ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1140×

301 examples

TechniqueUsed byProcedure example
T1140
Deobfuscate/Decode Files or Information
MalwareBendyBear

BendyBear has decrypted function blocks using a XOR key during runtime to evade detection.

T1140
Deobfuscate/Decode Files or Information
MalwareGlassWorm

GlassWorm has decoded its Base64 instructions. GlassWorm has also decrypted its AES protected payloads.

T1140
Deobfuscate/Decode Files or Information
MalwareUroburos

Uroburos can decrypt command parameters sent through C2 and use unpacking code to extract its packed executable.

T1140
Deobfuscate/Decode Files or Information
MalwareMetamorfo

Upon execution, Metamorfo has unzipped itself after being downloaded to the system and has performed string decryption.

T1140
Deobfuscate/Decode Files or Information
MalwareSpica

Upon execution Spica can decode an embedded .pdf and write it to the desktop as a decoy document.

T1140
Deobfuscate/Decode Files or Information
MalwareEmbargo

Embargo has utilized MDeployer to decrypt two payloads that contain MS4Killer toolkit b.cache and the Embargo ransomware executable a.cache with a hardcoded RC4 key `wlQYLoPCil3niI7x8CvR9EtNtL/aeaHrZ23LP3fAsJogVTIzdnZ5Pi09ZVeHFkiB`.

T1140
Deobfuscate/Decode Files or Information
MalwareBandook

Bandook has decoded its PowerShell script.

T1140
Deobfuscate/Decode Files or Information
MalwarePipeMon

PipeMon can decrypt password-protected executables.

T1140
Deobfuscate/Decode Files or Information
MalwareMagicRAT

MagicRAT stores command and control URLs using base64 encoding in the malware's configuration file.

T1140
Deobfuscate/Decode Files or Information
MalwareKONNI

KONNI has used certutil to download and decode base64 encoded strings and has also devoted a custom section to performing all the components of the deobfuscation process.

T1140
Deobfuscate/Decode Files or Information
MalwareWinnti for Linux

Winnti for Linux has decoded XOR encoded strings holding its configuration upon execution.

T1140
Deobfuscate/Decode Files or Information
MalwareRAPIDPULSE

RAPIDPULSE listens for specific HTTP query parameters in received communications. If specific parameters match, a hard-coded RC4 key is used to decrypt the HTTP query paremter hmacTime. This decrypts to a filename that is then open, read, encrypted with the same RC4 key, base64-encoded, written to standard out, then passed as a response to the HTTP request.

T1140
Deobfuscate/Decode Files or Information
Malwaregh0st RAT

gh0st RAT has decrypted and loaded the gh0st RAT DLL into memory, once the initial dropper executable is launched.

T1140
Deobfuscate/Decode Files or Information
MalwareShamoon

Shamoon decrypts ciphertext using an XOR cipher and a base64-encoded string.

T1140
Deobfuscate/Decode Files or Information
MalwareKGH_SPY

KGH_SPY can decrypt encrypted strings and write them to a newly created folder.

T1140
Deobfuscate/Decode Files or Information
MalwareKerrdown

Kerrdown can decode, decrypt, and decompress multiple layers of shellcode.

T1140
Deobfuscate/Decode Files or Information
MalwareRedLine Stealer

RedLine Stealer has decoded its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareOopsIE

OopsIE concatenates then decompresses multiple resources to load an embedded .Net Framework assembly.

T1140
Deobfuscate/Decode Files or Information
MalwareRogueRobin

RogueRobin decodes an embedded executable using base64 and decompresses it.

T1140
Deobfuscate/Decode Files or Information
MalwareSQLRat

SQLRat has scripts that are responsible for deobfuscating additional scripts.

T1140
Deobfuscate/Decode Files or Information
MalwareMegaCortex

MegaCortex has used a Base64 key to decode its components.

T1140
Deobfuscate/Decode Files or Information
MalwareSDBbot

SDBbot has the ability to decrypt and decompress its payload to enable code execution.

T1140
Deobfuscate/Decode Files or Information
MalwareQUIETCANARY

QUIETCANARY can use a custom parsing routine to decode the command codes and additional parameters from the C2 before executing them.

