Real-world descriptions of how a group, tool or campaign used a technique.
301 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1140 Deobfuscate/Decode Files or Information |
MalwareCobalt Strike | Cobalt Strike can deobfuscate shellcode using a rolling XOR and decrypt metadata from Beacon sessions. The Cobalt Strike loader component can also decrypt the .bss section of the Beacon binary prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSampleCheck5000 | SampleCheck5000 can decode and decrypt command line strings and files received through C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareREvil | REvil can decode encrypted strings to enable execution of commands and payloads. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareValak | Valak has the ability to decode and decrypt downloaded files. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses a decode routine combining bit shifting and XOR operations with a variable key that depends on the length of the string that was encoded. If the computation for the variable XOR key turns out to be 0, the default XOR key of 0x1B is used. This routine is also referenced as the `rotate` function in reporting. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareOilBooster | OilBooster can Base64-decode and XOR-decrypt C2 commands taken from JSON files. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareOnionDuke | OnionDuke can use a custom decryption algorithm to decrypt strings. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTaidoor | Taidoor can use a stream cipher to decrypt stings used by the malware. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCyclops Blink | Cyclops Blink can decrypt and parse instructions sent from C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareNativeZone | NativeZone can decrypt and decode embedded Cobalt Strike beacon stage shellcode. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRaccoon Stealer | Raccoon Stealer uses RC4-encrypted, base64-encoded strings to obfuscate functionality and command and control servers. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCarbon | Carbon decrypts task and configuration files for execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCardinal RAT | Cardinal RAT decodes many of its artifacts and is decrypted (AES-128) after being downloaded. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDanBot | DanBot can use a VBA macro to decode its payload prior to installation and execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRGDoor | RGDoor decodes Base64 strings and decrypts strings using a custom XOR algorithm. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRamsay | Ramsay can extract its agent from the body of a malicious document. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAshTag | The AshTag stager compoment can decode and decrypt Base64 and XOR-encrypted payloads. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareFRAMESTING | FRAMESTING can decompress data received within `POST` requests. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePillowmint | Pillowmint has been decompressed by included shellcode prior to being launched. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMacMa | MacMa decrypts a downloaded file using AES-128-EBC with a custom delta. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareROADSWEEP | ROADSWEEP can decrypt embedded scripts prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSUNSPOT | SUNSPOT decrypts SUNBURST, which was stored in AES128-CBC encrypted blobs. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMOPSLED | MOPSLED can decrypt obfuscated configuration files. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMore_eggs | More_eggs will decode malware components that are then dropped to the system. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSysUpdate | SysUpdate can deobfuscate packed binaries in memory. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBackConfig | BackConfig has used a custom routine to decrypt strings. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePowGoop | PowGoop can decrypt PowerShell scripts for execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareANELLDR | ANELLDR can decrypt encrypted payload data using AES-256-CBC and subsequently execute the payload in memory. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKwampirs | Kwampirs decrypts and extracts a copy of its main DLL payload when executing. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBoomBox | BoomBox can decrypt AES-encrypted files downloaded from C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDEADEYE | DEADEYE has the ability to combine multiple sections of a binary which were broken up to evade detection into a single .dll prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareProton | Proton uses an encrypted file to store commands and configuration values. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLAMEHUG | LAMEHUG can decode and drop a decoy file attached to spearphishing emails. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareWIREFIRE | WIREFIRE can decode, decrypt, and decompress data received in C2 HTTP `POST` requests. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKessel | Kessel has decrypted the binary's configuration once the |
| T1140 Deobfuscate/Decode Files or Information |
MalwareGrimAgent | GrimAgent can use a decryption algorithm for strings based on Rotate on Right (RoR) and Rotate on Left (RoL) functionality. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLookBack | LookBack has a function that decrypts malicious data. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSTEADYPULSE | STEADYPULSE can URL decode key/value pairs sent over C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePHASEJAM | PHASEJAM has the ability to decode Base64 commands and data. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareClop | Clop has used a simple XOR operation to decrypt strings. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareYAHOYAH | YAHOYAH decrypts downloaded files before execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLokibot | Lokibot has decoded and decrypted its stages multiple times using hard-coded keys to deliver the final payload, and has decoded its server response hex string using XOR. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareEgregor | Egregor has been decrypted before execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePoetRAT | PoetRAT has used LZMA and base64 libraries to decode obfuscated scripts. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareStealBit | StealBit can deobfuscate loaded modules prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRIFLESPINE | RIFLESPINE can deobfuscate encrypted files prior to execution on targeted hosts. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSLIGHTPULSE | SLIGHTPULSE can deobfuscate base64 encoded and RC4 encrypted C2 messages. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCoinTicker | CoinTicker decodes the initially-downloaded hidden encoded file using OpenSSL. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDDKONG | DDKONG decodes an embedded configuration using XOR. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has decoded a XOR encoded private key. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.