Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1036.005

T1036.005Match Legitimate Resource Name or Location

T1036.005 — Match Legitimate Resource Name or Location is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 73 detection use cases covering it and 52 threat-intel articles citing it.

Defense Evasion
View on the matrix → Filter Detection Library MITRE official spec ↗
73Use cases
52Articles
0Sub-techniques
1Tactic

Use cases covering this technique (73)

Attacker Tools On Endpoint ESCU actions · alerting P Windows LOLBAS Executed Outside Expected Path ESCU actions · hunting P Windows MSC EvilTwin Directory Path Manipulation ESCU actions · alerting P Windows Process Execution From ProgramData ESCU actions · hunting P Windows Process Execution in Temp Dir ESCU actions · hunting P Windows Suspicious Process File Path ESCU actions · alerting P [LLM] Tengu guardian process masquerading as kernel thread [kworker/0:0] Bespoke install · hunting DSΣPDDCS [LLM] Operation BlueDash fake Teams/Zoom update payload-host infrastructure contact Bespoke delivery · alerting DSΣPDDCS [LLM] msaRAT: MSI impersonating Windows update executed from ProgramData Bespoke install · alerting DSΣPDDCS [LLM] Cavern Manticore WinDirStat DLL side-load of fake uxtheme.dll (Cavern backdoor) Bespoke install · alerting DSΣP [LLM] Masqueraded uxtheme.dll dropped outside Windows dirs via SysAid/RMM deployment (Cavern Manticore) Bespoke delivery · alerting DSΣPDDCS [LLM] AppDomainManager hijacking config artifact dropped in user-writable path (Screening Serpens/UNC1549) Bespoke exploit · hunting DSΣPDDCS [LLM] CAV3RN framework module DLLs loaded/dropped (AzureCommunication / n-HTCommp / masqueraded uxtheme) Bespoke install · hunting DSΣPDDCS [LLM] SleeperGem payload drop: native binary written to hidden ~/.local/share/gcm/ Bespoke install · alerting DSΣPDDCS [LLM] SleeperGem privilege escalation: setuid-root shell planted as /usr/local/sbin/ping6 Bespoke install · alerting DSΣPDDCS [LLM] pythonw.exe loader executing from deceptive %LocalAppData%\Temp dir (ACR Stealer) Bespoke install · hunting DSΣPDDCS [LLM] HelloInjector DLL side-load: wtsapi32.dll dropped into ViPNet Update System dir Bespoke install · alerting DSΣPDDCS [LLM] HelloNet renamed-PuTTY reverse SSH tunnel to 5.39.253.206 Bespoke c2 · alerting DSΣPDDCS [LLM] GoSerpent/McMx masquerading proxy binaries lass.exe and updates.exe Bespoke install · alerting DSΣPDDCS [LLM] Second-stage sync.js dropped under OS 'NodeJS' masquerade directory Bespoke install · alerting DSΣPDDCS [LLM] Velora macOS backdoor launchctl persistence (com.apple.Terminal.profiler.plist) Bespoke install · hunting DSΣPCS [LLM] axios RAT dropped artifacts: renamed PowerShell wt.exe + campaign 6202033 files Bespoke install · alerting DSΣPDDCS [LLM] Java/Spring drops & runs svchosts.exe (svchost masquerade) — Jackson typosquat implant Bespoke install · alerting DSΣPDDCS [LLM] Jackson typosquat Cobalt Strike implant hash sighting (Win + macOS/Linux) Bespoke install · hunting DSΣPDDCS [LLM] TinyRCT backdoor masquerading as PerfWatson2.exe executing from %LOCALAPPDATA% Bespoke install · alerting DSΣPDDCS [LLM] SoftEther VPN / VNT tunneler masquerading as VMware vmtools.exe Bespoke c2 · hunting DSΣPDDCS [LLM] Scheduled task persistence for GoogleUpdater or VMware-disguised VNT binary Bespoke install · hunting DSΣPDDCS [LLM] macOS.Gaslight LaunchAgent persistence masquerading as com.apple.system.services.activity Bespoke install · alerting DSΣPCS [LLM] easy-day-js stealer persistence masquerading as Node tooling (NodePackages / LaunchAgent / systemd) Bespoke install · alerting DSΣPDDCS [LLM] SPECTRALVIPER DLL side-load: IntelAudioService.exe (renamed dtlupdate.exe) loads DtlCrashCatch.dll Bespoke install · alerting DSΣPDDCS [LLM] Bun runtime download to /tmp from a node process during npm install Bespoke delivery · alerting DSPDDCS [LLM] Orphaned process (ppid=1) executing from /tmp hidden hex path (post-dropper stage-2) Bespoke actions · alerting DSΣPDDCS [LLM] axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging Bespoke install · alerting DSΣPDDCS [LLM] DNS/HTTPS exfil to sentry.anyclaw.store (Codex token C2 masquerading as Sentry) Bespoke c2 · alerting DSΣPDDCS [LLM] DebugChromium.exe execution (Laravel-Lang stealer Windows artifact) Bespoke install · alerting DSΣPDDCS [LLM] Stealer or VBS launcher dropped into .laravel_locale temp directory Bespoke install · alerting DSΣPDDCS [LLM] Python backdoor self-daemonisation