Sub-technique of T1070 Indicator Removal.View on attack.mitre.org
Adversaries may modify file time attributes to hide new files or changes to existing files. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change times), often to mimic files that are in the same folder and blend malicious files with legitimate files.
In Windows systems, both the `$STANDARD_INFORMATION` (`$SI`) and `$FILE_NAME` (`$FN`) attributes record times in a Master File Table (MFT) file. `$SI` (dates/time stamps) is displayed to the end user, including in the File System view, while `$FN` is dealt with by the kernel.
Modifying the `$SI` attribute is the most common method of timestomping because it can be modified at the user level using API calls. `$FN` timestomping, however, typically requires interacting with the system kernel or moving or renaming a file.
Adversaries modify timestamps on files so that they do not appear conspicuous to forensic investigators or file analysis tools. In order to evade detections that rely on identifying discrepancies between the `$SI` and `$FN` attributes, adversaries may also engage in “double timestomping” by modifying times on both attributes simultaneously.
In Linux systems and on ESXi servers, threat actors may attempt to perform timestomping using commands such as `touch -a -m -t <timestamp> <filename>` (which sets access and modification times to a specific value) or `touch -r <filename> <filename>` (which sets access and modification times to match those of another file).
Timestomping may be used along with file name Masquerading to hide malware and tools.
Rules on DetectionCode tagged with T1070.006.
| Rule | Level | Log source |
|---|---|---|
| File Creation Date Changed to Another Year | high | windows / file_change |
| File Time Attribute Change | medium | macos / process_creation |
| File Time Attribute Change - Linux | medium | linux / NULL |
| Powershell Timestomp | medium | windows / ps_script |
| Touch Suspicious Service File | medium | linux / process_creation |
| Unauthorized System Time Modification | low | windows / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| ESXi System Clock Manipulation | TTP | NULL | VMWare ESXi Syslog |
| Used by | Procedure example |
|---|---|
| GroupAPT28 | APT28 has performed timestomping on victim files. |
| GroupAPT29 | APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. |
| GroupAPT32 | APT32 has used scheduled task raw XML with a backdated timestamp of June 2, 2016. The group has also set the creation time of the files dropped by the second stage of the exploit to match the creation time of kernel32.dll. Additionally, APT32 has used a random value to modify the timestamp of the file storing the clientID. |
| GroupAPT38 | APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host. |
| GroupAPT5 | APT5 has modified file timestamps. |
| GroupChimera | Chimera has used a Windows version of the Linux |
| GroupKimsuky | Kimsuky has manipulated timestamps for creation or compilation dates to defeat anti-forensics. |
| GroupLazarus Group | Several Lazarus Group malware families use timestomping, including modifying the last write timestamp of a specified Registry key to a random date, as well as copying the timestamp for legitimate .exe files (such as calc.exe or mspaint.exe) to its dropped files. |
| Used by | Procedure example |
|---|---|
| Malware3PARA RAT | 3PARA RAT has a command to set certain attributes such as creation/modification timestamps on files. |
| MalwareAttor | Attor has manipulated the time of last access to files and registry keys after they have been created or modified. |
| MalwareBankshot | Bankshot modifies the time of a file as specified by the control server. |
| MalwareBitPaymer | BitPaymer can modify the timestamp of an executable so that it can be identified and restored by the decryption tool. |
| MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware can timestomp files for defense evasion and anti-forensics purposes. |
| MalwareBLINDINGCAN | BLINDINGCAN has modified file and directory timestamps. |
| MalwareBOOKWORM | BOOKWORM has modified file timestamps from the export address table (EAT) to make it difficult to discern when the module was created. |
| MalwareBPFDoor | BPFDoor uses the `utimes()` function to change the executable's timestamp. |
| Used by | Procedure example |
|---|---|
| CampaignC0032 | During the C0032 campaign, TEMP.Veles used timestomping to modify the |
| CampaignCutting Edge | During Cutting Edge, threat actors changed timestamps of multiple files on compromised Ivanti Secure Connect VPNs to conceal malicious activity. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 modified timestamps of backdoors to match legitimate Windows files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.