{ "id": "bundle--65b89dec-062b-44d5-b9c4-4edd3f855d57", "objects": [ { "created": "2018-05-31T00:00:00.000Z", "created_by_ref": "identity--e50ab59c-5c4f-4d40-bf6a-d58418d89bcd", "description": "Adversaries know that certain binaries will be regularly executed as part of normal processing. If these binaries are not protected with the appropriate file system permissions, it could be possible to replace them with malware. This malware might be executed at higher system permission levels. A variation of this pattern is to discover self-extracting installation packages that unpack binaries to directories with weak file permissions which it does not clean up appropriately. These binaries can be replaced by malware, which can then be executed.", "external_references": [ { "external_id": "CAPEC-642", "source_name": "capec", "url": "https://capec.mitre.org/data/definitions/642.html" }, { "external_id": "CWE-732", "source_name": "cwe", "url": "http://cwe.mitre.org/data/definitions/732.html" }, { "description": "Server Software Component: Terminal Services DLL", "external_id": "T1505.005", "source_name": "ATTACK", "url": "https://attack.mitre.org/wiki/Technique/T1505/005" }, { "description": "Compromise Client Software Binary", "external_id": "T1554", "source_name": "ATTACK", "url": "https://attack.mitre.org/wiki/Technique/T1554" }, { "description": "Hijack Execution Flow:Executable Installer File Permissions Weakness", "external_id": "T1574.005", "source_name": "ATTACK", "url": "https://attack.mitre.org/wiki/Technique/T1574/005" }, { "description": "Binary planting", "source_name": "OWASP Attacks", "url": "https://owasp.org/www-community/attacks/Binary_planting" } ], "id": "attack-pattern--15e6b769-4cbd-4c39-b774-b45673fd55de", "modified": "2022-09-29T00:00:00.000Z", "name": "Replace Binaries", "object_marking_refs": [ "marking-definition--17d82bb2-eeeb-4898-bda5-3ddbcd2b799d" ], "spec_version": "2.1", "type": "attack-pattern", "x_capec_abstraction": "Detailed", "x_capec_child_of_refs": [ "attack-pattern--9ad2c2eb-9939-4590-9683-2e789692d262" ], "x_capec_domains": [ "Software" ], "x_capec_example_instances": [ "The installer for a previous version of Firefox would use a DLL maliciously placed in the default download directory instead of the existing DLL located elsewhere, probably due to DLL hijacking. This DLL would be run with administrator privileges if the installer has those privileges.", "By default, the Windows screensaver application SCRNSAVE.exe leverages the scrnsave.scr Portable Executable (PE) file in C:\\Windows\\system32\\. This value is set in the registry at HKEY_CURRENT_USER\\Control Panel\\Desktop, which can be modified by an adversary to instead point to a malicious program. This program would then run any time the SCRNSAVE.exe program is activated and with administrator privileges. An adversary may additionally modify other registry values within the same location to set the SCRNSAVE.exe program to run more frequently." ], "x_capec_prerequisites": [ "The attacker must be able to place the malicious binary on the target machine." ], "x_capec_status": "Draft", "x_capec_typical_severity": "High", "x_capec_version": "3.9" } ], "type": "bundle" }