Rename Legitimate Utilities

T1036.003

Sub-technique of T1036 Masquerading.View on attack.mitre.org

About this technique

Adversaries may rename legitimate / system utilities to try to evade security mechanisms concerning the usage of those utilities. Security monitoring and control mechanisms may be in place for legitimate utilities adversaries are capable of abusing, including both built-in binaries and tools such as PSExec, AutoHotKey, and IronPython. It may be possible to bypass those security mechanisms by renaming the utility prior to utilization (ex: rename rundll32.exe). An alternative case occurs when a legitimate utility is copied or moved to a different directory and renamed to avoid detections based on these utilities executing from non-standard paths.

Detection rules39

Rules on DetectionCode tagged with T1036.003.

Sigma27

RuleLevelLog source
File Download Via Bitsadmin To A Suspicious Target Folderhighwindows / process_creation
File With Suspicious Extension Downloaded Via Bitsadminhighwindows / process_creation
LOL-Binary Copied From System Directoryhighwindows / process_creation
Potential Defense Evasion Via Rename Of Highly Relevant Binarieshighwindows / process_creation
Potential WerFault ReflectDebugger Registry Value Abusehighwindows / registry_set
Remote Access Tool - Renamed MeshAgent Execution - MacOShighmacos / process_creation
Remote Access Tool - Renamed MeshAgent Execution - Windowshighwindows / process_creation
Renamed BrowserCore.EXE Executionhighwindows / process_creation
Renamed Jusched.EXE Executionhighwindows / process_creation
Renamed Msdt.EXE Executionhighwindows / process_creation
Renamed Office Binary Executionhighwindows / process_creation
Renamed ProcDump Executionhighwindows / process_creation
Renamed Schtasks Executionhighwindows / process_creation
Suspicious Download From Direct IP Via Bitsadminhighwindows / process_creation
Suspicious Download From File-Sharing Website Via Bitsadminhighwindows / process_creation

Splunk12

RuleTypeRiskData source
Execution of File with Multiple ExtensionsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Execution of File With Spaces Before ExtensionTTPNULLSysmon EventID 1
Suspicious Copy on System32AnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Suspicious microsoft workflow compiler renameHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Suspicious msbuild pathTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Suspicious MSBuild RenameHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Suspicious Rundll32 RenameHuntingNULLSysmon EventID 1
System Processes Run From Unexpected LocationsAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows DotNet Binary in Non Standard PathTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows InstallUtil in Non Standard PathTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows LOLBAS Executed As Renamed FileTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Renamed Powershell ExecutionTTPNULLSysmon EventID 1

Groups6

Software5

Campaigns0

None recorded.

Procedure examples11

Groups6

Used byProcedure example
GroupAPT32

APT32 has moved and renamed pubprn.vbs to a .txt file to avoid detection.

GroupAPT38

APT38 has renamed system utilities, such as `rundll32.exe` and `mshta.exe`, to avoid detection.

GroupDaggerfly

Daggerfly used a renamed version of rundll32.exe, such as "dbengin.exe" located in the `ProgramData\Microsoft\PlayReady` directory, to proxy malicious DLL execution.

GroupGALLIUM

GALLIUM used a renamed cmd.exe file to evade detection.

GroupLazarus Group

Lazarus Group has renamed system utilities such as wscript.exe and mshta.exe.

GroupmenuPass

menuPass has renamed certutil and moved it to a different location on the system to avoid detection based on use of the tool.

Software5

Used byProcedure example
MalwareCozyCar

The CozyCar dropper has masqueraded a copy of the infected system's rundll32.exe executable that was moved to the malware's install directory and renamed according to a predefined configuration file.

MalwareDarkGate

DarkGate executes a Windows Batch script during installation that creases a randomly-named directory in the C:\\ root directory that copies and renames the legitimate Windows <curl>curl</code> command to this new location.

MalwareKevin

Kevin has renamed an image of `cmd.exe` with a random name followed by a `.tmpl` extension.

MalwarePHASEJAM

PHASEJAM has renamed the file `/home/bin/remotedebug` to `remotedebug.bak`, allowing the threats actors to write a malicious `/home/bin/remotedebug` shell script.

MalwareStrelaStealer

StrelaStealer has used a renamed, legitimate `msinfo32.exe` executable to sideload the StrelaStealer payload during initial installation.

References6

  1. Elastic Masquerade Ball Open source
    Ewing, P. (2016, October 31). How to Hunt: The Masquerade Ball. Retrieved October 31, 2016.
  2. F-Secure CozyDuke Open source
    F-Secure Labs. (2015, April 22). CozyDuke: Malware Analysis. Retrieved December 10, 2015.
  3. Huntress Python Malware 2025 Open source
    Matthew Brennan. (2024, July 5). Snakes on a Domain: An Analysis of a Python Malware Loader. Retrieved April 3, 2025.
  4. LOLBAS Main Site Open source
    LOLBAS. (n.d.). Living Off The Land Binaries and Scripts (and also Libraries). Retrieved February 10, 2020.
  5. Splunk Detect Renamed PSExec Open source
    Splunk. (2025, February 24). Detection: Detect Renamed PSExec. Retrieved April 3, 2025.
  6. The DFIR Report AutoHotKey 2023 Open source
    The DFIR Report. (2023, February 6). Collect, Exfiltrate, Sleep, Repeat. Retrieved April 3, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.