Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1140 Deobfuscate/Decode Files or Information |
MalwareNightdoor | Nightdoor stores network configuration data in a file XOR encoded with the key value of `0x7A`. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHTTPTroy | HTTPTroy has decoded strings encoded with Base64 and XOR prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHUI Loader | HUI Loader can decrypt and load files containing malicious payloads. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use an embedded RC4 key to decrypt Windows API function strings. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareFatDuke | FatDuke can decrypt AES encrypted C2 communications. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLucifer | Lucifer can decrypt its C2 address upon execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareGLASSTOKEN | GLASSTOKEN has the ability to decode hexadecimal and Base64 C2 requests. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBOOSTWRITE | BOOSTWRITE has used a a 32-byte long multi-XOR key to decode data inside its payload. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRising Sun | Rising Sun has decrypted itself using a single-byte XOR scheme. Additionally, Rising Sun can decrypt its configuration data at runtime. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareShimRat | ShimRat has decompressed its core DLL using shellcode once an impersonated antivirus component was running on a system. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareChrommme | Chrommme can decrypt its encrypted internal code. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAvaddon | Avaddon has decrypted encrypted strings. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareGreen Lambert | Green Lambert can use multiple custom routines to decrypt strings prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareISMInjector | ISMInjector uses the |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePUNCHBUGGY | PUNCHBUGGY has used PowerShell to decode base64-encoded assembly. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareGoldMax | GoldMax has decoded and decrypted the configuration file when executed. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCostaBricks | CostaBricks has the ability to use bytecode to decrypt embedded payloads. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLIGHTWIRE | LIGHTWIRE can RC4 decrypt and Base64 decode C2 commands. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHyperBro | HyperBro can unpack and decrypt its payload prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePteranodon | Pteranodon can decrypt encrypted data strings prior to using them. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDarkTortilla | DarkTortilla can decrypt its payload and associated configuration elements using the Rijndael cipher. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareROKRAT | ROKRAT can decrypt strings using the victim's hostname as the key. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSplatDropper | SplatDropper has decoded XOR encrypted payload. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBabuk | Babuk has the ability to unpack itself into memory using XOR. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareExbyte | Exbyte decodes and decrypts data stored in the configuration file with a key provided on the command line during execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDarkWatchman | DarkWatchman has the ability to self-extract as a RAR archive. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDyre | Dyre decrypts resources needed for targeting the victim. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLunarLoader | LunarLoader can deobfuscate files containing the next stages in the infection chain. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBBSRAT | BBSRAT uses Expand to decompress a CAB file into executable content. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePlugX | PlugX decompresses and decrypts itself using the Microsoft API call RtlDecompressBuffer. PlugX has also decrypted its payloads in memory. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBisonal | Bisonal has decoded strings in the malware using XOR and RC4. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareNOOPLDR | NOOPLDR can decrypt its payload prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLumma Stealer | Lumma Stealer has used Base64-encoded content during execution, decoded via PowerShell. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLightNeuron | LightNeuron has used AES and XOR to decrypt configuration files and commands. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKEYPLUG | KEYPLUG can decode its configuration file to determine C2 protocols. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareClambling | Clambling can deobfuscate its payload prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePureCrypter | PureCrypter can decrypt downloaded resources and parse internal files to determine its settings. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDarkGate | DarkGate installation includes binary code stored in a file located in a hidden directory, such as |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMongall | Mongall has the ability to decrypt its payload prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLockBit 3.0 | The LockBit 3.0 payload is decrypted at runtime. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareFoggyWeb | FoggyWeb can be decrypted in memory using a Lightweight Encryption Algorithm (LEA)-128 key and decoded using a XOR key. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareNetwalker | Netwalker's PowerShell script can decode and decrypt multiple layers of obfuscation, leading to the Netwalker DLL being loaded into memory. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTSCookie | TSCookie has the ability to decrypt, load, and execute a DLL and its resources. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLatrodectus | Latrodectus has the ability to deobfuscate encrypted strings. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSaint Bot | Saint Bot can deobfuscate strings and files for execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareChaes | Chaes has decrypted an AES encrypted binary file to trigger the download of other files. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCharmPower | CharmPower can decrypt downloaded modules prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMuddyViper | MuddyViper has decrypted the embedded HackBrowserData tool prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTYPEFRAME | One TYPEFRAME variant decrypts an archive using an RC4 key, then decompresses and installs the decrypted malicious DLL module. Another variant decodes the embedded file by XORing it with the value "0x35". |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBundlore | Bundlore has used |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.