Real-world descriptions of how a group, tool or campaign used a technique.
195 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareTrickBot | TrickBot uses an AES CBC (256 bits) encryption algorithm for its loader and configuration files. |
| T1027.013 Encrypted/Encoded File |
MalwareBLINDINGCAN | BLINDINGCAN has obfuscated code using Base64 encoding. |
| T1027.013 Encrypted/Encoded File |
MalwareNinja | The Ninja payload is XOR encrypted and compressed. Ninja has also XORed its configuration data with a constant value of `0xAA`. |
| T1027.013 Encrypted/Encoded File |
MalwareBRICKSTORM | BRICKSTORM has utilized XOR cipher encryption to hide key strings within their code, to include IPv4 addresses of public DNS-over-HTTPS (DOH) servers. |
| T1027.013 Encrypted/Encoded File |
MalwareTorisma | Torisma has been Base64 encoded and AES encrypted. |
| T1027.013 Encrypted/Encoded File |
MalwareDOGCALL | DOGCALL is encrypted using single-byte XOR. |
| T1027.013 Encrypted/Encoded File |
MalwareStuxnet | Stuxnet uses encrypted configuration blocks and writes encrypted files to disk. |
| T1027.013 Encrypted/Encoded File |
MalwareMEDUSA | MEDUSA can XOR encrypt configuration strings. |
| T1027.013 Encrypted/Encoded File |
MalwareVersaMem | VersaMem encrypted captured credentials with AES then Base64 encoded them before writing to local storage. |
| T1027.013 Encrypted/Encoded File |
MalwareChinoxy | Chinoxy has encrypted its configuration file. |
| T1027.013 Encrypted/Encoded File |
MalwarePAKLOG | PAKLOG has utilized a simple encoding mechanism to encode characters in the buffer. |
| T1027.013 Encrypted/Encoded File |
MalwareSmoke Loader | Smoke Loader uses a simple one-byte XOR method to obfuscate values in the malware. |
| T1027.013 Encrypted/Encoded File |
MalwareWindTail | WindTail can be delivered as a compressed, encrypted, and encoded payload. |
| T1027.013 Encrypted/Encoded File |
MalwareEmissary | Variants of Emissary encrypt payloads using various XOR ciphers, as well as a custom algorithm that uses the "srand" and "rand" functions. |
| T1027.013 Encrypted/Encoded File |
MalwareExaramel for Linux | Exaramel for Linux uses RC4 for encrypting the configuration. |
| T1027.013 Encrypted/Encoded File |
MalwareHAWKBALL | HAWKBALL has encrypted the payload with an XOR-based algorithm. |
| T1027.013 Encrypted/Encoded File |
MalwarePS1 | PS1 is distributed as a set of encrypted files and scripts. |
| T1027.013 Encrypted/Encoded File |
MalwareHeartCrypt | HeartCrypt strings are encrypted via a single-byte XOR operation rotating over a hard-coded key, possibly provided by the PaaS customers. |
| T1027.013 Encrypted/Encoded File |
MalwareUrsnif | Ursnif has used an XOR-based algorithm to encrypt Tor clients dropped to disk. Ursnif droppers have also been delivered as password-protected zip files that execute base64 encoded PowerShell commands. |
| T1027.013 Encrypted/Encoded File |
MalwareThreatNeedle | ThreatNeedle has been compressed and obfuscated using RC4, AES, or XOR. |
| T1027.013 Encrypted/Encoded File |
MalwareRansomHub | RansomHub has an encrypted configuration file. |
| T1027.013 Encrypted/Encoded File |
MalwareRedLeaves | A RedLeaves configuration file is encrypted with a simple XOR key, 0x53. |
| T1027.013 Encrypted/Encoded File |
MalwareTsundere Botnet | Tsundere Botnet’s loader contained AES-CBC/PKCS7 encrypted blobs, which were descrypted and written to disk. |
| T1027.013 Encrypted/Encoded File |
MalwareZeus Panda | Zeus Panda encrypts strings with XOR. Zeus Panda also encrypts all configuration and settings in AES and RC4. |
