Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareDenis | Denis obfuscates its code and encrypts the API names. |
| T1027 Obfuscated Files or Information |
MalwareComnie | Comnie uses RC4 and Base64 to obfuscate strings. |
| T1027 Obfuscated Files or Information |
MalwareLizar | Lizar has obfuscated the fingerprint of the victim system, the local IP address, and the Fowler-Noll-V 1 (FNV-1) hash of the local IP address using an XOR operation. The data is then sent to the C2 server. |
| T1027 Obfuscated Files or Information |
MalwareH1N1 | H1N1 uses multiple techniques to obfuscate strings, including XOR. |
| T1027 Obfuscated Files or Information |
MalwareSLOWPULSE | SLOWPULSE can hide malicious code in the padding regions between legitimate functions in the Pulse Secure `libdsplibs.so` file. |
| T1027 Obfuscated Files or Information |
MalwareADVSTORESHELL | Most of the strings in ADVSTORESHELL are encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed. API function names are also reversed, presumably to avoid detection in memory. |
| T1027 Obfuscated Files or Information |
MalwareSmall Sieve | Small Sieve has the ability to use a custom hex byte swapping encoding scheme combined with an obfuscated Base64 function to protect program strings and Telegram credentials. |
| T1027 Obfuscated Files or Information |
ToolShimRatReporter | ShimRatReporter encrypted gathered information with a combination of shifting and XOR using a static key. |
| T1027 Obfuscated Files or Information |
ToolSliver | Sliver obfuscates configuration and other static files using native Go libraries such as `garble` and `gobfuscate` to inhibit configuration analysis and static detection. |
| T1027 Obfuscated Files or Information |
ToolCARROTBALL | CARROTBALL has used a custom base64 alphabet to decode files. |
| T1027 Obfuscated Files or Information |
ToolBrute Ratel C4 | Brute Ratel C4 has used encrypted payload files and maintains an encrypted configuration structure in memory. |
| T1027 Obfuscated Files or Information |
ToolRemcos | Remcos uses RC4 and base64 to obfuscate data, including Registry entries and file paths. Remcos can also employ control flow flattening to hinder analysis. |
| T1027 Obfuscated Files or Information |
ToolOut1 | Out1 has the ability to encode data. |
| T1027 Obfuscated Files or Information |
ToolImminent Monitor | Imminent Monitor has encrypted the spearphish attachments to avoid detection from email gateways; the debugger also encrypts information before sending to the C2. |
| T1027 Obfuscated Files or Information |
ToolMCMD | MCMD can Base64 encode output strings prior to sending to C2. |
| T1027.001 Binary Padding |
MalwareEmissary | A variant of Emissary appends junk data to the end of its DLL file to create a large file that may exceed the maximum size that anti-virus programs can scan. |
| T1027.001 Binary Padding |
MalwareHeartCrypt | HeartCrypt can add several hundred thousand kilobytes of null padding to payloads before saving onto the file system. |
| T1027.001 Binary Padding |
MalwareTONESHELL | TONESHELL has used randomized padding to obfuscate payloads. |
| T1027.001 Binary Padding |
MalwareEmotet | Emotet inflates malicious files and malware as an evasion technique. |
| T1027.001 Binary Padding |
MalwareSnip3 | Snip3 can obfuscate strings using junk Chinese characters. |
| T1027.001 Binary Padding |
MalwareRifdoor | Rifdoor has added four additional bytes of data upon launching, then saved the changed version as |
| T1027.001 Binary Padding |
MalwareCHIMNEYSWEEP | The CHIMNEYSWEEP installer has been padded with null bytes to inflate its size. |
| T1027.001 Binary Padding |
MalwareLightSpy | LightSpy's configuration file is appended to the end of the binary. For example, the last `0x1d0` bytes of one sample is an AES encrypted configuration file with a static key of `3e2717e8b3873b29`. |
| T1027.001 Binary Padding |
MalwareCostaBricks | CostaBricks has added the entire unobfuscated code of the legitimate open source application Blink to its code. |
| T1027.001 Binary Padding |
MalwareJavali | Javali can use large obfuscated libraries to hinder detection and analysis. |
| T1027.001 Binary Padding |
MalwarePlugX | PlugX has utilized junk code and opaque predicates in payloads to hinder analysis. |
| T1027.001 Binary Padding |
MalwareBisonal | Bisonal has appended random binary data to the end of itself to generate a large binary. |
| T1027.001 Binary Padding |
MalwareLatrodectus | Latrodectus has been obfuscated with a 129 byte sequence of junk data prepended to the file. |
| T1027.001 Binary Padding |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can execute |
| T1027.001 Binary Padding |
MalwareBlack Basta | Black Basta had added data prior to the Portable Executable (PE) header to prevent automatic scanners from identifying the payload. |
| T1027.001 Binary Padding |
MalwareGrandoreiro | Grandoreiro has added BMP images to the resources section of its Portable Executable (PE) file increasing each binary to at least 300MB in size. |
| T1027.001 Binary Padding |
MalwareCaminho | Caminho can use junk code for obfuscation. |
| T1027.001 Binary Padding |
MalwareKwampirs | Before writing to disk, Kwampirs inserts a randomly generated string into the middle of the decrypted payload in an attempt to evade hash-based detections. |
| T1027.001 Binary Padding |
MalwareGrimAgent | GrimAgent has the ability to add bytes to change the file hash. |
| T1027.001 Binary Padding |
MalwareGoopy | Goopy has had null characters padded in its malicious DLL payload. |
| T1027.001 Binary Padding |
MalwareQakBot | QakBot can use large file sizes to evade detection. |
| T1027.001 Binary Padding |
MalwareComnie | Comnie appends a total of 64MB of garbage data to a file to deter any security products in place that may be scanning files on disk. |
| T1027.002 Software Packing |
MalwareTrickBot | TrickBot leverages a custom packer to obfuscate its functionality. |
| T1027.002 Software Packing |
MalwareBLINDINGCAN | BLINDINGCAN has been packed with the UPX packer. |
| T1027.002 Software Packing |
MalwareSpark | Spark has been packed with Enigma Protector to obfuscate its contents. |
| T1027.002 Software Packing |
MalwareTorisma | Torisma has been packed with Iz4 compression. |
| T1027.002 Software Packing |
Malwareyty | yty packs a plugin with UPX. |
| T1027.002 Software Packing |
MalwareCOATHANGER | The first stage of COATHANGER is delivered as a packed file. |
| T1027.002 Software Packing |
MalwareMisdat | Misdat was typically packed using UPX. |
| T1027.002 Software Packing |
MalwareHeartCrypt | HeartCrypt can pack malicious Windows x86 and .NET payloads in order to evade detection. |
| T1027.002 Software Packing |
MalwareAppleSeed | AppleSeed has used UPX packers for its payload DLL. |
| T1027.002 Software Packing |
MalwareNETWIRE | NETWIRE has used .NET packer tools to evade detection. |
| T1027.002 Software Packing |
MalwareGreyEnergy | GreyEnergy is packed for obfuscation. |
| T1027.002 Software Packing |
MalwareEmotet | Emotet has used custom packers to protect its payloads. |
| T1027.002 Software Packing |
MalwareTomiris | Tomiris has been packed with UPX. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.