ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareDenis

Denis obfuscates its code and encrypts the API names.

T1027
Obfuscated Files or Information
MalwareComnie

Comnie uses RC4 and Base64 to obfuscate strings.

T1027
Obfuscated Files or Information
MalwareLizar

Lizar has obfuscated the fingerprint of the victim system, the local IP address, and the Fowler-Noll-V 1 (FNV-1) hash of the local IP address using an XOR operation. The data is then sent to the C2 server.

T1027
Obfuscated Files or Information
MalwareH1N1

H1N1 uses multiple techniques to obfuscate strings, including XOR.

T1027
Obfuscated Files or Information
MalwareSLOWPULSE

SLOWPULSE can hide malicious code in the padding regions between legitimate functions in the Pulse Secure `libdsplibs.so` file.

T1027
Obfuscated Files or Information
MalwareADVSTORESHELL

Most of the strings in ADVSTORESHELL are encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed. API function names are also reversed, presumably to avoid detection in memory.

T1027
Obfuscated Files or Information
MalwareSmall Sieve

Small Sieve has the ability to use a custom hex byte swapping encoding scheme combined with an obfuscated Base64 function to protect program strings and Telegram credentials.

T1027
Obfuscated Files or Information
ToolShimRatReporter

ShimRatReporter encrypted gathered information with a combination of shifting and XOR using a static key.

T1027
Obfuscated Files or Information
ToolSliver

Sliver obfuscates configuration and other static files using native Go libraries such as `garble` and `gobfuscate` to inhibit configuration analysis and static detection.

T1027
Obfuscated Files or Information
ToolCARROTBALL

CARROTBALL has used a custom base64 alphabet to decode files.

T1027
Obfuscated Files or Information
ToolBrute Ratel C4

Brute Ratel C4 has used encrypted payload files and maintains an encrypted configuration structure in memory.

T1027
Obfuscated Files or Information
ToolRemcos

Remcos uses RC4 and base64 to obfuscate data, including Registry entries and file paths. Remcos can also employ control flow flattening to hinder analysis.

T1027
Obfuscated Files or Information
ToolOut1

Out1 has the ability to encode data.

T1027
Obfuscated Files or Information
ToolImminent Monitor

Imminent Monitor has encrypted the spearphish attachments to avoid detection from email gateways; the debugger also encrypts information before sending to the C2.

T1027
Obfuscated Files or Information
ToolMCMD

MCMD can Base64 encode output strings prior to sending to C2.

T1027.001
Binary Padding
MalwareEmissary

A variant of Emissary appends junk data to the end of its DLL file to create a large file that may exceed the maximum size that anti-virus programs can scan.

T1027.001
Binary Padding
MalwareHeartCrypt

HeartCrypt can add several hundred thousand kilobytes of null padding to payloads before saving onto the file system.

T1027.001
Binary Padding
MalwareTONESHELL

TONESHELL has used randomized padding to obfuscate payloads.

T1027.001
Binary Padding
MalwareEmotet

Emotet inflates malicious files and malware as an evasion technique.

T1027.001
Binary Padding
MalwareSnip3

Snip3 can obfuscate strings using junk Chinese characters.

T1027.001
Binary Padding
MalwareRifdoor

Rifdoor has added four additional bytes of data upon launching, then saved the changed version as C:\ProgramData\Initech\Initech.exe.

T1027.001
Binary Padding
MalwareCHIMNEYSWEEP

The CHIMNEYSWEEP installer has been padded with null bytes to inflate its size.

T1027.001
Binary Padding
MalwareLightSpy

LightSpy's configuration file is appended to the end of the binary. For example, the last `0x1d0` bytes of one sample is an AES encrypted configuration file with a static key of `3e2717e8b3873b29`.

T1027.001
Binary Padding
MalwareCostaBricks

CostaBricks has added the entire unobfuscated code of the legitimate open source application Blink to its code.

T1027.001
Binary Padding
MalwareJavali

Javali can use large obfuscated libraries to hinder detection and analysis.

T1027.001
Binary Padding
MalwarePlugX

PlugX has utilized junk code and opaque predicates in payloads to hinder analysis.

T1027.001
Binary Padding
MalwareBisonal

Bisonal has appended random binary data to the end of itself to generate a large binary.

T1027.001
Binary Padding
MalwareLatrodectus

Latrodectus has been obfuscated with a 129 byte sequence of junk data prepended to the file.

T1027.001
Binary Padding
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can execute FileRecvWriteRand to append random bytes to the end of a file received from C2.

T1027.001
Binary Padding
MalwareBlack Basta

Black Basta had added data prior to the Portable Executable (PE) header to prevent automatic scanners from identifying the payload.

T1027.001
Binary Padding
MalwareGrandoreiro

Grandoreiro has added BMP images to the resources section of its Portable Executable (PE) file increasing each binary to at least 300MB in size.

T1027.001
Binary Padding
MalwareCaminho

Caminho can use junk code for obfuscation.

T1027.001
Binary Padding
MalwareKwampirs

Before writing to disk, Kwampirs inserts a randomly generated string into the middle of the decrypted payload in an attempt to evade hash-based detections.

T1027.001
Binary Padding
MalwareGrimAgent

GrimAgent has the ability to add bytes to change the file hash.

T1027.001
Binary Padding
MalwareGoopy

Goopy has had null characters padded in its malicious DLL payload.

T1027.001
Binary Padding
MalwareQakBot

QakBot can use large file sizes to evade detection.

T1027.001
Binary Padding
MalwareComnie

Comnie appends a total of 64MB of garbage data to a file to deter any security products in place that may be scanning files on disk.

T1027.002
Software Packing
MalwareTrickBot

TrickBot leverages a custom packer to obfuscate its functionality.

T1027.002
Software Packing
MalwareBLINDINGCAN

BLINDINGCAN has been packed with the UPX packer.

T1027.002
Software Packing
MalwareSpark

Spark has been packed with Enigma Protector to obfuscate its contents.

T1027.002
Software Packing
MalwareTorisma

Torisma has been packed with Iz4 compression.

T1027.002
Software Packing
Malwareyty

yty packs a plugin with UPX.

T1027.002
Software Packing
MalwareCOATHANGER

The first stage of COATHANGER is delivered as a packed file.

T1027.002
Software Packing
MalwareMisdat

Misdat was typically packed using UPX.

T1027.002
Software Packing
MalwareHeartCrypt

HeartCrypt can pack malicious Windows x86 and .NET payloads in order to evade detection.

T1027.002
Software Packing
MalwareAppleSeed

AppleSeed has used UPX packers for its payload DLL.

T1027.002
Software Packing
MalwareNETWIRE

NETWIRE has used .NET packer tools to evade detection.

T1027.002
Software Packing
MalwareGreyEnergy

GreyEnergy is packed for obfuscation.

T1027.002
Software Packing
MalwareEmotet

Emotet has used custom packers to protect its payloads.

T1027.002
Software Packing
MalwareTomiris

Tomiris has been packed with UPX.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.