Create File

April 3, 2025 ยท View on GitHub

ID C0016
Objective(s) File System
Related ATT&CK Techniques None
Version 2.1
Created 14 August 2020
Last Modified 5 December 2023

Create File

Malware creates a file.

Methods

NameIDDescription
Create Office DocumentC0016.001An Office document is created.
Create Ransomware FileC0016.002Create a file used by ransomware.

Use in Malware

NameDateMethodDescription
Snake2004--Snake creates files. [1]

Detection

Tool: capaMappingAPIs
create or open fileCreate File (C0016)CreateFile, CreateFileEx, IoCreateFile, IoCreateFileEx, ZwOpenFile, ZwCreateFile, NtOpenFile, NtCreateFile, LZCreateFile, LZOpenFile, fopen, fopen64, fdopen, freopen, open, openat
Tool: CAPEClassMappingAPIs
copies_selfCopiesSelfCreate File (C0016)--
rat_pcclientPcClientMutexesCreate File (C0016)--
ransomware_radamantRansomwareRadamantCreate File (C0016)--
remcos_filesRemcosFilesCreate File (C0016)--
karagany_filesKaraganyFilesCreate File (C0016)--
obliquerat_filesObliquekRATFilesCreate File (C0016)--
ransomware_messageRansomwareMessageCreate File (C0016)NtWriteFile
rat_luminosityLuminosityRATCreate File (C0016)NtCreateFile, CryptHashData
xpertrat_filesXpertRATFilesCreate File (C0016)--
nemty_noteNemtyNoteCreate File (C0016)NtWriteFile
office_write_exeOfficeWriteEXECreate File (C0016)NtWriteFile
warzonerat_filesWarzoneRATFilesCreate File (C0016)--
spreading_autoruninfCreatesAutorunInfCreate File (C0016)--
neshta_filesNeshtaFilesCreate File (C0016)NtCreateFile
arkei_filesArkeiFilesCreate File (C0016)--
office_postscriptOfficePostScriptCreate File (C0016)NtWriteFile
rat_nanocoreNanocoreRATCreate File (C0016)CryptHashData
qulab_filesQulabFilesCreate File (C0016)--
ransomware_filesRansomwareFilesCreate File (C0016), Create File (C0016)--
ransomware_filesRansomwareFilesCreate File (C0016), Create File::Create Ransomware File (C0016.002)--
dcrat_filesDCRatFilesCreate File (C0016)--
rtf_embedded_office_fileRTFEmbeddedOfficeFileCreate File (C0016)--
rtf_embedded_office_fileRTFEmbeddedOfficeFileCreate File::Create Office Document (C0016.001)--
stack_pivot_file_createdStackPivotFileCreatedCreate File (C0016)NtCreateFile
masslogger_filesMassLoggerFilesCreate File (C0016)--
stealth_fileStealthFileCreate File (C0016)NtSetInformationFile, NtClose, NtCreateFile, NtDuplicateObject, NtOpenFile

References

[1] https://www.cybereason.com/blog/research/threat-analysis-report-snake-infostealer-malware