Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1036.005

T1036.005Match Legitimate Resource Name or Location

T1036.005 — Match Legitimate Resource Name or Location is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 62 detection use cases covering it and 48 threat-intel articles citing it.

Defense Evasion
View on the matrix → Filter Detection Library MITRE official spec ↗
62Use cases
48Articles
0Sub-techniques
1Tactic

Use cases covering this technique (62)

Attacker Tools On Endpoint ESCU actions · alerting P Windows LOLBAS Executed Outside Expected Path ESCU actions · hunting P Windows MSC EvilTwin Directory Path Manipulation ESCU actions · alerting P Windows Process Execution From ProgramData ESCU actions · hunting P Windows Process Execution in Temp Dir ESCU actions · hunting P Windows Suspicious Process File Path ESCU actions · alerting P [LLM] SOCKS5 proxy masquerading as 'smbd -D' from non-Samba install path Bespoke c2 · alerting DSΣPDDCS [LLM] First-seen pam_unix.so / sshd / ssh binary hash in Linux fleet Bespoke install · hunting DSPDDCS [LLM] MeshCentral agent disguised as Microsoft Azure binary calling azurenetfiles.net Bespoke c2 · alerting DSΣPDDCS [LLM] Talos prevalent malware filename pattern — VID001.exe and d4aa3e70..._N_Exe.exe Bespoke install · hunting DSΣPDDCS [LLM] Execution or drop of fake AI-platform installer (DeepSeek/Manus/Seedance/GPT-5.5/Kimi) Bespoke install · alerting DSΣPDDCS [LLM] Bun runtime download to /tmp from a node process during npm install Bespoke delivery · alerting DSPDDCS [LLM] Orphaned process (ppid=1) executing from /tmp hidden hex path (post-dropper stage-2) Bespoke actions · alerting DSΣPDDCS [LLM] payload.bin written under node_modules by node process Bespoke install · alerting DSΣPDDCS [LLM] axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging Bespoke install · alerting DSΣPDDCS [LLM] DNS/HTTPS exfil to sentry.anyclaw.store (Codex token C2 masquerading as Sentry) Bespoke c2 · alerting DSΣPDDCS [LLM] DebugChromium.exe execution (Laravel-Lang stealer Windows artifact) Bespoke install · alerting DSΣPDDCS [LLM] Stealer or VBS launcher dropped into .laravel_locale temp directory Bespoke install · alerting DSΣPDDCS [LLM] Screening Serpens recruitment lure — Hiring Portal.zip + job requisition PDFs Bespoke delivery · alerting DSΣPDDCS [LLM] BadIIS rogue native module drop in IIS folders (demo.pdb / Chinese path heuristic) Bespoke install · hunting DSΣPDDCS [LLM] Python backdoor self-daemonisation via __DAEMONIZED=1 spawned by VS Code helper or node Bespoke install · hunting DSΣPDDCS [LLM] TeamPCP rope.pyz Dropper Infection Markers on Linux Bespoke install · alerting DSΣPDDCS [LLM] Drop of /tmp/transformers.pyz on Linux endpoint Bespoke install · alerting DSΣPDDCS [LLM] AdaptixC2 'systemd-resolved' or Sliver 'CWan' implant on Linux / SD-WAN host Bespoke install · hunting DSΣPDDCS [LLM] FrostyNeighbor PicassoLoader drop to %AppData%\WinDataScope\Update.js Bespoke install · alerting DSΣPDDCS [LLM] FrostyNeighbor Cobalt Strike beacon ViberPC.dll image load Bespoke install · hunting DSΣPDDCS [LLM] Hidden .fullgc cryptominer binary written to /ql/data/db/ Bespoke install · alerting DSΣPDDCS [LLM] Qinglong .fullgc cryptominer execution with nohup backgrounding Bespoke install · alerting DSΣPDDCS [LLM] whisper.dll loaded / svchost.exe spawned outside services.exe (GopherWhisper JabGopher injection) Bespoke install · alerting DSΣPDDCS [LLM] Stage-2 implant masquerading as node-health-check daemon (/tmp/.kh, /tmp/.ns) Bespoke install · alerting DSΣPDD [LLM] launchctl persistence registering zsh.profiler service from non-admin location Bespoke install · alerting DSΣPDDCS [LLM] macOS file write of profiler binary to com.apple.Terminal masquerade path Bespoke