Real-world descriptions of how a group, tool or campaign used a technique.
138 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareTrickBot | TrickBot uses non-descriptive names to hide functionality. |
| T1027 Obfuscated Files or Information |
MalwareEKANS | EKANS uses encoded strings in its process kill list. |
| T1027 Obfuscated Files or Information |
MalwareSynAck | SynAck payloads are obfuscated prior to compilation to inhibit analysis and/or reverse engineering. |
| T1027 Obfuscated Files or Information |
MalwareBumblebee | Bumblebee has been delivered as password-protected zipped ISO files and used control-flow-flattening to obfuscate the flow of functions. |
| T1027 Obfuscated Files or Information |
MalwareBRICKSTORM | BRICKSTORM has utilized Go libraries to include Garble to obfuscate code. |
| T1027 Obfuscated Files or Information |
MalwareAmadey | Amadey has obfuscated strings such as antivirus vendor names, domains, files, and others. |
| T1027 Obfuscated Files or Information |
MalwareOrz | Some Orz strings are base64 encoded, such as the embedded DLL known as MockDll. |
| T1027 Obfuscated Files or Information |
MalwareNOKKI | NOKKI uses Base64 encoding for strings. |
| T1027 Obfuscated Files or Information |
MalwareAvosLocker | AvosLocker has used XOR-encoded strings. |
| T1027 Obfuscated Files or Information |
MalwareCOATHANGER | COATHANGER can store obfuscated configuration information in the last 56 bytes of the file `/date/.bd.key/preload.so`. |
| T1027 Obfuscated Files or Information |
MalwareSardonic | Sardonic can use certain ConfuserEx features for obfuscation and can be encoded in a base64 string. |
| T1027 Obfuscated Files or Information |
MalwareMatryoshka | Matryoshka obfuscates API function names using a substitute cipher combined with Base64 encoding. |
| T1027 Obfuscated Files or Information |
MalwareEcipekac | Ecipekac can use XOR, AES, and DES to encrypt loader shellcode. |
| T1027 Obfuscated Files or Information |
MalwareAppleSeed | AppleSeed has the ability to Base64 encode its payload and custom encrypt API calls. |
| T1027 Obfuscated Files or Information |
MalwareBUSHWALK | BUSHWALK can encrypt the resulting data generated from C2 commands with RC4. |
| T1027 Obfuscated Files or Information |
MalwareNETWIRE | NETWIRE has used a custom obfuscation algorithm to hide strings including Registry keys, APIs, and DLL names. |
| T1027 Obfuscated Files or Information |
MalwareBOOKWORM | BOOKWORM has been delivered using self-extracting RAR archives. |
| T1027 Obfuscated Files or Information |
MalwareOLDBAIT | OLDBAIT obfuscates internal strings and unpacks them at startup. |
| T1027 Obfuscated Files or Information |
MalwareTEARDROP | TEARDROP created and read from a file with a fake JPG header, and its payload was encrypted with a simple rotating XOR cipher. |
| T1027 Obfuscated Files or Information |
MalwareTurian | Turian can use VMProtect for obfuscation. |
| T1027 Obfuscated Files or Information |
MalwareAction RAT | Action RAT's commands, strings, and domains can be Base64 encoded within the payload. |
| T1027 Obfuscated Files or Information |
MalwarePUBLOAD | PUBLOAD has obfuscated DLL names using the ror13AddHash32 algorithm. |
| T1027 Obfuscated Files or Information |
MalwareGootloader | The Gootloader first stage script is obfuscated using random alpha numeric strings. |
| T1027 Obfuscated Files or Information |
MalwarePolyglotDuke | PolyglotDuke can custom encrypt strings. |
| T1027 Obfuscated Files or Information |
MalwareSombRAT | SombRAT can encrypt strings with XOR-based routines and use a custom AES storage format for plugins, configuration, C2 domains, and harvested data. |
| T1027 Obfuscated Files or Information |
MalwareSnip3 | Snip3 has the ability to obfuscate strings using XOR encryption. |