via __DAEMONIZED=1 spawned by VS Code helper or node Bespoke install · hunting DSΣPDDCS [LLM] TeamPCP rope.pyz Dropper Infection Markers on Linux Bespoke install · alerting DSΣPDDCS [LLM] FrostyNeighbor PicassoLoader drop to %AppData%\WinDataScope\Update.js Bespoke install · alerting DSΣPDDCS [LLM] FrostyNeighbor Cobalt Strike beacon ViberPC.dll image load Bespoke install · hunting DSΣPDDCS [LLM] Hidden .fullgc cryptominer binary written to /ql/data/db/ Bespoke install · alerting DSΣPDDCS [LLM] Qinglong .fullgc cryptominer execution with nohup backgrounding Bespoke install · alerting DSΣPDD [LLM] whisper.dll loaded / svchost.exe spawned outside services.exe (GopherWhisper JabGopher injection) Bespoke install · alerting DSΣPDDCS [LLM] Stage-2 implant masquerading as node-health-check daemon (/tmp/.kh, /tmp/.ns) Bespoke install · alerting DSΣPDD [LLM] launchctl persistence registering zsh.profiler service from non-admin location Bespoke install · alerting DSΣPDDCS [LLM] macOS file write of profiler binary to com.apple.Terminal masquerade path Bespoke install · alerting DSΣPDDCS [LLM] plain-crypto-js setup.js self-deletion or package.json overwrite (anti-forensics) Bespoke actions · hunting DSΣPDDCS [LLM] IoliteLabs Stage-2 regsvr32 LOLbin loading ntuser DLL from fake Chrome\ChromeUpdate path Bespoke install · alerting DSΣPDD [LLM] msbuild.exe dropped to Startup folder (TeamPCP telnyx Windows persistence) Bespoke install · alerting DSΣPDDCS [LLM] Linux user-systemd sysmon persistence drop (~/.config/sysmon/sysmon.py + sysmon.service) Bespoke install · alerting DSΣPDDCS [LLM] PowerShell masquerading as Windows Terminal at %PROGRAMDATA%\wt.exe (Axios RAT Windows stage) Bespoke install · alerting DSΣPDDCS [LLM] axios RAT artifact dropped: com.apple.act.mond / wt.exe / ld.py with known SHA256 Bespoke install · alerting DSΣPDD [LLM] PowerShell copy masqueraded as Windows Terminal in %PROGRAMDATA% running 6202033.ps1 Bespoke install · alerting DSΣPDD [LLM] TeamPCP msbuild.exe persistence in user Startup folder Bespoke install · alerting DSΣPDDCS [LLM] CanisterWorm persistence: pglog/pg_state/internal-monitor systemd unit and /tmp/pglog drop Bespoke install · alerting DSΣPDDCS [LLM] GlassWorm Stage-3a UpdateLedger Run-key persistence pointing at %TEMP%\SKuyzYcDD.exe Bespoke install · alerting DSΣPDDCS [LLM] GlassWorm Stage-3a Ledger impersonator binary execution (SHA256 06fab21d / SKuyzYcDD.exe) Bespoke actions · alerting DSΣPDDCS [LLM] Glassworm side-staged Node.js runtime under %APPDATA%\_node_x86 / _node_x64 Bespoke install · alerting DSΣPDD [LLM] SlimAgent / BeardShell DLL load with implant filename outside System32 Bespoke install · alerting DSΣPDDCS [LLM] PlugX DLL side-load — G DATA Avk.exe running from C:\Users\Public\GDatas\ Bespoke install · alerting DSΣPDD [LLM] Scavenger loader/install.js dropped into node_modules (known SHA256 or filename match) Bespoke delivery · hunting DSΣPDD [LLM] DynoWiper schtask.exe / *_update.exe execution from C:\inetpub\pub\ Bespoke install · alerting DSΣPDDCS [LLM] DynoWiper deployment from shared inetpub\pub directory (Sandworm, Poland Dec 2025) Bespoke install · alerting DSΣP [LLM] NosyDoor AppDomainManager hijack: UevAppMonitor.exe executing from non-standard path Bespoke install · alerting DSΣP [LLM] NosyDoor persistence: scheduled task 'OneDrive Reporting Task-S-1-5-21-' under Microsoft folder Bespoke install · alerting DSΣP [LLM] NosyDoor dropper file artefacts in C:\Windows\Microsoft.NET\Framework Bespoke install · alerting DSP [LLM] MuddyWater Fooder loader (OsUpdater.exe) execution from Downloads Bespoke install · alerting DSΣPDDCS [LLM] LittleDaemon / DaemonicLogistics update-hijack URL pattern (popup_4.2.0.2246.dll, /update/updateInfo.bzp, /update/file6.bdat, /update/file2. Bespoke delivery · alerting DSΣP [LLM] DaemonicLogistics fake-Tencent payload drop (logo.gif at %PROGRAMDATA%\Tencent\QQUpdateMgr\UpdateFiles) Bespoke install · alerting DSΣP [LLM] ESET-impersonating typosquat domain contact (InedibleOchotense / Kalambur delivery) Bespoke delivery · alerting DSΣPDDCS [LLM] Python interpreter executed from %TEMP% / Public — RomCom DLL side-load chain (CVE-2025-8088) Bespoke exploit · alerting DSΣP [LLM] Polyfill malware C2: contact with googie-anaiytics homograph or kuurza redirect Bespoke c2 · alerting DSΣPDDCS [LLM] Process execution from masquerade directory C:\$Windows.~SXK (Discord/Roblox stealer) Bespoke install · alerting DSΣPDDCS

Articles citing this technique (52)