install · alerting DSΣPDDCS [LLM] plain-crypto-js setup.js self-deletion or package.json overwrite (anti-forensics) Bespoke actions · hunting DSΣPDDCS [LLM] IoliteLabs Stage-2 regsvr32 LOLbin loading ntuser DLL from fake Chrome\ChromeUpdate path Bespoke install · alerting DSΣPDD [LLM] msbuild.exe dropped to Startup folder (TeamPCP telnyx Windows persistence) Bespoke install · alerting DSΣPDDCS [LLM] Linux user-systemd sysmon persistence drop (~/.config/sysmon/sysmon.py + sysmon.service) Bespoke install · alerting DSΣPDDCS [LLM] PowerShell masquerading as Windows Terminal at %PROGRAMDATA%\wt.exe (Axios RAT Windows stage) Bespoke install · alerting DSΣPDDCS [LLM] axios RAT artifact dropped: com.apple.act.mond / wt.exe / ld.py with known SHA256 Bespoke install · alerting DSΣPDD [LLM] PowerShell copy masqueraded as Windows Terminal in %PROGRAMDATA% running 6202033.ps1 Bespoke install · alerting DSΣPDD [LLM] TeamPCP msbuild.exe persistence in user Startup folder Bespoke install · alerting DSΣPDDCS [LLM] CanisterWorm persistence: pglog/pg_state/internal-monitor systemd unit and /tmp/pglog drop Bespoke install · alerting DSΣPDDCS [LLM] GlassWorm Stage-3a UpdateLedger Run-key persistence pointing at %TEMP%\SKuyzYcDD.exe Bespoke install · alerting DSΣPDDCS [LLM] GlassWorm Stage-3a Ledger impersonator binary execution (SHA256 06fab21d / SKuyzYcDD.exe) Bespoke actions · alerting DSΣPDDCS [LLM] Glassworm side-staged Node.js runtime under %APPDATA%\_node_x86 / _node_x64 Bespoke install · alerting DSΣPDD [LLM] SlimAgent / BeardShell DLL load with implant filename outside System32 Bespoke install · alerting DSΣPDDCS [LLM] PlugX DLL side-load — G DATA Avk.exe running from C:\Users\Public\GDatas\ Bespoke install · alerting DSΣPDDCS [LLM] Scavenger loader/install.js dropped into node_modules (known SHA256 or filename match) Bespoke delivery · hunting DSΣPDD [LLM] DynoWiper schtask.exe / *_update.exe execution from C:\inetpub\pub\ Bespoke install · alerting DSΣPDDCS [LLM] Weaponised ScreenConnect install path with attacker instance GUID 083e4d30c7ea44f7 Bespoke install · alerting DSΣPDDCS [LLM] DynoWiper deployment from shared inetpub\pub directory (Sandworm, Poland Dec 2025) Bespoke install · alerting DSΣP [LLM] G_Wagon Python runtime drop into npm cache with lib_core/renderer or python_runtime paths Bespoke install · alerting DSΣPDDCS [LLM] NosyDoor AppDomainManager hijack: UevAppMonitor.exe executing from non-standard path Bespoke install · alerting DSΣP [LLM] NosyDoor persistence: scheduled task 'OneDrive Reporting Task-S-1-5-21-' under Microsoft folder Bespoke install · alerting DSΣP [LLM] NosyDoor dropper file artefacts in C:\Windows\Microsoft.NET\Framework Bespoke install · alerting DSP [LLM] MuddyWater Fooder loader (OsUpdater.exe) execution from Downloads Bespoke install · alerting DSΣPDDCS [LLM] LittleDaemon / DaemonicLogistics update-hijack URL pattern (popup_4.2.0.2246.dll, /update/updateInfo.bzp, /update/file6.bdat, /update/file2. Bespoke delivery · alerting DSΣP [LLM] DaemonicLogistics fake-Tencent payload drop (logo.gif at %PROGRAMDATA%\Tencent\QQUpdateMgr\UpdateFiles) Bespoke install · alerting DSΣP [LLM] ESET-impersonating typosquat domain contact (InedibleOchotense / Kalambur delivery) Bespoke delivery · alerting DSΣPDDCS [LLM] Python interpreter executed from %TEMP% / Public — RomCom DLL side-load chain (CVE-2025-8088) Bespoke exploit · alerting DSΣP [LLM] DreamJob trojanized PDF/installer execution from job-lure decoy folder Bespoke delivery · hunting DSΣPDDCS [LLM] GhostAction GitHub workflow secret-enumeration commit pattern Bespoke weapon · hunting DSPDDCS [LLM] Polyfill malware C2: contact with googie-anaiytics homograph or kuurza redirect Bespoke c2 · alerting DSΣPDDCS

Articles citing this technique (48)