| T1027 Obfuscated Files or Information |
MalwareRegDuke | RegDuke can use control-flow flattening or the commercially available .NET Reactor for obfuscation. |
| T1027 Obfuscated Files or Information |
MalwareInvisiMole | InvisiMole avoids analysis by encrypting all strings, internal files, configuration data and by using a custom executable format. |
| T1027 Obfuscated Files or Information |
MalwareP.A.S. Webshell | P.A.S. Webshell can use encryption and base64 encoding to hide strings and to enforce access control once deployed. |
| T1027 Obfuscated Files or Information |
MalwareConti | Conti can use compiler-based obfuscation for its code, encrypt DLLs, and hide Windows API calls. |
| T1027 Obfuscated Files or Information |
MalwareRaspberry Robin | Raspberry Robin uses mixed-case letters for filenames and commands to evade detection. |
| T1027 Obfuscated Files or Information |
MalwareDiavol | Diavol has Base64 encoded the RSA public key used for encrypting files. |
| T1027 Obfuscated Files or Information |
MalwareSiloscape | Siloscape itself is obfuscated and uses obfuscated API calls. |
| T1027 Obfuscated Files or Information |
MalwareRustyWater | RustyWater has an obfuscated function (i.e. love_me__()) that dynamically reconstructs the string WScript.Shell using hard-coded ASCII values and the Chr() function. |
| T1027 Obfuscated Files or Information |
MalwareHTTPTroy | HTTPTroy has obfuscated strings using Single Instruction Multiple Data (SIMD) instructions to hinder analysis and detection. |
| T1027 Obfuscated Files or Information |
MalwareKazuar | Kazuar is obfuscated using the open source ConfuserEx protector. Kazuar also obfuscates the name of created files/folders/mutexes and encrypts debug messages written to log files using the Rijndael cipher. |
| T1027 Obfuscated Files or Information |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use a custom Base64 alphabet to encode an API decryption key. |
| T1027 Obfuscated Files or Information |
MalwareFatDuke | FatDuke can use base64 encoding, string stacking, and opaque predicates for obfuscation. |
| T1027 Obfuscated Files or Information |
MalwareDRATzarus | DRATzarus can be partly encrypted with XOR. |
| T1027 Obfuscated Files or Information |
MalwareSHOTPUT | SHOTPUT is obscured using XOR encoding and appended to a valid GIF file. |
| T1027 Obfuscated Files or Information |
MalwareAvaddon | Avaddon has used encrypted strings. |
| T1027 Obfuscated Files or Information |
MalwareConficker | Conficker has obfuscated its code to prevent its removal from host machines. |
| T1027 Obfuscated Files or Information |
MalwareFlagpro | Flagpro has been delivered within ZIP or RAR password-protected archived files. |
| T1027 Obfuscated Files or Information |
MalwareGreen Lambert | Green Lambert has encrypted strings. |
| T1027 Obfuscated Files or Information |
MalwareISMInjector | ISMInjector is obfuscated with the off-the-shelf SmartAssembly .NET obfuscator created by red-gate.com. |
| T1027 Obfuscated Files or Information |
MalwarePUNCHBUGGY | PUNCHBUGGY has hashed most its code's functions and encrypted payloads with base64 and XOR. |
| T1027 Obfuscated Files or Information |
MalwarePOSHSPY | POSHSPY appends a file signature header (randomly selected from six file types) to encrypted data prior to upload or download. |
| T1027 Obfuscated Files or Information |
MalwareMiniDuke | MiniDuke can use control flow flattening to obscure code. |
| T1027 Obfuscated Files or Information |
MalwareAnchor | Anchor has obfuscated code with stack strings and string encryption. |
| T1027 Obfuscated Files or Information |
MalwareDarkTortilla | DarkTortilla has been obfuscated with the DeepSea .NET and ConfuserEx code obfuscators. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.