ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1140×

301 examples

TechniqueUsed byProcedure example
T1140
Deobfuscate/Decode Files or Information
MalwareTrickBot

TrickBot decodes the configuration data and modules.

T1140
Deobfuscate/Decode Files or Information
MalwareBLINDINGCAN

BLINDINGCAN has used AES and XOR to decrypt its DLLs.

T1140
Deobfuscate/Decode Files or Information
MalwareNinja

The Ninja loader component can decrypt and decompress the payload.

T1140
Deobfuscate/Decode Files or Information
MalwarePikabot

Pikabot decrypts command and control URIs using ADVobfuscator, and decrypts IP addresses and port numbers with a custom algorithm. Other versions of Pikabot decode chunks of stored stage 2 payload content in the initial payload .text section before consolidating them for further execution. Overall LunarMail is associated with multiple encoding and encryption mechanisms to obfuscate the malware's presence and avoid analysis or detection.

T1140
Deobfuscate/Decode Files or Information
MalwareSpark

Spark has used a custom XOR algorithm to decrypt the payload.

T1140
Deobfuscate/Decode Files or Information
MalwareBumblebee

Bumblebee can deobfuscate C2 server responses and unpack its code on targeted hosts.

T1140
Deobfuscate/Decode Files or Information
MalwareBRICKSTORM

BRICKSTORM has decoded its encrypted C2 traffic prior to execution. BRICKSTORM also has the ability to decode its obfuscated payload before execution.

T1140
Deobfuscate/Decode Files or Information
MalwareAmadey

Amadey has decoded antivirus name strings.

T1140
Deobfuscate/Decode Files or Information
MalwareTorisma

Torisma has used XOR and Base64 to decode C2 data.

T1140
Deobfuscate/Decode Files or Information
MalwareNOKKI

NOKKI uses a unique, custom de-obfuscation technique.

T1140
Deobfuscate/Decode Files or Information
MalwareStuxnet

Stuxnet decrypts resources that are loaded into memory and executed.

T1140
Deobfuscate/Decode Files or Information
MalwareIronWind

IronWind can deobfuscate the next stage payload using Base64 and XOR operations with the key "53".

T1140
Deobfuscate/Decode Files or Information
MalwareRotaJakiro

RotaJakiro uses the AES algorithm, bit shifts in a function called `rotate`, and an XOR cipher to decrypt resources required for persistence, process guarding, and file locking. It also performs this same function on encrypted stack strings and the `head` and `key` sections in the network packet structure used for C2 communications.

T1140
Deobfuscate/Decode Files or Information
MalwareAvosLocker

AvosLocker has deobfuscated XOR-encoded strings.

T1140
Deobfuscate/Decode Files or Information
MalwareChinoxy

The Chinoxy dropping function can initiate decryption of its config file.

T1140
Deobfuscate/Decode Files or Information
MalwareSharpStage

SharpStage has decompressed data received from the C2 server.

T1140
Deobfuscate/Decode Files or Information
MalwareCOATHANGER

COATHANGER decodes configuration items from a bundled file for command and control activity.

T1140
Deobfuscate/Decode Files or Information
MalwareSardonic

Sardonic can first decrypt with the RC4 algorithm using a hardcoded decryption key before decompressing.

T1140
Deobfuscate/Decode Files or Information
MalwareSmoke Loader

Smoke Loader deobfuscates its code.

T1140
Deobfuscate/Decode Files or Information
MalwareWindTail

WindTail has the ability to decrypt strings using hard-coded AES keys.

T1140
Deobfuscate/Decode Files or Information
MalwareExaramel for Linux

Exaramel for Linux can decrypt its configuration file.

T1140
Deobfuscate/Decode Files or Information
MalwarePS1

PS1 can use an XOR key to decrypt a PowerShell loader and payload binary.

