Real-world descriptions of how a group, tool or campaign used a technique.
301 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1140 Deobfuscate/Decode Files or Information |
MalwareBabyShark | BabyShark has the ability to decode downloaded files prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareWinnti for Windows | The Winnti for Windows dropper can decrypt and decompresses a data blob. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareEbury | Ebury has verified C2 domain ownership by decrypting the TXT record using an embedded RSA public key. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePITSTOP | PITSTOP can deobfuscate base64 encoded and AES encrypted commands. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareComRAT | ComRAT has used unique per machine passwords to decrypt the orchestrator payload and a hardcoded XOR key to decrypt its communications module. ComRAT has also used a unique password to decrypt the file used for its hidden file system. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareIceApple | IceApple can use a Base64-encoded AES key to decrypt tasking. |
| T1140 Deobfuscate/Decode Files or Information |
MalwaremetaMain | metaMain can decrypt and load other modules. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSideTwist | SideTwist can decode and decrypt messages received from C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKOCTOPUS | KOCTOPUS has deobfuscated itself before executing its commands. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHeyoka Backdoor | Heyoka Backdoor can decrypt its payload prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBRUSHFIRE | BRUSHFIRE has decrypted XOR strings prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLunarWeb | LunarWeb can decrypt strings related to communication configuration using RC4 with a static key. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAppleJeus | AppleJeus has decoded files received from a C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSoreFang | SoreFang can decode and decrypt exfiltrated data sent to C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMirageFox | MirageFox has a function for decrypting data containing C2 configuration information. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareIndustroyer | Industroyer decrypts code to connect to a remote C2 server. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAgent Tesla | Agent Tesla has the ability to decrypt strings encrypted with the Rijndael symmetric encryption algorithm. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePOWERSTATS | POWERSTATS can deobfuscate the main backdoor code. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareStarProxy | StarProxy has decrypted network packets using a custom algorithm. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareGoopy | Goopy has used a polymorphic decryptor to decrypt itself at runtime. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareShadowPad | ShadowPad has decrypted a binary blob to start execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRemexi | Remexi decrypts the configuration data using XOR with 25-character keys. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAstaroth | Astaroth uses a fromCharCode() deobfuscation method to avoid explicitly writing execution commands and to hide its code. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareQakBot | QakBot can deobfuscate and re-assemble code strings for execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDOWNIISSA | DOWNIISSA can decode strings prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCookieMiner | CookieMiner has used Google Chrome's decryption and extraction operations. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHancitor | Hancitor has decoded Base64 encoded URLs to insert a recipient’s name into the filename of the Word document. Hancitor has also extracted executables from ZIP files. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareGelsemium | Gelsemium can decompress and decrypt DLLs and shellcode. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBBK | BBK has the ability to decrypt AES encrypted payloads. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareOSX/Shlayer | OSX/Shlayer can base64-decode and AES-decrypt downloaded payloads. Versions of OSX/Shlayer pass encrypted and password-protected code to |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDenis | Denis will decrypt important strings used for C&C communication. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareINC Ransomware | INC Ransomware can run `CryptStringToBinaryA` to decrypt base64 content containing its ransom note. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDEADWOOD | DEADWOOD XORs some strings within the binary using the value |
| T1140 Deobfuscate/Decode Files or Information |
MalwareWaterbear | Waterbear has the ability to decrypt its RC4 encrypted payload for execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareFIVEHANDS | FIVEHANDS has the ability to decrypt its payload prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLizar | Lizar has decrypted its configuration data, such as the C2 IP address, ports and other network communication. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDtrack | Dtrack has used a decryption routine that is part of an executable physical patch. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAzorult | Azorult uses an XOR key to decrypt content and uses Base64 to decode the C2 address. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHiddenWasp | HiddenWasp uses a cipher to implement a decoding function. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareWarzoneRAT | WarzoneRAT can use XOR 0x45 to decrypt obfuscated code. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareXORIndex Loader | XORIndex Loader can decode its payload prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
Toolcertutil | certutil has been used to decode binaries hidden inside certificate files as Base64 information. |
| T1140 Deobfuscate/Decode Files or Information |
ToolPcShare | PcShare has decrypted its strings by applying a XOR operation and a decompression using a custom implemented LZM algorithm. |
| T1140 Deobfuscate/Decode Files or Information |
ToolBrute Ratel C4 | Brute Ratel C4 has the ability to deobfuscate its payload prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
ToolImminent Monitor | Imminent Monitor has decoded malware components that are then dropped to the system. |
| T1140 Deobfuscate/Decode Files or Information |
ToolIronNetInjector | IronNetInjector has the ability to decrypt embedded .NET and PE payloads. |
| T1140 Deobfuscate/Decode Files or Information |
ToolExpand | Expand can be used to decompress a local or remote CAB file into an executable. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can deobfuscate an encoded Python script prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMini Shai-Hulud | Mini Shai-Hulud has the ability to decrypt obfuscated payloads. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCanisterWorm | CanisterWorm has decoded a long Base64 string to obtain a Python script for its second-stage payload. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.