ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1027.001×

22 examples

TechniqueUsed byProcedure example
T1027.001
Binary Padding
MalwareEmissary

A variant of Emissary appends junk data to the end of its DLL file to create a large file that may exceed the maximum size that anti-virus programs can scan.

T1027.001
Binary Padding
MalwareHeartCrypt

HeartCrypt can add several hundred thousand kilobytes of null padding to payloads before saving onto the file system.

T1027.001
Binary Padding
MalwareTONESHELL

TONESHELL has used randomized padding to obfuscate payloads.

T1027.001
Binary Padding
MalwareEmotet

Emotet inflates malicious files and malware as an evasion technique.

T1027.001
Binary Padding
MalwareSnip3

Snip3 can obfuscate strings using junk Chinese characters.

T1027.001
Binary Padding
MalwareRifdoor

Rifdoor has added four additional bytes of data upon launching, then saved the changed version as C:\ProgramData\Initech\Initech.exe.

T1027.001
Binary Padding
MalwareCHIMNEYSWEEP

The CHIMNEYSWEEP installer has been padded with null bytes to inflate its size.

T1027.001
Binary Padding
MalwareLightSpy

LightSpy's configuration file is appended to the end of the binary. For example, the last `0x1d0` bytes of one sample is an AES encrypted configuration file with a static key of `3e2717e8b3873b29`.

T1027.001
Binary Padding
MalwareCostaBricks

CostaBricks has added the entire unobfuscated code of the legitimate open source application Blink to its code.

T1027.001
Binary Padding
MalwareJavali

Javali can use large obfuscated libraries to hinder detection and analysis.

T1027.001
Binary Padding
MalwarePlugX

PlugX has utilized junk code and opaque predicates in payloads to hinder analysis.

T1027.001
Binary Padding
MalwareBisonal

Bisonal has appended random binary data to the end of itself to generate a large binary.

T1027.001
Binary Padding
MalwareLatrodectus

Latrodectus has been obfuscated with a 129 byte sequence of junk data prepended to the file.

T1027.001
Binary Padding
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can execute FileRecvWriteRand to append random bytes to the end of a file received from C2.

T1027.001
Binary Padding
MalwareBlack Basta

Black Basta had added data prior to the Portable Executable (PE) header to prevent automatic scanners from identifying the payload.

T1027.001
Binary Padding
MalwareGrandoreiro

Grandoreiro has added BMP images to the resources section of its Portable Executable (PE) file increasing each binary to at least 300MB in size.

T1027.001
Binary Padding
MalwareCaminho

Caminho can use junk code for obfuscation.

T1027.001
Binary Padding
MalwareKwampirs

Before writing to disk, Kwampirs inserts a randomly generated string into the middle of the decrypted payload in an attempt to evade hash-based detections.

T1027.001
Binary Padding
MalwareGrimAgent

GrimAgent has the ability to add bytes to change the file hash.

T1027.001
Binary Padding
MalwareGoopy

Goopy has had null characters padded in its malicious DLL payload.

T1027.001
Binary Padding
MalwareQakBot

QakBot can use large file sizes to evade detection.

T1027.001
Binary Padding
MalwareComnie

Comnie appends a total of 64MB of garbage data to a file to deter any security products in place that may be scanning files on disk.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.