Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.001 Junk Data |
MalwareDowndelph | Downdelph inserts pseudo-random characters between each original character during encoding of C2 network requests, making it difficult to write signatures on them. |
| T1001.001 Junk Data |
MalwareUPSTYLE | UPSTYLE retrieves a non-existent webpage from the command and control server then parses commands from the resulting error logs to decode commands to the web shell. |
| T1001.001 Junk Data |
MalwareTurian | Turian can insert pseudo-random characters into its network encryption setup. |
| T1001.001 Junk Data |
MalwareWellMess | WellMess can use junk data in the Base64 string for additional obfuscation. |
| T1001.001 Junk Data |
MalwareGoldMax | GoldMax has used decoy traffic to surround its malicious network traffic to avoid detection. |
| T1001.001 Junk Data |
MalwareBeaverTail | BeaverTail has added junk data or a dummy character prepended to a string to hamper decoding attempts. |
| T1001.001 Junk Data |
MalwareLODEINFO | LODEINFO can append C2 communication with randomly generated junk data. |
| T1001.001 Junk Data |
MalwareP8RAT | P8RAT can send randomly-generated data as part of its C2 communication. |
| T1001.001 Junk Data |
MalwareMori | Mori has obfuscated the FML.dll with 200MB of junk data. |
| T1001.001 Junk Data |
MalwareBendyBear | BendyBear has used byte randomization to obscure its behavior. |
| T1001.001 Junk Data |
MalwareUroburos | Uroburos can add extra characters in encoded strings to help mimic DNS legitimate requests. |
| T1001.001 Junk Data |
MalwareSUNBURST | SUNBURST added junk bytes to its C2 over HTTP. |
| T1001.001 Junk Data |
MalwareP2P ZeuS | P2P ZeuS added junk data to outgoing UDP packets to peer implants. |
| T1001.001 Junk Data |
MalwarePLEAD | PLEAD samples were found to be highly obfuscated with junk code. |
| T1001.001 Junk Data |
MalwareTrailBlazer | TrailBlazer has used random identifier strings to obscure its C2 operations and result codes. |
| T1001.001 Junk Data |
MalwareGrimAgent | GrimAgent can pad C2 messages with random generated values. |
| T1001.001 Junk Data |
MalwareKevin | Kevin can generate a sequence of dummy HTTP C2 requests to obscure traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.