ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1027.013×

195 examples

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareMetamorfo

Metamorfo has encrypted payloads and strings.

T1027.013
Encrypted/Encoded File
MalwareEmbargo

Embargo has encrypted both MDeployer and MS4 Killer payloads with RC4.

T1027.013
Encrypted/Encoded File
MalwarePipeMon

PipeMon modules are stored encrypted on disk.

T1027.013
Encrypted/Encoded File
MalwareMagicRAT

MagicRAT stores base64 encoded command and contorl URLs in a configuraiton file, with each URL prefixed with the value `LR02DPt22R`.

T1027.013
Encrypted/Encoded File
MalwareTINYTYPHON

TINYTYPHON has used XOR with 0x90 to obfuscate its configuration file.

T1027.013
Encrypted/Encoded File
MalwareKONNI

KONNI is heavily obfuscated and includes encrypted configuration files.

T1027.013
Encrypted/Encoded File
MalwareWinnti for Linux

Winnti for Linux can encode its configuration file with single-byte XOR encoding.

T1027.013
Encrypted/Encoded File
MalwareRAPIDPULSE

RAPIDPULSE has the ability to RC4 encrypt and base64 encode decrypted files on compromised servers prior to writing them to stdout.

T1027.013
Encrypted/Encoded File
MalwareJHUHUGIT

Many strings in JHUHUGIT are obfuscated with a XOR algorithm.

T1027.013
Encrypted/Encoded File
MalwareBLUELIGHT

BLUELIGHT has a XOR-encoded payload.

T1027.013
Encrypted/Encoded File
MalwareKGH_SPY

KGH_SPY has used encrypted strings in its installer.

T1027.013
Encrypted/Encoded File
MalwareMicropsia

Micropsia obfuscates the configuration with a custom Base64 and XOR.

T1027.013
Encrypted/Encoded File
MalwareKerrdown

Kerrdown can encrypt, encode, and compress multiple layers of shellcode.

T1027.013
Encrypted/Encoded File
MalwareRedLine Stealer

RedLine Stealer has encrypted and encoded configuration data with Base64 and XOR functions.

T1027.013
Encrypted/Encoded File
MalwareStoneDrill

StoneDrill has obfuscated its module with an alphabet-based table or XOR encryption.

T1027.013
Encrypted/Encoded File
MalwareAttor

Strings in Attor's components are encrypted with a XOR cipher, using a hardcoded key and the configuration data, log files and plugins are encrypted using a hybrid encryption scheme of Blowfish-OFB combined with RSA.

T1027.013
Encrypted/Encoded File
MalwareMosquito

Mosquito’s installer is obfuscated with a custom crypter to obfuscate the installer.

T1027.013
Encrypted/Encoded File
MalwareBlackByte Ransomware

BlackByte Ransomware is distributed as an encrypted payload.

T1027.013
Encrypted/Encoded File
MalwarePHPsert

PHPsert can use multiple obfuscation techniques including XOR encoding, hexadecimal character representation, string concatenation, and randomized variable names.

T1027.013
Encrypted/Encoded File
MalwareStrelaStealer

StrelaStealer uses XOR-encoded strings to obfuscate items.

T1027.013
Encrypted/Encoded File
MalwareGrandoreiro

The Grandoreiro payload has been delivered encrypted with a custom XOR-based algorithm and also as a base64-encoded ZIP file.

T1027.013
Encrypted/Encoded File
MalwareSakula

Sakula uses single-byte XOR obfuscation to obfuscate many of its files.

T1027.013
Encrypted/Encoded File
MalwareZxxZ

ZxxZ has been encoded to avoid detection from static analysis tools.

T1027.013
Encrypted/Encoded File
MalwareCaminho

Caminho can use code flattening for payload obfuscation.

T1027.013
Encrypted/Encoded File
MalwareShark

Shark can use encrypted and encoded files for C2 configuration.

T1027.013
Encrypted/Encoded File
MalwareBazar

Bazar has used XOR, RSA2, and RC4 encrypted files.

T1027.013
Encrypted/Encoded File
MalwareXLoader

XLoader features encrypted functions using the RC4 algorithm and bytecode operations.

T1027.013
Encrypted/Encoded File
MalwareHiddenFace

HiddenFace has encrypted its payload with AES.

T1027.013
Encrypted/Encoded File
MalwareCorKLOG

CorKLOG has encrypted collected contents using RC4. CorKLOG has also utilized XOR encrypted strings.

T1027.013
Encrypted/Encoded File
MalwareKapeka

Kapeka utilizes AES-256 (CBC mode), XOR, and RSA-2048 encryption schemas for various configuration and other objects.

T1027.013
Encrypted/Encoded File
MalwareSpeakUp

SpeakUp encodes its second-stage payload with Base64.

T1027.013
Encrypted/Encoded File
MalwareLunarMail

LunarMail has used RC4 and AES to encrypt strings and its exfiltration configuration respectively.

T1027.013
Encrypted/Encoded File
MalwareHotCroissant

HotCroissant has encrypted strings with single-byte XOR and base64 encoded RC4.

T1027.013
Encrypted/Encoded File
MalwareREvil

REvil has used encrypted strings and configuration files.

T1027.013
Encrypted/Encoded File
MalwareMilan

Milan can encode files containing information about the targeted system.

T1027.013
Encrypted/Encoded File
MalwareUSBStealer

Most strings in USBStealer are encrypted using 3DES and XOR and reversed.

T1027.013
Encrypted/Encoded File
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D encrypts its strings in RSA256 and encodes them in a custom base64 scheme and XOR.

T1027.013
Encrypted/Encoded File
MalwareTaidoor

Taidoor can use encrypted string blocks for obfuscation.

T1027.013
Encrypted/Encoded File
MalwareSUPERNOVA

SUPERNOVA contained Base64-encoded strings.

T1027.013
Encrypted/Encoded File
MalwareSeasalt

Seasalt obfuscates configuration data.

T1027.013
Encrypted/Encoded File
MalwareRaccoon Stealer

Raccoon Stealer uses RC4 encryption for strings and command and control addresses to evade static detection.

T1027.013
Encrypted/Encoded File
MalwareIPsec Helper

IPsec Helper contains an embedded XML configuration file with an encrypted list of command and control servers. These are written to an external configuration file during execution.

T1027.013
Encrypted/Encoded File
MalwareCardinal RAT

Cardinal RAT encodes many of its artifacts and is encrypted (AES-128) when downloaded.

T1027.013
Encrypted/Encoded File
MalwareDanBot

DanBot can Base64 encode its payload.

T1027.013
Encrypted/Encoded File
MalwareGoldenSpy

GoldenSpy's uninstaller has base64-encoded its variables.

T1027.013
Encrypted/Encoded File
MalwareAshTag

The AshTag AshenOrchestrator component payload as been Base64 encoded and embedded with HTML content from the C2 server.

T1027.013
Encrypted/Encoded File
MalwareCarberp

Carberp has used XOR-based encryption to mask C2 server locations within the trojan.

T1027.013
Encrypted/Encoded File
MalwareFunnyDream

FunnyDream can Base64 encode its C2 address stored in a template binary with the `xyz0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvw_-` or
`xyz0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvw_=` character sets.

T1027.013
Encrypted/Encoded File
MalwareROADSWEEP

The ROADSWEEP binary contains RC4 encrypted embedded scripts.

T1027.013
Encrypted/Encoded File
MalwareMOPSLED

MOPSLED can encrypt configuration files with a custom ChaCha20 algorithm.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.