T1140
Deobfuscate/Decode Files or Information
MalwareBlackByte Ransomware

BlackByte Ransomware is distributed as an obfuscated JavaScript launcher file.

T1140
Deobfuscate/Decode Files or Information
MalwarePHPsert

PHPsert has the ability to decode and decrypt obfuscated strings prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareStrelaStealer

StrelaStealer payloads have included strings encrypted via XOR. StrelaStealer JavaScript payloads utilize Base64-encoded payloads that are decoded via certutil to create a malicious DLL file.

T1140
Deobfuscate/Decode Files or Information
MalwareGrandoreiro

Grandoreiro can decrypt its encrypted internal strings.

T1140
Deobfuscate/Decode Files or Information
MalwareWellMail

WellMail can decompress scripts received from C2.

T1140
Deobfuscate/Decode Files or Information
MalwareLiteDuke

LiteDuke has the ability to decrypt and decode multiple layers of obfuscation.

T1140
Deobfuscate/Decode Files or Information
MalwareStarloader

Starloader decrypts and executes shellcode from a file called Stars.jps.

T1140
Deobfuscate/Decode Files or Information
MalwareVaporRage

VaporRage can deobfuscate XOR-encoded shellcode prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareSibot

Sibot can decrypt data received from a C2 and save to a file.

T1140
Deobfuscate/Decode Files or Information
MalwareZxxZ

ZxxZ has used a XOR key to decrypt strings.

T1140
Deobfuscate/Decode Files or Information
MalwareCaminho

Caminho can deobfuscate downloaded files prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareDrovorub

Drovorub has de-obsfuscated XOR encrypted payloads in WebSocket messages.

T1140
Deobfuscate/Decode Files or Information
MalwareShark

Shark can extract and decrypt downloaded .zip files.

T1140
Deobfuscate/Decode Files or Information
MalwareBazar

Bazar can decrypt downloaded payloads. Bazar also resolves strings and other artifacts at runtime.

T1140
Deobfuscate/Decode Files or Information
MalwareKobalos

Kobalos decrypts strings right after the initial communication, but before the authentication process.

T1140
Deobfuscate/Decode Files or Information
MalwareMESSAGETAP

After checking for the existence of two files, keyword_parm.txt and parm.txt, MESSAGETAP XOR decodes and read the contents of the files.

T1140
Deobfuscate/Decode Files or Information
MalwareXLoader

XLoader uses XOR and RC4 algorithms to decrypt payloads and functions. XLoader can be distributed as a self-extracting RAR archive that launches an AutoIT loader.

T1140
Deobfuscate/Decode Files or Information
MalwareHiddenFace

HiddenFace has the ability to decrypt its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareCorKLOG

CorKLOG has decoded XOR encrypted strings.

T1140
Deobfuscate/Decode Files or Information
MalwareHermeticWiper

HermeticWiper can decompress and copy driver files using `LZCopy`.

T1140
Deobfuscate/Decode Files or Information
MalwareABK

ABK has the ability to decrypt AES encrypted payloads.

T1140
Deobfuscate/Decode Files or Information
MalwareFinal1stspy

Final1stspy uses Python code to deobfuscate base64-encoded strings.

T1140
Deobfuscate/Decode Files or Information
MalwareKapeka

Kapeka utilizes obfuscated JSON structures for various data storage and configuration management items.

T1140
Deobfuscate/Decode Files or Information
MalwareLockBit 2.0

LockBit 2.0 can decode scripts and strings in loaded modules.

T1140
Deobfuscate/Decode Files or Information
MalwareZebrocy

Zebrocy decodes its secondary payload and writes it to the victim’s machine. Zebrocy also uses AES and XOR to decrypt strings and payloads.

T1140
Deobfuscate/Decode Files or Information
MalwareFinFisher

FinFisher extracts and decrypts stage 3 malware, which is stored in encrypted resources.

T1140
Deobfuscate/Decode Files or Information
MalwareLunarMail

LunarMail can decrypt strings to retrieve configuration settings.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.