ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1140×

301 examples

TechniqueUsed byProcedure example
T1140
Deobfuscate/Decode Files or Information
MalwareTurian

Turian has the ability to use a XOR decryption key to extract C2 server domains and IP addresses.

T1140
Deobfuscate/Decode Files or Information
MalwareTHINCRUST

THINCRUST can deobfuscate RSA encrypted C2 commands received through the DEVICEID cookie.

T1140
Deobfuscate/Decode Files or Information
MalwareMachete

Machete’s downloaded data is decrypted using AES.

T1140
Deobfuscate/Decode Files or Information
MalwarePowerLess

PowerLess can use base64 and AES ECB decryption prior to execution of downloaded modules.

T1140
Deobfuscate/Decode Files or Information
MalwareAction RAT

Action RAT can use Base64 to decode actor-controlled C2 server communications.

T1140
Deobfuscate/Decode Files or Information
MalwareAvenger

Avenger has the ability to decrypt files downloaded from C2.

T1140
Deobfuscate/Decode Files or Information
MalwareDUSTPAN

DUSTPAN decodes and decrypts embedded payloads.

T1140
Deobfuscate/Decode Files or Information
MalwarePUBLOAD

PUBLOAD has decoded its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareSystemBC

SystemBC has the ability to decrypt RC4 encrypted packets and to decode obfuscated data before C2 communication. Additionally, SystemBC has decrypted its config file that was encoded with XOR and a hardcoded 40-byte key.

T1140
Deobfuscate/Decode Files or Information
MalwareGootloader

Gootloader has the ability to decode and decrypt malicious payloads prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwarePingPull

PingPull can decrypt received data from its C2 server by using AES.

T1140
Deobfuscate/Decode Files or Information
MalwareWellMess

WellMess can decode and decrypt data received from C2.

T1140
Deobfuscate/Decode Files or Information
MalwareDropBook

DropBook can unarchive data downloaded from the C2 to obtain the payload and persistence modules.

T1140
Deobfuscate/Decode Files or Information
MalwareWoody RAT

Woody RAT can deobfuscate Base64-encoded strings and scripts.

T1140
Deobfuscate/Decode Files or Information
MalwareMafalda

Mafalda can decrypt files and data.

T1140
Deobfuscate/Decode Files or Information
MalwareSquirrelwaffle

Squirrelwaffle has decrypted files and payloads using a XOR-based algorithm.

T1140
Deobfuscate/Decode Files or Information
MalwarePolyglotDuke

PolyglotDuke can use a custom algorithm to decrypt strings used by the malware.

T1140
Deobfuscate/Decode Files or Information
MalwareHexEval Loader

HexEval Loader has decoded its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareHildegard

Hildegard has decrypted ELF files with AES.

T1140
Deobfuscate/Decode Files or Information
MalwareSombRAT

SombRAT can run upload to decrypt and upload files from storage.

T1140
Deobfuscate/Decode Files or Information
MalwareODAgent

ODAgent can Base64-decode and XOR decrypt received C2 commands.

T1140
Deobfuscate/Decode Files or Information
MalwareSnip3

Snip3 can decode its second-stage PowerShell script prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareFYAnti

FYAnti has the ability to decrypt an embedded .NET module.

T1140
Deobfuscate/Decode Files or Information
MalwareCuckoo Stealer

Cuckoo Stealer strings are deobfuscated prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareWastedLocker

WastedLocker's custom cryptor, CryptOne, used an XOR based algorithm to decrypt the payload.

T1140
Deobfuscate/Decode Files or Information
MalwareRegDuke

RegDuke can decrypt strings with a key either stored in the Registry or hardcoded in the code.

T1140
Deobfuscate/Decode Files or Information
MalwareInvisiMole

InvisiMole can decrypt, unpack and load a DLL from its resources, or from blobs encrypted with Data Protection API, two-key triple DES, and variations of the XOR cipher.

T1140
Deobfuscate/Decode Files or Information
MalwareCLAIMLOADER

CLAIMLOADER has decoded its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareP.A.S. Webshell

P.A.S. Webshell can use a decryption mechanism to process a user supplied password and allow execution.

T1140
Deobfuscate/Decode Files or Information
MalwareApostle

Apostle compiled code is obfuscated in an unspecified fashion prior to delivery to victims.

T1140
Deobfuscate/Decode Files or Information
MalwareVolgmer

Volgmer deobfuscates its strings and APIs once its executed.

T1140
Deobfuscate/Decode Files or Information
MalwareWhisperGate

WhisperGate can deobfuscate downloaded files stored in reverse byte order and decrypt embedded resources using multiple XOR operations.

T1140
Deobfuscate/Decode Files or Information
MalwareZeroT

ZeroT shellcode decrypts and decompresses its RC4-encrypted payload.

T1140
Deobfuscate/Decode Files or Information
MalwareRDAT

RDAT can deobfuscate the base64-encoded and AES-encrypted files downloaded from the C2 server.

T1140
Deobfuscate/Decode Files or Information
MalwareSkidmap

Skidmap has the ability to download, unpack, and decrypt tar.gz files .

T1140
Deobfuscate/Decode Files or Information
MalwareOkrum

Okrum's loader can decrypt the backdoor code, embedded within the loader or within a legitimate PNG file. A custom XOR cipher or RC4 is used for decryption.

T1140
Deobfuscate/Decode Files or Information
MalwareLine Dancer

Line Dancer shellcode payloads are base64 encoded when transmitted to compromised devices.

T1140
Deobfuscate/Decode Files or Information
MalwareConti

Conti has decrypted its payload using a hardcoded AES-256 key.

T1140
Deobfuscate/Decode Files or Information
MalwareRaspberry Robin

Raspberry Robin contains several layers of obfuscation to hide malicious code from detection and analysis.

T1140
Deobfuscate/Decode Files or Information
MalwareMispadu

Mispadu decrypts its encrypted configuration files prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareREPTILE

The REPTILE launcher component can decrypt kernel module code from a file and load it into memory.

T1140
Deobfuscate/Decode Files or Information
MalwareRaindrop

Raindrop decrypted its Cobalt Strike payload using an AES-256 encryption algorithm in CBC mode with a unique key per sample.

T1140
Deobfuscate/Decode Files or Information
MalwareSiloscape

Siloscape has decrypted the password of the C2 server with a simple byte by byte XOR. Siloscape also writes both an archive of Tor and the unzip binary to disk from data embedded within the payload using Visual Studio’s Resource Manager.

T1140
Deobfuscate/Decode Files or Information
MalwareRustyWater

RustyWater has used the WriteHexToFile function to transform an embedded hex string to the payload CertificationKit.ini.

T1140
Deobfuscate/Decode Files or Information
MalwareVERMIN

VERMIN decrypts code, strings, and commands to use once it's on the victim's machine.

T1140
Deobfuscate/Decode Files or Information
MalwareNightdoor

Nightdoor stores network configuration data in a file XOR encoded with the key value of `0x7A`.

T1140
Deobfuscate/Decode Files or Information
MalwareHTTPTroy

HTTPTroy has decoded strings encoded with Base64 and XOR prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareHUI Loader

HUI Loader can decrypt and load files containing malicious payloads.

T1140
Deobfuscate/Decode Files or Information
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use an embedded RC4 key to decrypt Windows API function strings.

T1140
Deobfuscate/Decode Files or Information
MalwareFatDuke

FatDuke can decrypt AES encrypted C2 communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.