ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1140
Deobfuscate/Decode Files or Information
MalwareNightdoor

Nightdoor stores network configuration data in a file XOR encoded with the key value of `0x7A`.

T1140
Deobfuscate/Decode Files or Information
MalwareHTTPTroy

HTTPTroy has decoded strings encoded with Base64 and XOR prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareHUI Loader

HUI Loader can decrypt and load files containing malicious payloads.

T1140
Deobfuscate/Decode Files or Information
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use an embedded RC4 key to decrypt Windows API function strings.

T1140
Deobfuscate/Decode Files or Information
MalwareFatDuke

FatDuke can decrypt AES encrypted C2 communications.

T1140
Deobfuscate/Decode Files or Information
MalwareLucifer

Lucifer can decrypt its C2 address upon execution.

T1140
Deobfuscate/Decode Files or Information
MalwareGLASSTOKEN

GLASSTOKEN has the ability to decode hexadecimal and Base64 C2 requests.

T1140
Deobfuscate/Decode Files or Information
MalwareBOOSTWRITE

BOOSTWRITE has used a a 32-byte long multi-XOR key to decode data inside its payload.

T1140
Deobfuscate/Decode Files or Information
MalwareRising Sun

Rising Sun has decrypted itself using a single-byte XOR scheme. Additionally, Rising Sun can decrypt its configuration data at runtime.

T1140
Deobfuscate/Decode Files or Information
MalwareShimRat

ShimRat has decompressed its core DLL using shellcode once an impersonated antivirus component was running on a system.

T1140
Deobfuscate/Decode Files or Information
MalwareChrommme

Chrommme can decrypt its encrypted internal code.

T1140
Deobfuscate/Decode Files or Information
MalwareAvaddon

Avaddon has decrypted encrypted strings.

T1140
Deobfuscate/Decode Files or Information
MalwareGreen Lambert

Green Lambert can use multiple custom routines to decrypt strings prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareISMInjector

ISMInjector uses the certutil command to decode a payload file.

T1140
Deobfuscate/Decode Files or Information
MalwarePUNCHBUGGY

PUNCHBUGGY has used PowerShell to decode base64-encoded assembly.

T1140
Deobfuscate/Decode Files or Information
MalwareGoldMax

GoldMax has decoded and decrypted the configuration file when executed.

T1140
Deobfuscate/Decode Files or Information
MalwareCostaBricks

CostaBricks has the ability to use bytecode to decrypt embedded payloads.

T1140
Deobfuscate/Decode Files or Information
MalwareLIGHTWIRE

LIGHTWIRE can RC4 decrypt and Base64 decode C2 commands.

T1140
Deobfuscate/Decode Files or Information
MalwareHyperBro

HyperBro can unpack and decrypt its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwarePteranodon

Pteranodon can decrypt encrypted data strings prior to using them.

T1140
Deobfuscate/Decode Files or Information
MalwareDarkTortilla

DarkTortilla can decrypt its payload and associated configuration elements using the Rijndael cipher.

T1140
Deobfuscate/Decode Files or Information
MalwareROKRAT

ROKRAT can decrypt strings using the victim's hostname as the key.

T1140
Deobfuscate/Decode Files or Information
MalwareSplatDropper

SplatDropper has decoded XOR encrypted payload.

T1140
Deobfuscate/Decode Files or Information
MalwareBabuk

Babuk has the ability to unpack itself into memory using XOR.

T1140
Deobfuscate/Decode Files or Information
MalwareExbyte

Exbyte decodes and decrypts data stored in the configuration file with a key provided on the command line during execution.

T1140
Deobfuscate/Decode Files or Information
MalwareDarkWatchman

DarkWatchman has the ability to self-extract as a RAR archive.

T1140
Deobfuscate/Decode Files or Information
MalwareDyre

Dyre decrypts resources needed for targeting the victim.

T1140
Deobfuscate/Decode Files or Information
MalwareLunarLoader

LunarLoader can deobfuscate files containing the next stages in the infection chain.

T1140
Deobfuscate/Decode Files or Information
MalwareBBSRAT

BBSRAT uses Expand to decompress a CAB file into executable content.

T1140
Deobfuscate/Decode Files or Information
MalwarePlugX

PlugX decompresses and decrypts itself using the Microsoft API call RtlDecompressBuffer. PlugX has also decrypted its payloads in memory.

T1140
Deobfuscate/Decode Files or Information
MalwareBisonal

Bisonal has decoded strings in the malware using XOR and RC4.

T1140
Deobfuscate/Decode Files or Information
MalwareNOOPLDR

NOOPLDR can decrypt its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareLumma Stealer

Lumma Stealer has used Base64-encoded content during execution, decoded via PowerShell.

T1140
Deobfuscate/Decode Files or Information
MalwareLightNeuron

LightNeuron has used AES and XOR to decrypt configuration files and commands.

T1140
Deobfuscate/Decode Files or Information
MalwareKEYPLUG

KEYPLUG can decode its configuration file to determine C2 protocols.

T1140
Deobfuscate/Decode Files or Information
MalwareClambling

Clambling can deobfuscate its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwarePureCrypter

PureCrypter can decrypt downloaded resources and parse internal files to determine its settings.

T1140
Deobfuscate/Decode Files or Information
MalwareDarkGate

DarkGate installation includes binary code stored in a file located in a hidden directory, such as shell.txt, that is decrypted then executed. DarkGate uses hexadecimal-encoded shellcode payloads during installation that are called via Windows API CallWindowProc() to decode and then execute.

T1140
Deobfuscate/Decode Files or Information
MalwareMongall

Mongall has the ability to decrypt its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareLockBit 3.0

The LockBit 3.0 payload is decrypted at runtime.

T1140
Deobfuscate/Decode Files or Information
MalwareFoggyWeb

FoggyWeb can be decrypted in memory using a Lightweight Encryption Algorithm (LEA)-128 key and decoded using a XOR key.

T1140
Deobfuscate/Decode Files or Information
MalwareNetwalker

Netwalker's PowerShell script can decode and decrypt multiple layers of obfuscation, leading to the Netwalker DLL being loaded into memory.

T1140
Deobfuscate/Decode Files or Information
MalwareTSCookie

TSCookie has the ability to decrypt, load, and execute a DLL and its resources.

T1140
Deobfuscate/Decode Files or Information
MalwareLatrodectus

Latrodectus has the ability to deobfuscate encrypted strings.

T1140
Deobfuscate/Decode Files or Information
MalwareSaint Bot

Saint Bot can deobfuscate strings and files for execution.

T1140
Deobfuscate/Decode Files or Information
MalwareChaes

Chaes has decrypted an AES encrypted binary file to trigger the download of other files.

T1140
Deobfuscate/Decode Files or Information
MalwareCharmPower

CharmPower can decrypt downloaded modules prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareMuddyViper

MuddyViper has decrypted the embedded HackBrowserData tool prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareTYPEFRAME

One TYPEFRAME variant decrypts an archive using an RC4 key, then decompresses and installs the decrypted malicious DLL module. Another variant decodes the embedded file by XORing it with the value "0x35".

T1140
Deobfuscate/Decode Files or Information
MalwareBundlore

Bundlore has used openssl to decrypt AES encrypted payload data. Bundlore has also used base64 and RC4 with a hardcoded key to deobfuscate data.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.