ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1132.001×

114 examples

TechniqueUsed byProcedure example
T1132.001
Standard Encoding
MalwareSTARWHALE

STARWHALE has the ability to hex-encode collected data from an infected host.

T1132.001
Standard Encoding
MalwareKevin

Kevin can Base32 encode chunks of output files during exfiltration.

T1132.001
Standard Encoding
MalwarePOWERSTATS

POWERSTATS encoded C2 traffic with base64.

T1132.001
Standard Encoding
MalwareBADNEWS

BADNEWS encodes C2 traffic with base64.

T1132.001
Standard Encoding
MalwareAstaroth

Astaroth encodes data using Base64 before sending it to the C2 server.

T1132.001
Standard Encoding
MalwareQakBot

QakBot can Base64 encode system information sent to C2.

T1132.001
Standard Encoding
MalwareHelminth

For C2 over HTTP, Helminth encodes data with base64 and sends it via the "Cookie" field of HTTP requests. For C2 over DNS, Helminth converts ASCII characters into their hexadecimal values and sends the data in cleartext.

T1132.001
Standard Encoding
MalwareDenis

Denis encodes the data sent to the server in Base64.

T1132.001
Standard Encoding
MalwareAutoIt backdoor

AutoIt backdoor has sent a C2 response that was base64-encoded.

T1132.001
Standard Encoding
MalwareUPPERCUT

UPPERCUT can base64 encode C2 communications.

T1132.001
Standard Encoding
MalwareADVSTORESHELL

C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding.

T1132.001
Standard Encoding
ToolSliver

Sliver can use standard encoding techniques like gzip and hex to ASCII to encode the C2 communication payload.

T1132.001
Standard Encoding
ToolRemcos

Remcos can serialize collected data with Protobuf.

T1132.001
Standard Encoding
MalwareMini Shai-Hulud

Mini Shai-Hulud has used base64 encoding to obfuscate URLs used for C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.