORENSIA

ATT&CK · T1564.004 · sub-technique

NTFS File Attributes

Tactics: stealth

About

Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection. Every New Technology File System (NTFS) formatted partition contains a Master File Table (MFT) that maintains a record for every file/directory on the partition. Within MFT entries are file attributes, such as Extended Attributes (EA) and Data [known as Alternate Data Streams (ADSs) when more than one Data attribute is present], that can be used to store arbitrary data (and even complete files). Adversaries may store malicious data or binaries in file attribute metadata instead of directly in files. This may be done to evade some defenses, such as static indicator scanning tools and anti-virus.

Platforms: WindowsParent: T1564 Hide ArtifactsMITRE ATT&CK ↗

Used by actors

1 known groups

Software

15 malware/tools implement this

ReginZeroaccessPowerDukePOWERSOURCEGazerExpandAstarothLoJaxesentutlValakAnchorBitPaymerWastedLockerDEADEYELatrodectus

Corpus indicators tagged with this technique

217 indicators in the corpus carry T1564.004.

IndicatorTypeFamilySevSrc
02bb20455cc592a69c080abac770ce90hash801
0ba93109757776a44de9d8c88baa4963hash801
1794369214b7f62e70a0485e61335c61hash803
8e1624d110c090ff57d4b493a9107c66hash803
8ca36b9cbd72d1f4ab4a9c8fcf85fe7ehash801
887ec87e4a19759cad25d4bc0956d2b965d3041dhash801
65c053030558b4a3588e2590c5c4961a9912180b731686deb3f4c831e765a095hash803
39dd1bd3bccc314d8933e5c41ed2ab084e4e20af569f77b7cf09abc5855b9483hash801
6c6cbed6aad96564ed87094785be07a1hashphishing802
2add9429d2822ae0c01c08bbd66c3a110ef2e9c3a00cded1477657e9024e391ehash801
08060143ea9b55b480746b415af22e3ahashransomware801
55d6238b01a177e25eb7d53c943f3abea64ec073hashphishing802
b148626849c11dd5b3230632a38a6302hashransomware802
31037a42ca048e06e69a78f55bc2eff5hash801
15d1002d9935fbfc9dfc65eb70fe4ecc0943c784hashransomware801
61e9d76f07334843df561fe4bac449fb6fdaed5e5eb91480bded225f3d265c5fhashphishing802
46b2155c1e71b840d4b7a2e94410b89a61e2446523e6f497206d402eb02e0e93hashransomware801
1c170b7470d507378ddb78e9d66305f1184e965baaf2d27ededb23a318a58953hash804
4c357a29b202b77e7db190d359ead2dfd3f8869c6808b96bfa8bee82525bb2a2hashransomware801
22b07d2af98bb180474c33d93861124bbdf9b5dd7e42a8bddc654310469a9a2chash803
6870e3bbf2447c96d21682caf943cf31c2e8c21c8cfb91a5092eab1c9e5f19aehashransomware801
e5c4e634b2f443f783cae1b5e8247a1069df0c9fhashransomware802
1e41c7bfaa6aa3b93b6cc024274a10e33f3e12fe7c98c1db387ef8927f9d1984hashransomware802
75635009a00cb26d2f532ad974ede59785a18e4b30132a1f585108589394ba5ahashransomware801
a5a5b6257304eefe5212edfd8c0ad27f77357c5046a7acb8eb7ba72ed4bad9e0hashransomware801
2af0a6135df3502a7f6de4d2de6db73bhash803
a2c6e01001c62f6198e31a9d603977c6hash802
ac66c2d47cdefb221822b9074c9810434e8da702a0694139aa9177557e6b292bhashransomware801
ced6b0f44410f6133ad63b61e04613a8b56cc3338d7b34497540e9541163e7echashransomware801
2c6f05f1f309d89b2236e6c8b59c88f9hash801

Showing the top 30 by severity of 217.