ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1001.001×

17 examples

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwareDowndelph

Downdelph inserts pseudo-random characters between each original character during encoding of C2 network requests, making it difficult to write signatures on them.

T1001.001
Junk Data
MalwareUPSTYLE

UPSTYLE retrieves a non-existent webpage from the command and control server then parses commands from the resulting error logs to decode commands to the web shell.

T1001.001
Junk Data
MalwareTurian

Turian can insert pseudo-random characters into its network encryption setup.

T1001.001
Junk Data
MalwareWellMess

WellMess can use junk data in the Base64 string for additional obfuscation.

T1001.001
Junk Data
MalwareGoldMax

GoldMax has used decoy traffic to surround its malicious network traffic to avoid detection.

T1001.001
Junk Data
MalwareBeaverTail

BeaverTail has added junk data or a dummy character prepended to a string to hamper decoding attempts.

T1001.001
Junk Data
MalwareLODEINFO

LODEINFO can append C2 communication with randomly generated junk data.

T1001.001
Junk Data
MalwareP8RAT

P8RAT can send randomly-generated data as part of its C2 communication.

T1001.001
Junk Data
MalwareMori

Mori has obfuscated the FML.dll with 200MB of junk data.

T1001.001
Junk Data
MalwareBendyBear

BendyBear has used byte randomization to obscure its behavior.

T1001.001
Junk Data
MalwareUroburos

Uroburos can add extra characters in encoded strings to help mimic DNS legitimate requests.

T1001.001
Junk Data
MalwareSUNBURST

SUNBURST added junk bytes to its C2 over HTTP.

T1001.001
Junk Data
MalwareP2P ZeuS

P2P ZeuS added junk data to outgoing UDP packets to peer implants.

T1001.001
Junk Data
MalwarePLEAD

PLEAD samples were found to be highly obfuscated with junk code.

T1001.001
Junk Data
MalwareTrailBlazer

TrailBlazer has used random identifier strings to obscure its C2 operations and result codes.

T1001.001
Junk Data
MalwareGrimAgent

GrimAgent can pad C2 messages with random generated values.

T1001.001
Junk Data
MalwareKevin

Kevin can generate a sequence of dummy HTTP C2 requests to obscure traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.