T1140
Deobfuscate/Decode Files or Information
MalwareHeartCrypt

HeartCrypt can decrypt payloads prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareUrsnif

Ursnif has used crypto key information stored in the Registry to decrypt Tor clients dropped to disk.

T1140
Deobfuscate/Decode Files or Information
MalwareCASTLETAP

CASTLETAP can filter and deobfuscate an XOR encrypted activation string in the payload of an ICMP echo request.

T1140
Deobfuscate/Decode Files or Information
MalwareThreatNeedle

ThreatNeedle can decrypt its payload using RC4, AES, or one-byte XORing.

T1140
Deobfuscate/Decode Files or Information
MalwareRansomHub

RansomHub can use a provided passphrase to decrypt its configuration file.

T1140
Deobfuscate/Decode Files or Information
MalwareTsundere Botnet

Tsundere Botnet’s loader has decrypted obfuscated JavaScript files using the AES-256 CBC algorithm, a build-specific key, and initialization vector.

T1140
Deobfuscate/Decode Files or Information
MalwareZeus Panda

Zeus Panda decrypts strings in the code during the execution process.

T1140
Deobfuscate/Decode Files or Information
MalwareInvisibleFerret

InvisibleFerret has decoded XOR-encrypted and Base-64-encoded payloads prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareBankshot

Bankshot decodes embedded XOR strings.

T1140
Deobfuscate/Decode Files or Information
MalwarexCaon

xCaon has decoded strings from the C2 server before executing commands.

T1140
Deobfuscate/Decode Files or Information
MalwareAuditCred

AuditCred uses XOR and RC4 to perform decryption on the code functions.

T1140
Deobfuscate/Decode Files or Information
MalwareROAMINGHOUSE

ROAMINGHOUSE can decode and drop a malicious ZIP file prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareTONESHELL

TONESHELL has decoded its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareUPSTYLE

UPSTYLE encodes its main content prior to loading via Python as base64-encoded blobs.

T1140
Deobfuscate/Decode Files or Information
MalwareMedusa Ransomware

Medusa Ransomware has decoded XOR encrypted strings prior to execution in memory.

T1140
Deobfuscate/Decode Files or Information
MalwareRainyDay

RainyDay can decrypt its payload via a XOR key.

T1140
Deobfuscate/Decode Files or Information
MalwareEcipekac

Ecipekac has the ability to decrypt fileless loader modules.

T1140
Deobfuscate/Decode Files or Information
MalwareAppleSeed

AppleSeed can decode its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareBUSHWALK

BUSHWALK can Base64 decode and RC4 decrypt malicious payloads sent through a web request’s command parameter.

T1140
Deobfuscate/Decode Files or Information
MalwarePyDCrypt

PyDCrypt has decrypted and dropped the DCSrv payload to disk.

T1140
Deobfuscate/Decode Files or Information
MalwarePowerExchange

PowerExchange can decode and decrypt C2 commands received via email.

T1140
Deobfuscate/Decode Files or Information
MalwareBOOKWORM

BOOKWORM has decoded its Base64 encoded payload prior to execution. BOOKWORM has also encrypted files with RC4 and has decrypted its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareEnvyScout

EnvyScout can deobfuscate and write malicious ISO files to disk.

T1140
Deobfuscate/Decode Files or Information
MalwareAria-body

Aria-body has the ability to decrypt the loader configuration and payload DLL.

T1140
Deobfuscate/Decode Files or Information
MalwareEmotet

Emotet has used a self-extracting RAR file to deliver modules to victims. Emotet has also extracted embedded executables from files using hard-coded buffer offsets.

T1140
Deobfuscate/Decode Files or Information
MalwareCrimson

Crimson can decode its encoded PE file prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareTEARDROP

TEARDROP was decoded using a custom rolling XOR algorithm to execute a customized Cobalt Strike payload.

T1140
Deobfuscate/Decode Files or Information
MalwareDUSTTRAP

DUSTTRAP deobfuscates embedded payloads.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.