ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1027×

138 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareTrickBot

TrickBot uses non-descriptive names to hide functionality.

T1027
Obfuscated Files or Information
MalwareEKANS

EKANS uses encoded strings in its process kill list.

T1027
Obfuscated Files or Information
MalwareSynAck

SynAck payloads are obfuscated prior to compilation to inhibit analysis and/or reverse engineering.

T1027
Obfuscated Files or Information
MalwareBumblebee

Bumblebee has been delivered as password-protected zipped ISO files and used control-flow-flattening to obfuscate the flow of functions.

T1027
Obfuscated Files or Information
MalwareBRICKSTORM

BRICKSTORM has utilized Go libraries to include Garble to obfuscate code.

T1027
Obfuscated Files or Information
MalwareAmadey

Amadey has obfuscated strings such as antivirus vendor names, domains, files, and others.

T1027
Obfuscated Files or Information
MalwareOrz

Some Orz strings are base64 encoded, such as the embedded DLL known as MockDll.

T1027
Obfuscated Files or Information
MalwareNOKKI

NOKKI uses Base64 encoding for strings.

T1027
Obfuscated Files or Information
MalwareAvosLocker

AvosLocker has used XOR-encoded strings.

T1027
Obfuscated Files or Information
MalwareCOATHANGER

COATHANGER can store obfuscated configuration information in the last 56 bytes of the file `/date/.bd.key/preload.so`.

T1027
Obfuscated Files or Information
MalwareSardonic

Sardonic can use certain ConfuserEx features for obfuscation and can be encoded in a base64 string.

T1027
Obfuscated Files or Information
MalwareMatryoshka

Matryoshka obfuscates API function names using a substitute cipher combined with Base64 encoding.

T1027
Obfuscated Files or Information
MalwareEcipekac

Ecipekac can use XOR, AES, and DES to encrypt loader shellcode.

T1027
Obfuscated Files or Information
MalwareAppleSeed

AppleSeed has the ability to Base64 encode its payload and custom encrypt API calls.

T1027
Obfuscated Files or Information
MalwareBUSHWALK

BUSHWALK can encrypt the resulting data generated from C2 commands with RC4.

T1027
Obfuscated Files or Information
MalwareNETWIRE

NETWIRE has used a custom obfuscation algorithm to hide strings including Registry keys, APIs, and DLL names.

T1027
Obfuscated Files or Information
MalwareBOOKWORM

BOOKWORM has been delivered using self-extracting RAR archives.

T1027
Obfuscated Files or Information
MalwareOLDBAIT

OLDBAIT obfuscates internal strings and unpacks them at startup.

T1027
Obfuscated Files or Information
MalwareTEARDROP

TEARDROP created and read from a file with a fake JPG header, and its payload was encrypted with a simple rotating XOR cipher.

T1027
Obfuscated Files or Information
MalwareTurian

Turian can use VMProtect for obfuscation.

T1027
Obfuscated Files or Information
MalwareAction RAT

Action RAT's commands, strings, and domains can be Base64 encoded within the payload.

T1027
Obfuscated Files or Information
MalwarePUBLOAD

PUBLOAD has obfuscated DLL names using the ror13AddHash32 algorithm.

T1027
Obfuscated Files or Information
MalwareGootloader

The Gootloader first stage script is obfuscated using random alpha numeric strings.

T1027
Obfuscated Files or Information
MalwarePolyglotDuke

PolyglotDuke can custom encrypt strings.

T1027
Obfuscated Files or Information
MalwareSombRAT

SombRAT can encrypt strings with XOR-based routines and use a custom AES storage format for plugins, configuration, C2 domains, and harvested data.

T1027
Obfuscated Files or Information
MalwareSnip3

Snip3 has the ability to obfuscate strings using XOR encryption.

T1027
Obfuscated Files or Information
MalwareRegDuke

RegDuke can use control-flow flattening or the commercially available .NET Reactor for obfuscation.

T1027
Obfuscated Files or Information
MalwareInvisiMole

InvisiMole avoids analysis by encrypting all strings, internal files, configuration data and by using a custom executable format.

T1027
Obfuscated Files or Information
MalwareP.A.S. Webshell

P.A.S. Webshell can use encryption and base64 encoding to hide strings and to enforce access control once deployed.

T1027
Obfuscated Files or Information
MalwareConti

Conti can use compiler-based obfuscation for its code, encrypt DLLs, and hide Windows API calls.

T1027
Obfuscated Files or Information
MalwareRaspberry Robin

Raspberry Robin uses mixed-case letters for filenames and commands to evade detection.

T1027
Obfuscated Files or Information
MalwareDiavol

Diavol has Base64 encoded the RSA public key used for encrypting files.

T1027
Obfuscated Files or Information
MalwareSiloscape

Siloscape itself is obfuscated and uses obfuscated API calls.

T1027
Obfuscated Files or Information
MalwareRustyWater

RustyWater has an obfuscated function (i.e. love_me__()) that dynamically reconstructs the string WScript.Shell using hard-coded ASCII values and the Chr() function.

T1027
Obfuscated Files or Information
MalwareHTTPTroy

HTTPTroy has obfuscated strings using Single Instruction Multiple Data (SIMD) instructions to hinder analysis and detection.

T1027
Obfuscated Files or Information
MalwareKazuar

Kazuar is obfuscated using the open source ConfuserEx protector. Kazuar also obfuscates the name of created files/folders/mutexes and encrypts debug messages written to log files using the Rijndael cipher.

T1027
Obfuscated Files or Information
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use a custom Base64 alphabet to encode an API decryption key.

T1027
Obfuscated Files or Information
MalwareFatDuke

FatDuke can use base64 encoding, string stacking, and opaque predicates for obfuscation.

T1027
Obfuscated Files or Information
MalwareDRATzarus

DRATzarus can be partly encrypted with XOR.

T1027
Obfuscated Files or Information
MalwareSHOTPUT

SHOTPUT is obscured using XOR encoding and appended to a valid GIF file.

T1027
Obfuscated Files or Information
MalwareAvaddon

Avaddon has used encrypted strings.

T1027
Obfuscated Files or Information
MalwareConficker

Conficker has obfuscated its code to prevent its removal from host machines.

T1027
Obfuscated Files or Information
MalwareFlagpro

Flagpro has been delivered within ZIP or RAR password-protected archived files.

T1027
Obfuscated Files or Information
MalwareGreen Lambert

Green Lambert has encrypted strings.

T1027
Obfuscated Files or Information
MalwareISMInjector

ISMInjector is obfuscated with the off-the-shelf SmartAssembly .NET obfuscator created by red-gate.com.

T1027
Obfuscated Files or Information
MalwarePUNCHBUGGY

PUNCHBUGGY has hashed most its code's functions and encrypted payloads with base64 and XOR.

T1027
Obfuscated Files or Information
MalwarePOSHSPY

POSHSPY appends a file signature header (randomly selected from six file types) to encrypted data prior to upload or download.

T1027
Obfuscated Files or Information
MalwareMiniDuke

MiniDuke can use control flow flattening to obscure code.

T1027
Obfuscated Files or Information
MalwareAnchor

Anchor has obfuscated code with stack strings and string encryption.

T1027
Obfuscated Files or Information
MalwareDarkTortilla

DarkTortilla has been obfuscated with the DeepSea .NET and ConfuserEx code obfuscators.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.