Classe: Hoax
Um boato é um aviso falso sobre um vírus ou outro código malicioso. Normalmente, uma fraude toma a forma de uma mensagem de email avisando o leitor de um novo vírus perigoso e sugerindo que o leitor passe a mensagem. Os hoaxes não causam danos em si mesmos, mas sua distribuição por usuários bem-intencionados muitas vezes causa medo e incerteza. A maioria dos fornecedores de antivírus inclui informações fraudulentas em seus sites e é sempre aconselhável verificar antes de encaminhar mensagens de aviso.Plataforma: Win32
O Win32 é uma API em sistemas operacionais baseados no Windows NT (Windows XP, Windows 7, etc.) que oferece suporte à execução de aplicativos de 32 bits. Uma das plataformas de programação mais difundidas do mundo.Família: Hoax.Win32.BadJoke.Finger
No family descriptionExamples
B81B24F04BB36B2036C18EBF73CFEF08A3677B969ACBD6866D52156E2B1A2E60
03561D5E722BAC8F2D1438F54F20EDD9
F6E564D1818AA8385D656E11235EE60A
04A3FDF9758BC487417B7E03B68013C6
Tactics and Techniques: Mitre*
TA0005
Defense Evasion
The adversary is trying to avoid being detected.
Defense Evasion consists of techniques that adversaries use to avoid detection throughout their compromise. Techniques used for defense evasion include uninstalling/disabling security software or obfuscating/encrypting data and scripts. Adversaries also leverage and abuse trusted processes to hide and masquerade their malware. Other tactics’ techniques are cross-listed here when those techniques include the added benefit of subverting defenses.
Defense Evasion consists of techniques that adversaries use to avoid detection throughout their compromise. Techniques used for defense evasion include uninstalling/disabling security software or obfuscating/encrypting data and scripts. Adversaries also leverage and abuse trusted processes to hide and masquerade their malware. Other tactics’ techniques are cross-listed here when those techniques include the added benefit of subverting defenses.
T1070.006
Indicator Removal: Timestomp
Adversaries may modify file time attributes to hide new or changes to existing files. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change times), often to mimic files that are in the same folder. This is done, for example, on files that have been modified or created by the adversary so that they do not appear conspicuous to forensic investigators or file analysis tools.
Timestomping may be used along with file name Masquerading to hide malware and tools.(Citation: WindowsIR Anti-Forensic Techniques)
Timestomping may be used along with file name Masquerading to hide malware and tools.(Citation: WindowsIR Anti-Forensic Techniques)
T1140
Deobfuscate/Decode Files or Information
Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.
* © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.