Space after Filename

T1036.006

Sub-technique of T1036 Masquerading.View on attack.mitre.org

About this technique

Adversaries can hide a program's true filetype by changing the extension of a file. With certain file types (specifically this does not work with .app extensions), appending a space to the end of a filename will change how the file is processed by the operating system.

For example, if there is a Mach-O executable file called evil.bin, when it is double clicked by a user, it will launch Terminal.app and execute. If this file is renamed to evil.txt, then when double clicked by a user, it will launch with the default text editing application (not executing the binary). However, if the file is renamed to evil.txt (note the space at the end), then when double clicked by a user, the true file type is determined by the OS and handled appropriately and the binary will be executed .

Adversaries can use this feature to trick users into double clicking benign-looking files of any format and ultimately executing something malicious.

Detection rules1

Rules on DetectionCode tagged with T1036.006.

Sigma1

RuleLevelLog source
Space After Filename - macOSlowmacos / process_creation

Splunk0

No Splunk rules are mapped to this technique yet.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples2

Groups1

Used byProcedure example
GroupAPT38

APT38 has put several spaces before a file extension to avoid detection and suspicion.

Software1

Used byProcedure example
MalwareKeydnap

Keydnap puts a space after a false .jpg extension so that execution actually goes through the Terminal.app program.

References1

  1. Mac Backdoors are back Open source
    Dan Goodin. (2016, July 6). After hiatus, in-the-wild Mac backdoors are suddenly back. Retrieved July 8, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.