| T1027.013 Encrypted/Encoded File |
MalwareCARROTBAT | CARROTBAT has the ability to download a base64 encoded payload. |
| T1027.013 Encrypted/Encoded File |
MalwareGravityRAT | GravityRAT supports file encryption (AES with the key "lolomycin2017"). |
| T1027.013 Encrypted/Encoded File |
MalwareInvisibleFerret | InvisibleFerret has utilized the XOR and Base64 encoding for each of its modules. InvisibleFerret has also obfuscated files with a combination of zlib, Base64 and reverse string order. InvisibleFerret has also utilized the XOR and Base64 encoding some of its Python scripts. |
| T1027.013 Encrypted/Encoded File |
MalwareStrongPity | StrongPity has used encrypted strings in its dropper component. |
| T1027.013 Encrypted/Encoded File |
MalwareAuditCred | AuditCred encrypts the configuration. |
| T1027.013 Encrypted/Encoded File |
MalwareROAMINGHOUSE | ROAMINGHOUSE can embed a ZIP file containing UPPERCUT components into three base64 encoded parts. |
| T1027.013 Encrypted/Encoded File |
MalwareUPSTYLE | UPSTYLE stores primary content as base64-encoded objects. |
| T1027.013 Encrypted/Encoded File |
MalwareMedusa Ransomware | Medusa Ransomware has utilized XOR encrypted strings. |
| T1027.013 Encrypted/Encoded File |
MalwareRainyDay | RainyDay has downloaded as a XOR-encrypted payload. |
| T1027.013 Encrypted/Encoded File |
MalwarePyDCrypt | PyDCrypt has been compiled and encrypted with PyInstaller, specifically using the --key flag during the build phase. |
| T1027.013 Encrypted/Encoded File |
MalwareBOOKWORM | BOOKWORM has utilized Base64 encoding to obfuscate its payload. |
| T1027.013 Encrypted/Encoded File |
MalwareEnvyScout | EnvyScout can Base64 encode payloads. |
| T1027.013 Encrypted/Encoded File |
MalwareGreyEnergy | GreyEnergy encrypts its configuration files with AES-256 and also encrypts its strings. |
| T1027.013 Encrypted/Encoded File |
MalwareAria-body | Aria-body has used an encrypted configuration file for its loader. |
| T1027.013 Encrypted/Encoded File |
MalwareEmotet | Emotet uses obfuscated URLs to download a ZIP file. |
| T1027.013 Encrypted/Encoded File |
MalwareDUSTTRAP | DUSTTRAP begins with an initial launcher that decrypts an AES-128-CFB encrypted file on disk and executes it in memory. |
| T1027.013 Encrypted/Encoded File |
MalwareAvenger | Avenger has the ability to XOR encrypt files to be sent to C2. |
| T1027.013 Encrypted/Encoded File |
MalwareDUSTPAN | DUSTPAN decrypts an embedded payload. |
| T1027.013 Encrypted/Encoded File |
MalwarePrikormka | Some resources in Prikormka are encrypted with a simple XOR operation or encoded with Base64. |
| T1027.013 Encrypted/Encoded File |
MalwareDacls | Dacls can encrypt its configuration file with AES CBC. |
| T1027.013 Encrypted/Encoded File |
MalwareWoody RAT | Woody RAT has used Base64 encoded strings and scripts. |
| T1027.013 Encrypted/Encoded File |
MalwareMafalda | Mafalda has been obfuscated and contains encrypted functions. |
| T1027.013 Encrypted/Encoded File |
MalwareSquirrelwaffle | Squirrelwaffle has been obfuscated with a XOR-based algorithm. |
| T1027.013 Encrypted/Encoded File |
MalwareHexEval Loader | HexEval Loader has encoded module names and C2 URLs as hexadecimal strings in attempts to evade analysis. |
| T1027.013 Encrypted/Encoded File |
MalwareHildegard | Hildegard has encrypted an ELF file. |
| T1027.013 Encrypted/Encoded File |
MalwareFlawedGrace | FlawedGrace encrypts its C2 configuration files with AES in CBC mode. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.