ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1140×

301 examples

TechniqueUsed byProcedure example
T1140
Deobfuscate/Decode Files or Information
MalwareLucifer

Lucifer can decrypt its C2 address upon execution.

T1140
Deobfuscate/Decode Files or Information
MalwareGLASSTOKEN

GLASSTOKEN has the ability to decode hexadecimal and Base64 C2 requests.

T1140
Deobfuscate/Decode Files or Information
MalwareBOOSTWRITE

BOOSTWRITE has used a a 32-byte long multi-XOR key to decode data inside its payload.

T1140
Deobfuscate/Decode Files or Information
MalwareRising Sun

Rising Sun has decrypted itself using a single-byte XOR scheme. Additionally, Rising Sun can decrypt its configuration data at runtime.

T1140
Deobfuscate/Decode Files or Information
MalwareShimRat

ShimRat has decompressed its core DLL using shellcode once an impersonated antivirus component was running on a system.

T1140
Deobfuscate/Decode Files or Information
MalwareChrommme

Chrommme can decrypt its encrypted internal code.

T1140
Deobfuscate/Decode Files or Information
MalwareAvaddon

Avaddon has decrypted encrypted strings.

T1140
Deobfuscate/Decode Files or Information
MalwareGreen Lambert

Green Lambert can use multiple custom routines to decrypt strings prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareISMInjector

ISMInjector uses the certutil command to decode a payload file.

T1140
Deobfuscate/Decode Files or Information
MalwarePUNCHBUGGY

PUNCHBUGGY has used PowerShell to decode base64-encoded assembly.

T1140
Deobfuscate/Decode Files or Information
MalwareGoldMax

GoldMax has decoded and decrypted the configuration file when executed.

T1140
Deobfuscate/Decode Files or Information
MalwareCostaBricks

CostaBricks has the ability to use bytecode to decrypt embedded payloads.

T1140
Deobfuscate/Decode Files or Information
MalwareLIGHTWIRE

LIGHTWIRE can RC4 decrypt and Base64 decode C2 commands.

T1140
Deobfuscate/Decode Files or Information
MalwareHyperBro

HyperBro can unpack and decrypt its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwarePteranodon

Pteranodon can decrypt encrypted data strings prior to using them.

T1140
Deobfuscate/Decode Files or Information
MalwareDarkTortilla

DarkTortilla can decrypt its payload and associated configuration elements using the Rijndael cipher.

T1140
Deobfuscate/Decode Files or Information
MalwareROKRAT

ROKRAT can decrypt strings using the victim's hostname as the key.

T1140
Deobfuscate/Decode Files or Information
MalwareSplatDropper

SplatDropper has decoded XOR encrypted payload.

T1140
Deobfuscate/Decode Files or Information
MalwareBabuk

Babuk has the ability to unpack itself into memory using XOR.

T1140
Deobfuscate/Decode Files or Information
MalwareExbyte

Exbyte decodes and decrypts data stored in the configuration file with a key provided on the command line during execution.

T1140
Deobfuscate/Decode Files or Information
MalwareDarkWatchman

DarkWatchman has the ability to self-extract as a RAR archive.

T1140
Deobfuscate/Decode Files or Information
MalwareDyre

Dyre decrypts resources needed for targeting the victim.

T1140
Deobfuscate/Decode Files or Information
MalwareLunarLoader

LunarLoader can deobfuscate files containing the next stages in the infection chain.

T1140
Deobfuscate/Decode Files or Information
MalwareBBSRAT

BBSRAT uses Expand to decompress a CAB file into executable content.

T1140
Deobfuscate/Decode Files or Information
MalwarePlugX

PlugX decompresses and decrypts itself using the Microsoft API call RtlDecompressBuffer. PlugX has also decrypted its payloads in memory.

T1140
Deobfuscate/Decode Files or Information
MalwareBisonal

Bisonal has decoded strings in the malware using XOR and RC4.

T1140
Deobfuscate/Decode Files or Information
MalwareNOOPLDR

NOOPLDR can decrypt its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareLumma Stealer

Lumma Stealer has used Base64-encoded content during execution, decoded via PowerShell.

T1140
Deobfuscate/Decode Files or Information
MalwareLightNeuron

LightNeuron has used AES and XOR to decrypt configuration files and commands.

T1140
Deobfuscate/Decode Files or Information
MalwareKEYPLUG

KEYPLUG can decode its configuration file to determine C2 protocols.

T1140
Deobfuscate/Decode Files or Information
MalwareClambling

Clambling can deobfuscate its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwarePureCrypter

PureCrypter can decrypt downloaded resources and parse internal files to determine its settings.

T1140
Deobfuscate/Decode Files or Information
MalwareDarkGate

DarkGate installation includes binary code stored in a file located in a hidden directory, such as shell.txt, that is decrypted then executed. DarkGate uses hexadecimal-encoded shellcode payloads during installation that are called via Windows API CallWindowProc() to decode and then execute.

T1140
Deobfuscate/Decode Files or Information
MalwareMongall

Mongall has the ability to decrypt its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareLockBit 3.0

The LockBit 3.0 payload is decrypted at runtime.

T1140
Deobfuscate/Decode Files or Information
MalwareFoggyWeb

FoggyWeb can be decrypted in memory using a Lightweight Encryption Algorithm (LEA)-128 key and decoded using a XOR key.

T1140
Deobfuscate/Decode Files or Information
MalwareNetwalker

Netwalker's PowerShell script can decode and decrypt multiple layers of obfuscation, leading to the Netwalker DLL being loaded into memory.

T1140
Deobfuscate/Decode Files or Information
MalwareTSCookie

TSCookie has the ability to decrypt, load, and execute a DLL and its resources.

T1140
Deobfuscate/Decode Files or Information
MalwareLatrodectus

Latrodectus has the ability to deobfuscate encrypted strings.

T1140
Deobfuscate/Decode Files or Information
MalwareSaint Bot

Saint Bot can deobfuscate strings and files for execution.

T1140
Deobfuscate/Decode Files or Information
MalwareChaes

Chaes has decrypted an AES encrypted binary file to trigger the download of other files.

T1140
Deobfuscate/Decode Files or Information
MalwareCharmPower

CharmPower can decrypt downloaded modules prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareMuddyViper

MuddyViper has decrypted the embedded HackBrowserData tool prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareTYPEFRAME

One TYPEFRAME variant decrypts an archive using an RC4 key, then decompresses and installs the decrypted malicious DLL module. Another variant decodes the embedded file by XORing it with the value "0x35".

T1140
Deobfuscate/Decode Files or Information
MalwareBundlore

Bundlore has used openssl to decrypt AES encrypted payload data. Bundlore has also used base64 and RC4 with a hardcoded key to deobfuscate data.

T1140
Deobfuscate/Decode Files or Information
MalwareFooder

Fooder has decrypted payloads using the WinCrypt API and the AES key.

T1140
Deobfuscate/Decode Files or Information
MalwareMori

Mori can resolve networking APIs from strings that are ADD-encrypted.

T1140
Deobfuscate/Decode Files or Information
MalwareQUADAGENT

QUADAGENT uses AES and a preshared key to decrypt the custom Base64 routine used to encode strings and scripts.

T1140
Deobfuscate/Decode Files or Information
MalwareSagerunex

Sagerunex uses a custom decryption routine to unpack itself during installation.

T1140
Deobfuscate/Decode Files or Information
MalwareLP-Notes

LP-Notes has decrypted strings with lengths ranging from 15 to 19 characters using the same decryption key for each string.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.