Real-world descriptions of how a group, tool or campaign used a technique.
301 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1140 Deobfuscate/Decode Files or Information |
MalwareBendyBear | BendyBear has decrypted function blocks using a XOR key during runtime to evade detection. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareGlassWorm | GlassWorm has decoded its Base64 instructions. GlassWorm has also decrypted its AES protected payloads. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareUroburos | Uroburos can decrypt command parameters sent through C2 and use unpacking code to extract its packed executable. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMetamorfo | Upon execution, Metamorfo has unzipped itself after being downloaded to the system and has performed string decryption. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSpica | Upon execution Spica can decode an embedded .pdf and write it to the desktop as a decoy document. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareEmbargo | Embargo has utilized MDeployer to decrypt two payloads that contain MS4Killer toolkit b.cache and the Embargo ransomware executable a.cache with a hardcoded RC4 key `wlQYLoPCil3niI7x8CvR9EtNtL/aeaHrZ23LP3fAsJogVTIzdnZ5Pi09ZVeHFkiB`. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBandook | Bandook has decoded its PowerShell script. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePipeMon | PipeMon can decrypt password-protected executables. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMagicRAT | MagicRAT stores command and control URLs using base64 encoding in the malware's configuration file. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKONNI | KONNI has used certutil to download and decode base64 encoded strings and has also devoted a custom section to performing all the components of the deobfuscation process. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareWinnti for Linux | Winnti for Linux has decoded XOR encoded strings holding its configuration upon execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRAPIDPULSE | RAPIDPULSE listens for specific HTTP query parameters in received communications. If specific parameters match, a hard-coded RC4 key is used to decrypt the HTTP query paremter |
| T1140 Deobfuscate/Decode Files or Information |
Malwaregh0st RAT | gh0st RAT has decrypted and loaded the gh0st RAT DLL into memory, once the initial dropper executable is launched. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareShamoon | Shamoon decrypts ciphertext using an XOR cipher and a base64-encoded string. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKGH_SPY | KGH_SPY can decrypt encrypted strings and write them to a newly created folder. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKerrdown | Kerrdown can decode, decrypt, and decompress multiple layers of shellcode. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRedLine Stealer | RedLine Stealer has decoded its payload prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareOopsIE | OopsIE concatenates then decompresses multiple resources to load an embedded .Net Framework assembly. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRogueRobin | RogueRobin decodes an embedded executable using base64 and decompresses it. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSQLRat | SQLRat has scripts that are responsible for deobfuscating additional scripts. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMegaCortex | MegaCortex has used a Base64 key to decode its components. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSDBbot | SDBbot has the ability to decrypt and decompress its payload to enable code execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareQUIETCANARY | QUIETCANARY can use a custom parsing routine to decode the command codes and additional parameters from the C2 before executing them. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBlackByte Ransomware | BlackByte Ransomware is distributed as an obfuscated JavaScript launcher file. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePHPsert | PHPsert has the ability to decode and decrypt obfuscated strings prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareStrelaStealer | StrelaStealer payloads have included strings encrypted via XOR. StrelaStealer JavaScript payloads utilize Base64-encoded payloads that are decoded via certutil to create a malicious DLL file. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareGrandoreiro | Grandoreiro can decrypt its encrypted internal strings. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareWellMail | WellMail can decompress scripts received from C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLiteDuke | LiteDuke has the ability to decrypt and decode multiple layers of obfuscation. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareStarloader | Starloader decrypts and executes shellcode from a file called Stars.jps. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareVaporRage | VaporRage can deobfuscate XOR-encoded shellcode prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSibot | Sibot can decrypt data received from a C2 and save to a file. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareZxxZ | ZxxZ has used a XOR key to decrypt strings. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCaminho | Caminho can deobfuscate downloaded files prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDrovorub | Drovorub has de-obsfuscated XOR encrypted payloads in WebSocket messages. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareShark | Shark can extract and decrypt downloaded .zip files. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBazar | Bazar can decrypt downloaded payloads. Bazar also resolves strings and other artifacts at runtime. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKobalos | Kobalos decrypts strings right after the initial communication, but before the authentication process. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMESSAGETAP | After checking for the existence of two files, keyword_parm.txt and parm.txt, MESSAGETAP XOR decodes and read the contents of the files. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareXLoader | XLoader uses XOR and RC4 algorithms to decrypt payloads and functions. XLoader can be distributed as a self-extracting RAR archive that launches an AutoIT loader. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHiddenFace | HiddenFace has the ability to decrypt its payload prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCorKLOG | CorKLOG has decoded XOR encrypted strings. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHermeticWiper | HermeticWiper can decompress and copy driver files using `LZCopy`. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareABK | ABK has the ability to decrypt AES encrypted payloads. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareFinal1stspy | Final1stspy uses Python code to deobfuscate base64-encoded strings. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKapeka | Kapeka utilizes obfuscated JSON structures for various data storage and configuration management items. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLockBit 2.0 | LockBit 2.0 can decode scripts and strings in loaded modules. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareZebrocy | Zebrocy decodes its secondary payload and writes it to the victim’s machine. Zebrocy also uses AES and XOR to decrypt strings and payloads. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareFinFisher | FinFisher extracts and decrypts stage 3 malware, which is stored in encrypted resources. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLunarMail | LunarMail can decrypt strings to retrieve configuration settings. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.