ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1140×

301 examples

TechniqueUsed byProcedure example
T1140
Deobfuscate/Decode Files or Information
MalwareCobalt Strike

Cobalt Strike can deobfuscate shellcode using a rolling XOR and decrypt metadata from Beacon sessions. The Cobalt Strike loader component can also decrypt the .bss section of the Beacon binary prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareSampleCheck5000

SampleCheck5000 can decode and decrypt command line strings and files received through C2.

T1140
Deobfuscate/Decode Files or Information
MalwareREvil

REvil can decode encrypted strings to enable execution of commands and payloads.

T1140
Deobfuscate/Decode Files or Information
MalwareValak

Valak has the ability to decode and decrypt downloaded files.

T1140
Deobfuscate/Decode Files or Information
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D uses a decode routine combining bit shifting and XOR operations with a variable key that depends on the length of the string that was encoded. If the computation for the variable XOR key turns out to be 0, the default XOR key of 0x1B is used. This routine is also referenced as the `rotate` function in reporting.

T1140
Deobfuscate/Decode Files or Information
MalwareOilBooster

OilBooster can Base64-decode and XOR-decrypt C2 commands taken from JSON files.

T1140
Deobfuscate/Decode Files or Information
MalwareOnionDuke

OnionDuke can use a custom decryption algorithm to decrypt strings.

T1140
Deobfuscate/Decode Files or Information
MalwareTaidoor

Taidoor can use a stream cipher to decrypt stings used by the malware.

T1140
Deobfuscate/Decode Files or Information
MalwareCyclops Blink

Cyclops Blink can decrypt and parse instructions sent from C2.

T1140
Deobfuscate/Decode Files or Information
MalwareNativeZone

NativeZone can decrypt and decode embedded Cobalt Strike beacon stage shellcode.

T1140
Deobfuscate/Decode Files or Information
MalwareRaccoon Stealer

Raccoon Stealer uses RC4-encrypted, base64-encoded strings to obfuscate functionality and command and control servers.

T1140
Deobfuscate/Decode Files or Information
MalwareCarbon

Carbon decrypts task and configuration files for execution.

T1140
Deobfuscate/Decode Files or Information
MalwareCardinal RAT

Cardinal RAT decodes many of its artifacts and is decrypted (AES-128) after being downloaded.

T1140
Deobfuscate/Decode Files or Information
MalwareDanBot

DanBot can use a VBA macro to decode its payload prior to installation and execution.

T1140
Deobfuscate/Decode Files or Information
MalwareRGDoor

RGDoor decodes Base64 strings and decrypts strings using a custom XOR algorithm.

T1140
Deobfuscate/Decode Files or Information
MalwareRamsay

Ramsay can extract its agent from the body of a malicious document.

T1140
Deobfuscate/Decode Files or Information
MalwareAshTag

The AshTag stager compoment can decode and decrypt Base64 and XOR-encrypted payloads.

T1140
Deobfuscate/Decode Files or Information
MalwareFRAMESTING

FRAMESTING can decompress data received within `POST` requests.

T1140
Deobfuscate/Decode Files or Information
MalwarePillowmint

Pillowmint has been decompressed by included shellcode prior to being launched.

T1140
Deobfuscate/Decode Files or Information
MalwareMacMa

MacMa decrypts a downloaded file using AES-128-EBC with a custom delta.

T1140
Deobfuscate/Decode Files or Information
MalwareROADSWEEP

ROADSWEEP can decrypt embedded scripts prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareSUNSPOT

SUNSPOT decrypts SUNBURST, which was stored in AES128-CBC encrypted blobs.

T1140
Deobfuscate/Decode Files or Information
MalwareMOPSLED

MOPSLED can decrypt obfuscated configuration files.

T1140
Deobfuscate/Decode Files or Information
MalwareMore_eggs

More_eggs will decode malware components that are then dropped to the system.

T1140
Deobfuscate/Decode Files or Information
MalwareSysUpdate

SysUpdate can deobfuscate packed binaries in memory.

T1140
Deobfuscate/Decode Files or Information
MalwareBackConfig

BackConfig has used a custom routine to decrypt strings.

T1140
Deobfuscate/Decode Files or Information
MalwarePowGoop

PowGoop can decrypt PowerShell scripts for execution.

T1140
Deobfuscate/Decode Files or Information
MalwareANELLDR

ANELLDR can decrypt encrypted payload data using AES-256-CBC and subsequently execute the payload in memory.

T1140
Deobfuscate/Decode Files or Information
MalwareKwampirs

Kwampirs decrypts and extracts a copy of its main DLL payload when executing.

T1140
Deobfuscate/Decode Files or Information
MalwareBoomBox

BoomBox can decrypt AES-encrypted files downloaded from C2.

T1140
Deobfuscate/Decode Files or Information
MalwareDEADEYE

DEADEYE has the ability to combine multiple sections of a binary which were broken up to evade detection into a single .dll prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareProton

Proton uses an encrypted file to store commands and configuration values.

T1140
Deobfuscate/Decode Files or Information
MalwareLAMEHUG

LAMEHUG can decode and drop a decoy file attached to spearphishing emails.

T1140
Deobfuscate/Decode Files or Information
MalwareWIREFIRE

WIREFIRE can decode, decrypt, and decompress data received in C2 HTTP `POST` requests.

T1140
Deobfuscate/Decode Files or Information
MalwareKessel

Kessel has decrypted the binary's configuration once the main function was launched.

T1140
Deobfuscate/Decode Files or Information
MalwareGrimAgent

GrimAgent can use a decryption algorithm for strings based on Rotate on Right (RoR) and Rotate on Left (RoL) functionality.

T1140
Deobfuscate/Decode Files or Information
MalwareLookBack

LookBack has a function that decrypts malicious data.

T1140
Deobfuscate/Decode Files or Information
MalwareSTEADYPULSE

STEADYPULSE can URL decode key/value pairs sent over C2.

T1140
Deobfuscate/Decode Files or Information
MalwarePHASEJAM

PHASEJAM has the ability to decode Base64 commands and data.

T1140
Deobfuscate/Decode Files or Information
MalwareClop

Clop has used a simple XOR operation to decrypt strings.

T1140
Deobfuscate/Decode Files or Information
MalwareYAHOYAH

YAHOYAH decrypts downloaded files before execution.

T1140
Deobfuscate/Decode Files or Information
MalwareLokibot

Lokibot has decoded and decrypted its stages multiple times using hard-coded keys to deliver the final payload, and has decoded its server response hex string using XOR.

T1140
Deobfuscate/Decode Files or Information
MalwareEgregor

Egregor has been decrypted before execution.

T1140
Deobfuscate/Decode Files or Information
MalwarePoetRAT

PoetRAT has used LZMA and base64 libraries to decode obfuscated scripts.

T1140
Deobfuscate/Decode Files or Information
MalwareStealBit

StealBit can deobfuscate loaded modules prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareRIFLESPINE

RIFLESPINE can deobfuscate encrypted files prior to execution on targeted hosts.

T1140
Deobfuscate/Decode Files or Information
MalwareSLIGHTPULSE

SLIGHTPULSE can deobfuscate base64 encoded and RC4 encrypted C2 messages.

T1140
Deobfuscate/Decode Files or Information
MalwareCoinTicker

CoinTicker decodes the initially-downloaded hidden encoded file using OpenSSL.

T1140
Deobfuscate/Decode Files or Information
MalwareDDKONG

DDKONG decodes an embedded configuration using XOR.

T1140
Deobfuscate/Decode Files or Information
MalwareSPAWNCHIMERA

SPAWNCHIMERA has decoded a XOR encoded private key.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.