Real-world descriptions of how a group, tool or campaign used a technique.
114 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1132.001 Standard Encoding |
MalwareSTARWHALE | STARWHALE has the ability to hex-encode collected data from an infected host. |
| T1132.001 Standard Encoding |
MalwareKevin | Kevin can Base32 encode chunks of output files during exfiltration. |
| T1132.001 Standard Encoding |
MalwarePOWERSTATS | POWERSTATS encoded C2 traffic with base64. |
| T1132.001 Standard Encoding |
MalwareBADNEWS | BADNEWS encodes C2 traffic with base64. |
| T1132.001 Standard Encoding |
MalwareAstaroth | Astaroth encodes data using Base64 before sending it to the C2 server. |
| T1132.001 Standard Encoding |
MalwareQakBot | QakBot can Base64 encode system information sent to C2. |
| T1132.001 Standard Encoding |
MalwareHelminth | For C2 over HTTP, Helminth encodes data with base64 and sends it via the "Cookie" field of HTTP requests. For C2 over DNS, Helminth converts ASCII characters into their hexadecimal values and sends the data in cleartext. |
| T1132.001 Standard Encoding |
MalwareDenis | Denis encodes the data sent to the server in Base64. |
| T1132.001 Standard Encoding |
MalwareAutoIt backdoor | AutoIt backdoor has sent a C2 response that was base64-encoded. |
| T1132.001 Standard Encoding |
MalwareUPPERCUT | UPPERCUT can base64 encode C2 communications. |
| T1132.001 Standard Encoding |
MalwareADVSTORESHELL | C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding. |
| T1132.001 Standard Encoding |
ToolSliver | Sliver can use standard encoding techniques like gzip and hex to ASCII to encode the C2 communication payload. |
| T1132.001 Standard Encoding |
ToolRemcos | Remcos can serialize collected data with Protobuf. |
| T1132.001 Standard Encoding |
MalwareMini Shai-Hulud | Mini Shai-Hulud has used base64 encoding to obfuscate URLs used for C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.