ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1140×

301 examples

TechniqueUsed byProcedure example
T1140
Deobfuscate/Decode Files or Information
MalwareBabyShark

BabyShark has the ability to decode downloaded files prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareWinnti for Windows

The Winnti for Windows dropper can decrypt and decompresses a data blob.

T1140
Deobfuscate/Decode Files or Information
MalwareEbury

Ebury has verified C2 domain ownership by decrypting the TXT record using an embedded RSA public key.

T1140
Deobfuscate/Decode Files or Information
MalwarePITSTOP

PITSTOP can deobfuscate base64 encoded and AES encrypted commands.

T1140
Deobfuscate/Decode Files or Information
MalwareComRAT

ComRAT has used unique per machine passwords to decrypt the orchestrator payload and a hardcoded XOR key to decrypt its communications module. ComRAT has also used a unique password to decrypt the file used for its hidden file system.

T1140
Deobfuscate/Decode Files or Information
MalwareIceApple

IceApple can use a Base64-encoded AES key to decrypt tasking.

T1140
Deobfuscate/Decode Files or Information
MalwaremetaMain

metaMain can decrypt and load other modules.

T1140
Deobfuscate/Decode Files or Information
MalwareSideTwist

SideTwist can decode and decrypt messages received from C2.

T1140
Deobfuscate/Decode Files or Information
MalwareKOCTOPUS

KOCTOPUS has deobfuscated itself before executing its commands.

T1140
Deobfuscate/Decode Files or Information
MalwareHeyoka Backdoor

Heyoka Backdoor can decrypt its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareBRUSHFIRE

BRUSHFIRE has decrypted XOR strings prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareLunarWeb

LunarWeb can decrypt strings related to communication configuration using RC4 with a static key.

T1140
Deobfuscate/Decode Files or Information
MalwareAppleJeus

AppleJeus has decoded files received from a C2.

T1140
Deobfuscate/Decode Files or Information
MalwareSoreFang

SoreFang can decode and decrypt exfiltrated data sent to C2.

T1140
Deobfuscate/Decode Files or Information
MalwareMirageFox

MirageFox has a function for decrypting data containing C2 configuration information.

T1140
Deobfuscate/Decode Files or Information
MalwareIndustroyer

Industroyer decrypts code to connect to a remote C2 server.

T1140
Deobfuscate/Decode Files or Information
MalwareAgent Tesla

Agent Tesla has the ability to decrypt strings encrypted with the Rijndael symmetric encryption algorithm.

T1140
Deobfuscate/Decode Files or Information
MalwarePOWERSTATS

POWERSTATS can deobfuscate the main backdoor code.

T1140
Deobfuscate/Decode Files or Information
MalwareStarProxy

StarProxy has decrypted network packets using a custom algorithm.

T1140
Deobfuscate/Decode Files or Information
MalwareGoopy

Goopy has used a polymorphic decryptor to decrypt itself at runtime.

T1140
Deobfuscate/Decode Files or Information
MalwareShadowPad

ShadowPad has decrypted a binary blob to start execution.

T1140
Deobfuscate/Decode Files or Information
MalwareRemexi

Remexi decrypts the configuration data using XOR with 25-character keys.

T1140
Deobfuscate/Decode Files or Information
MalwareAstaroth

Astaroth uses a fromCharCode() deobfuscation method to avoid explicitly writing execution commands and to hide its code.

T1140
Deobfuscate/Decode Files or Information
MalwareQakBot

QakBot can deobfuscate and re-assemble code strings for execution.

T1140
Deobfuscate/Decode Files or Information
MalwareDOWNIISSA

DOWNIISSA can decode strings prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareCookieMiner

CookieMiner has used Google Chrome's decryption and extraction operations.

T1140
Deobfuscate/Decode Files or Information
MalwareHancitor

Hancitor has decoded Base64 encoded URLs to insert a recipient’s name into the filename of the Word document. Hancitor has also extracted executables from ZIP files.

T1140
Deobfuscate/Decode Files or Information
MalwareGelsemium

Gelsemium can decompress and decrypt DLLs and shellcode.

T1140
Deobfuscate/Decode Files or Information
MalwareBBK

BBK has the ability to decrypt AES encrypted payloads.

T1140
Deobfuscate/Decode Files or Information
MalwareOSX/Shlayer

OSX/Shlayer can base64-decode and AES-decrypt downloaded payloads. Versions of OSX/Shlayer pass encrypted and password-protected code to openssl and then write the payload to the /tmp folder.

T1140
Deobfuscate/Decode Files or Information
MalwareDenis

Denis will decrypt important strings used for C&C communication.

T1140
Deobfuscate/Decode Files or Information
MalwareINC Ransomware

INC Ransomware can run `CryptStringToBinaryA` to decrypt base64 content containing its ransom note.

T1140
Deobfuscate/Decode Files or Information
MalwareDEADWOOD

DEADWOOD XORs some strings within the binary using the value 0xD5, and deobfuscates these items at runtime.

T1140
Deobfuscate/Decode Files or Information
MalwareWaterbear

Waterbear has the ability to decrypt its RC4 encrypted payload for execution.

T1140
Deobfuscate/Decode Files or Information
MalwareFIVEHANDS

FIVEHANDS has the ability to decrypt its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareLizar

Lizar has decrypted its configuration data, such as the C2 IP address, ports and other network communication.

T1140
Deobfuscate/Decode Files or Information
MalwareDtrack

Dtrack has used a decryption routine that is part of an executable physical patch.

T1140
Deobfuscate/Decode Files or Information
MalwareAzorult

Azorult uses an XOR key to decrypt content and uses Base64 to decode the C2 address.

T1140
Deobfuscate/Decode Files or Information
MalwareHiddenWasp

HiddenWasp uses a cipher to implement a decoding function.

T1140
Deobfuscate/Decode Files or Information
MalwareWarzoneRAT

WarzoneRAT can use XOR 0x45 to decrypt obfuscated code.

T1140
Deobfuscate/Decode Files or Information
MalwareXORIndex Loader

XORIndex Loader can decode its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
Toolcertutil

certutil has been used to decode binaries hidden inside certificate files as Base64 information.

T1140
Deobfuscate/Decode Files or Information
ToolPcShare

PcShare has decrypted its strings by applying a XOR operation and a decompression using a custom implemented LZM algorithm.

T1140
Deobfuscate/Decode Files or Information
ToolBrute Ratel C4

Brute Ratel C4 has the ability to deobfuscate its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
ToolImminent Monitor

Imminent Monitor has decoded malware components that are then dropped to the system.

T1140
Deobfuscate/Decode Files or Information
ToolIronNetInjector

IronNetInjector has the ability to decrypt embedded .NET and PE payloads.

T1140
Deobfuscate/Decode Files or Information
ToolExpand

Expand can be used to decompress a local or remote CAB file into an executable.

T1140
Deobfuscate/Decode Files or Information
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can deobfuscate an encoded Python script prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareMini Shai-Hulud

Mini Shai-Hulud has the ability to decrypt obfuscated payloads.

T1140
Deobfuscate/Decode Files or Information
MalwareCanisterWorm

CanisterWorm has decoded a long Base64 string to obtain a Python script for its second-stage payload.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.