ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
ToolOut1

Out1 has the ability to encode data.

T1027
Obfuscated Files or Information
ToolImminent Monitor

Imminent Monitor has encrypted the spearphish attachments to avoid detection from email gateways; the debugger also encrypts information before sending to the C2.

T1027
Obfuscated Files or Information
ToolMCMD

MCMD can Base64 encode output strings prior to sending to C2.

T1027.001
Binary Padding
GroupKimsuky

Kimsuky has performed padding of PowerShell command line code with over 100 spaces.

T1027.001
Binary Padding
GroupPatchwork

Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes.

T1027.001
Binary Padding
GroupMoafee

Moafee has been known to employ binary padding.

T1027.001
Binary Padding
GroupAkira

Akira has used binary padding to obfuscate payloads.

T1027.001
Binary Padding
GroupHigaisa

Higaisa performed padding with null bytes before calculating its hash.

T1027.001
Binary Padding
GroupLeviathan

Leviathan has inserted garbage characters into code, presumably to avoid anti-virus detection.

T1027.001
Binary Padding
GroupAPT29

APT29 used large size files to avoid detection by security solutions with hardcoded size limits.

T1027.001
Binary Padding
GroupBRONZE BUTLER

BRONZE BUTLER downloader code has included "0" characters at the end of the file to inflate the file size in a likely attempt to evade anti-virus detection.

T1027.001
Binary Padding
MalwareEmissary

A variant of Emissary appends junk data to the end of its DLL file to create a large file that may exceed the maximum size that anti-virus programs can scan.

T1027.001
Binary Padding
MalwareHeartCrypt

HeartCrypt can add several hundred thousand kilobytes of null padding to payloads before saving onto the file system.

T1027.001
Binary Padding
MalwareTONESHELL

TONESHELL has used randomized padding to obfuscate payloads.

T1027.001
Binary Padding
MalwareEmotet

Emotet inflates malicious files and malware as an evasion technique.

T1027.001
Binary Padding
MalwareSnip3

Snip3 can obfuscate strings using junk Chinese characters.

T1027.001
Binary Padding
MalwareRifdoor

Rifdoor has added four additional bytes of data upon launching, then saved the changed version as C:\ProgramData\Initech\Initech.exe.

T1027.001
Binary Padding
MalwareCHIMNEYSWEEP

The CHIMNEYSWEEP installer has been padded with null bytes to inflate its size.

T1027.001
Binary Padding
MalwareLightSpy

LightSpy's configuration file is appended to the end of the binary. For example, the last `0x1d0` bytes of one sample is an AES encrypted configuration file with a static key of `3e2717e8b3873b29`.

T1027.001
Binary Padding
MalwareCostaBricks

CostaBricks has added the entire unobfuscated code of the legitimate open source application Blink to its code.

T1027.001
Binary Padding
MalwareJavali

Javali can use large obfuscated libraries to hinder detection and analysis.

T1027.001
Binary Padding
MalwarePlugX

PlugX has utilized junk code and opaque predicates in payloads to hinder analysis.

T1027.001
Binary Padding
MalwareBisonal

Bisonal has appended random binary data to the end of itself to generate a large binary.

T1027.001
Binary Padding
MalwareLatrodectus

Latrodectus has been obfuscated with a 129 byte sequence of junk data prepended to the file.

T1027.001
Binary Padding
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can execute FileRecvWriteRand to append random bytes to the end of a file received from C2.

T1027.001
Binary Padding
MalwareBlack Basta

Black Basta had added data prior to the Portable Executable (PE) header to prevent automatic scanners from identifying the payload.

T1027.001
Binary Padding
MalwareGrandoreiro

Grandoreiro has added BMP images to the resources section of its Portable Executable (PE) file increasing each binary to at least 300MB in size.

T1027.001
Binary Padding
MalwareCaminho

Caminho can use junk code for obfuscation.

T1027.001
Binary Padding
MalwareKwampirs

Before writing to disk, Kwampirs inserts a randomly generated string into the middle of the decrypted payload in an attempt to evade hash-based detections.

T1027.001
Binary Padding
MalwareGrimAgent

GrimAgent has the ability to add bytes to change the file hash.

T1027.001
Binary Padding
MalwareGoopy

Goopy has had null characters padded in its malicious DLL payload.

T1027.001
Binary Padding
MalwareQakBot

QakBot can use large file sizes to evade detection.

T1027.001
Binary Padding
MalwareComnie

Comnie appends a total of 64MB of garbage data to a file to deter any security products in place that may be scanning files on disk.

T1027.002
Software Packing
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group packed malicious .db files with Themida to evade detection.

T1027.002
Software Packing
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors UPX-packed malicous payloads including 4L4MD4R ransomware.

T1027.002
Software Packing
CampaignOperation Dust Storm

For Operation Dust Storm, the threat actors used UPX to pack some payloads.

T1027.002
Software Packing
CampaignOperation Spalax

For Operation Spalax, the threat actors used a variety of packers, including CyaX, to obfuscate malicious executables.

T1027.002
Software Packing
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used UPX to pack a copy of Mimikatz.

T1027.002
Software Packing
CampaignNight Dragon

During Night Dragon, threat actors used software packing in its tools.

T1027.002
Software Packing
CampaignC0017

During C0017, APT41 used VMProtect to slow the reverse engineering of malicious binaries.

T1027.002
Software Packing
GroupAPT38

APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium, to pack their implants.

T1027.002
Software Packing
GroupElderwood

Elderwood has packed malware payloads before delivery to victims.

T1027.002
Software Packing
GroupGALLIUM

GALLIUM packed some payloads using different types of packers, both known and custom.

T1027.002
Software Packing
GroupAPT3

APT3 has been known to pack their tools.

T1027.002
Software Packing
GroupKimsuky

Kimsuky has packed malware with UPX.

T1027.002
Software Packing
GroupVolt Typhoon

Volt Typhoon has used the Ultimate Packer for Executables (UPX) to obfuscate the FRP client files BrightmetricAgent.exe and SMSvcService.ex) and the port scanning utility ScanLine.

T1027.002
Software Packing
GroupPatchwork

A Patchwork payload was packed with UPX.

T1027.002
Software Packing
GroupAPT41

APT41 uses packers such as Themida to obfuscate malicious files.

T1027.002
Software Packing
GroupTeamTNT

TeamTNT has used UPX and Ezuri packer to pack its binaries.

T1027.002
Software Packing
GroupZIRCONIUM

ZIRCONIUM has used multi-stage packers for exploit code.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.