Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1132.001 Standard Encoding |
MalwareDaserf | Daserf uses custom base64 encoding to obfuscate HTTP traffic. |
| T1132.001 Standard Encoding |
MalwareSolar | Solar can Base64-encode and gzip compress C2 communications including command outputs. |
| T1132.001 Standard Encoding |
MalwarePisloader | Responses from the Pisloader C2 server are base32-encoded. |
| T1132.001 Standard Encoding |
MalwareRamsay | Ramsay has used base64 to encode its C2 traffic. |
| T1132.001 Standard Encoding |
MalwareRevenge RAT | Revenge RAT uses Base64 to encode information sent to the C2 server. |
| T1132.001 Standard Encoding |
MalwareMore_eggs | More_eggs has used basE91 encoding, along with encryption, for C2 communication. |
| T1132.001 Standard Encoding |
MalwareSysUpdate | SysUpdate has used Base64 to encode its C2 traffic. |
| T1132.001 Standard Encoding |
MalwareMango | Mango can receive Base64-encoded commands from C2. |
| T1132.001 Standard Encoding |
MalwareWIREFIRE | WIREFIRE can Base64 encode process output sent to C2. |
| T1132.001 Standard Encoding |
MalwareKessel | Kessel has exfiltrated data via hexadecimal-encoded subdomain fields of DNS queries. |
| T1132.001 Standard Encoding |
MalwareGrimAgent | GrimAgent can base64 encode C2 replies. |
| T1132.001 Standard Encoding |
MalwareSTEADYPULSE | STEADYPULSE can transmit URL encoded data over C2. |
| T1132.001 Standard Encoding |
MalwareSLIGHTPULSE | SLIGHTPULSE can base64 encode all incoming and outgoing C2 messages. |
| T1132.001 Standard Encoding |
MalwareBabyShark | BabyShark has encoded data using certutil before exfiltration. |
| T1132.001 Standard Encoding |
MalwareCreepySnail | CreepySnail can use Base64 to encode its C2 traffic. |
| T1132.001 Standard Encoding |
MalwareTroll Stealer | Troll Stealer performs XOR encryption and Base64 encoding of data prior to sending to command and control infrastructure. |
| T1132.001 Standard Encoding |
MalwareEbury | Ebury has encoded C2 traffic in hexadecimal format. |
| T1132.001 Standard Encoding |
MalwarenjRAT | njRAT uses Base64 encoding for C2 traffic. |
| T1132.001 Standard Encoding |
MalwareChChes | ChChes can encode C2 data with a custom technique that utilizes Base64. |
| T1132.001 Standard Encoding |
MalwareManjusaka | Manjusaka communication includes a client-created session cookie with base64-encoded information representing information from the victim system. |
| T1132.001 Standard Encoding |
MalwareSideTwist | SideTwist has used Base64 for encoded C2 traffic. |
| T1132.001 Standard Encoding |
MalwareMechaFlounder | MechaFlounder has the ability to use base16 encoded strings in C2. |
| T1132.001 Standard Encoding |
MalwareMis-Type | Mis-Type uses Base64 encoding for C2 traffic. |
| T1132.001 Standard Encoding |
MalwareLunarWeb | LunarWeb can use Base64 encoding to obfuscate C2 commands. |
| T1132.001 Standard Encoding |
MalwareDipsind | Dipsind encodes C2 traffic with base64. |
| T1132.001 Standard Encoding |
MalwareOctopus | Octopus has encoded C2 communications in Base64. |
| T1132.001 Standard Encoding |
MalwareSTARWHALE | STARWHALE has the ability to hex-encode collected data from an infected host. |
| T1132.001 Standard Encoding |
MalwareKevin | Kevin can Base32 encode chunks of output files during exfiltration. |
| T1132.001 Standard Encoding |
MalwarePOWERSTATS | POWERSTATS encoded C2 traffic with base64. |
| T1132.001 Standard Encoding |
MalwareBADNEWS | BADNEWS encodes C2 traffic with base64. |
| T1132.001 Standard Encoding |
MalwareAstaroth | Astaroth encodes data using Base64 before sending it to the C2 server. |
| T1132.001 Standard Encoding |
MalwareQakBot | QakBot can Base64 encode system information sent to C2. |
| T1132.001 Standard Encoding |
MalwareHelminth | For C2 over HTTP, Helminth encodes data with base64 and sends it via the "Cookie" field of HTTP requests. For C2 over DNS, Helminth converts ASCII characters into their hexadecimal values and sends the data in cleartext. |
| T1132.001 Standard Encoding |
MalwareDenis | Denis encodes the data sent to the server in Base64. |
| T1132.001 Standard Encoding |
MalwareAutoIt backdoor | AutoIt backdoor has sent a C2 response that was base64-encoded. |
| T1132.001 Standard Encoding |
MalwareUPPERCUT | UPPERCUT can base64 encode C2 communications. |
| T1132.001 Standard Encoding |
MalwareADVSTORESHELL | C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding. |
| T1132.001 Standard Encoding |
ToolSliver | Sliver can use standard encoding techniques like gzip and hex to ASCII to encode the C2 communication payload. |
| T1132.001 Standard Encoding |
ToolRemcos | Remcos can serialize collected data with Protobuf. |
| T1132.001 Standard Encoding |
MalwareMini Shai-Hulud | Mini Shai-Hulud has used base64 encoding to obfuscate URLs used for C2. |
| T1132.002 Non-Standard Encoding |
MalwareNinja | Ninja can encode C2 communications with a base64 algorithm using a custom alphabet. |
| T1132.002 Non-Standard Encoding |
MalwareBankshot | Bankshot encodes commands from the control server using a range of characters and gzip. |
| T1132.002 Non-Standard Encoding |
MalwareTONESHELL | TONESHELL has encoded a payload with a random 32-byte key using XOR. TONESHELL has also encoded payloads with a 256-byte key using XOR. |
| T1132.002 Non-Standard Encoding |
MalwareOceanSalt | OceanSalt can encode data with a NOT operation before sending the data to the control server. |
| T1132.002 Non-Standard Encoding |
MalwareInvisiMole | InvisiMole can use a modified base32 encoding to encode data within the subdomain of C2 requests. |
| T1132.002 Non-Standard Encoding |
MalwareRDAT | RDAT can communicate with the C2 via subdomains that utilize base64 with character substitutions. |
| T1132.002 Non-Standard Encoding |
MalwareHTTPTroy | HTTPTroy has obfuscated HTTP POST request communications utilizing XOR with a designated key of 0x56, followed by Base64 encoding. |
| T1132.002 Non-Standard Encoding |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use a custom Base64 alphabet for encoding C2. |
| T1132.002 Non-Standard Encoding |
MalwareUroburos | Uroburos can use a custom base62 and a de-facto base32 encoding that uses digits 0-9 and lowercase letters a-z in C2 communications. |
| T1132.002 Non-Standard Encoding |
MalwareNightClub | NightClub has used a non-standard encoding in DNS tunneling removing any `=` from the result of base64 encoding, and replacing `/` characters with `-s` and `+` characters with `-p`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.