ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwarePolyglotDuke

PolyglotDuke can custom encrypt strings.

T1027
Obfuscated Files or Information
MalwareSombRAT

SombRAT can encrypt strings with XOR-based routines and use a custom AES storage format for plugins, configuration, C2 domains, and harvested data.

T1027
Obfuscated Files or Information
MalwareSnip3

Snip3 has the ability to obfuscate strings using XOR encryption.

T1027
Obfuscated Files or Information
MalwareRegDuke

RegDuke can use control-flow flattening or the commercially available .NET Reactor for obfuscation.

T1027
Obfuscated Files or Information
MalwareInvisiMole

InvisiMole avoids analysis by encrypting all strings, internal files, configuration data and by using a custom executable format.

T1027
Obfuscated Files or Information
MalwareP.A.S. Webshell

P.A.S. Webshell can use encryption and base64 encoding to hide strings and to enforce access control once deployed.

T1027
Obfuscated Files or Information
MalwareConti

Conti can use compiler-based obfuscation for its code, encrypt DLLs, and hide Windows API calls.

T1027
Obfuscated Files or Information
MalwareRaspberry Robin

Raspberry Robin uses mixed-case letters for filenames and commands to evade detection.

T1027
Obfuscated Files or Information
MalwareDiavol

Diavol has Base64 encoded the RSA public key used for encrypting files.

T1027
Obfuscated Files or Information
MalwareSiloscape

Siloscape itself is obfuscated and uses obfuscated API calls.

T1027
Obfuscated Files or Information
MalwareRustyWater

RustyWater has an obfuscated function (i.e. love_me__()) that dynamically reconstructs the string WScript.Shell using hard-coded ASCII values and the Chr() function.

T1027
Obfuscated Files or Information
MalwareHTTPTroy

HTTPTroy has obfuscated strings using Single Instruction Multiple Data (SIMD) instructions to hinder analysis and detection.

T1027
Obfuscated Files or Information
MalwareKazuar

Kazuar is obfuscated using the open source ConfuserEx protector. Kazuar also obfuscates the name of created files/folders/mutexes and encrypts debug messages written to log files using the Rijndael cipher.

T1027
Obfuscated Files or Information
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use a custom Base64 alphabet to encode an API decryption key.

T1027
Obfuscated Files or Information
MalwareFatDuke

FatDuke can use base64 encoding, string stacking, and opaque predicates for obfuscation.

T1027
Obfuscated Files or Information
MalwareDRATzarus

DRATzarus can be partly encrypted with XOR.

T1027
Obfuscated Files or Information
MalwareSHOTPUT

SHOTPUT is obscured using XOR encoding and appended to a valid GIF file.

T1027
Obfuscated Files or Information
MalwareAvaddon

Avaddon has used encrypted strings.

T1027
Obfuscated Files or Information
MalwareConficker

Conficker has obfuscated its code to prevent its removal from host machines.

T1027
Obfuscated Files or Information
MalwareFlagpro

Flagpro has been delivered within ZIP or RAR password-protected archived files.

T1027
Obfuscated Files or Information
MalwareGreen Lambert

Green Lambert has encrypted strings.

T1027
Obfuscated Files or Information
MalwareISMInjector

ISMInjector is obfuscated with the off-the-shelf SmartAssembly .NET obfuscator created by red-gate.com.

T1027
Obfuscated Files or Information
MalwarePUNCHBUGGY

PUNCHBUGGY has hashed most its code's functions and encrypted payloads with base64 and XOR.

T1027
Obfuscated Files or Information
MalwarePOSHSPY

POSHSPY appends a file signature header (randomly selected from six file types) to encrypted data prior to upload or download.

T1027
Obfuscated Files or Information
MalwareMiniDuke

MiniDuke can use control flow flattening to obscure code.

T1027
Obfuscated Files or Information
MalwareAnchor

Anchor has obfuscated code with stack strings and string encryption.

T1027
Obfuscated Files or Information
MalwareDarkTortilla

DarkTortilla has been obfuscated with the DeepSea .NET and ConfuserEx code obfuscators.

T1027
Obfuscated Files or Information
MalwareROKRAT

ROKRAT can encrypt data prior to exfiltration by using an RSA public key.

T1027
Obfuscated Files or Information
MalwareCORESHELL

CORESHELL obfuscates strings using a custom stream cipher.

T1027
Obfuscated Files or Information
MalwarePlugX

PlugX can use API hashing and modify the names of strings to evade detection.

T1027
Obfuscated Files or Information
MalwareNOOPLDR

NOOPLDR can use control flow flattening to help hide malicious code.

T1027
Obfuscated Files or Information
MalwareLumma Stealer

Lumma Stealer has used SmartAssembly to obfuscate .NET payloads.

T1027
Obfuscated Files or Information
MalwareDustySky

The DustySky dropper uses a function to obfuscate the name of functions and other parts of the malware.

T1027
Obfuscated Files or Information
MalwareEpic

Epic heavily obfuscates its code to make analysis more difficult.

T1027
Obfuscated Files or Information
MalwareCuba

Cuba has used multiple layers of obfuscation to avoid analysis, including its Base64 encoded payload.

T1027
Obfuscated Files or Information
MalwareClambling

The Clambling executable has been obfuscated when dropped on a compromised host.

T1027
Obfuscated Files or Information
MalwareDarkGate

DarkGate uses a hard-coded string as a seed, along with the victim machine hardware identifier and input text, to generate a unique string used as an internal mutex value to evade static detection based on mutexes.

T1027
Obfuscated Files or Information
MalwareSVCReady

SVCReady can encrypt victim data with an RC4 cipher.

T1027
Obfuscated Files or Information
MalwareCarbanak

Carbanak encrypts strings to make analysis more difficult.

T1027
Obfuscated Files or Information
MalwareXTunnel

A version of XTunnel introduced in July 2015 obfuscated the binary using opaque predicates and other techniques in a likely attempt to obfuscate it and bypass security products.

T1027
Obfuscated Files or Information
MalwareHydraq

Hydraq uses basic obfuscation in the form of spaghetti code.

T1027
Obfuscated Files or Information
MalwareSaint Bot

Saint Bot has been obfuscated to help avoid detection.

T1027
Obfuscated Files or Information
MalwareLODEINFO

LODEINFO has used control flow flattening to obfuscate code.

T1027
Obfuscated Files or Information
MalwareBundlore

Bundlore has obfuscated data with base64, AES, RC4, and bz2.

T1027
Obfuscated Files or Information
MalwareFooder

Fooder has stored its embedded payload in encrypted form within the binary, using a hardcoded key modified at runtime to produce the AES decryption key.

T1027
Obfuscated Files or Information
MalwareTrojan.Karagany

Trojan.Karagany can base64 encode and AES-128-CBC encrypt data prior to transmission.

T1027
Obfuscated Files or Information
MalwareShamoon

Shamoon contains base64-encoded strings.

T1027
Obfuscated Files or Information
MalwareBPFDoor

BPFDoor can require a password to activate the backdoor and uses RC4 encryption or static library encryption `libtomcrypt`.

T1027
Obfuscated Files or Information
MalwareOopsIE

OopsIE uses the Confuser protector to obfuscate an embedded .Net Framework assembly used for C2. OopsIE also encodes collected data in hexadecimal format before writing to files on disk and obfuscates strings.

T1027
Obfuscated Files or Information
MalwareStreamEx

StreamEx obfuscates some commands by using statically programmed fragments of strings when starting a DLL. It also uses a one-byte xor against 0x91 to encode configuration data.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.