Real-world descriptions of how a group, tool or campaign used a technique.
22 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.001 Binary Padding |
MalwareEmissary | A variant of Emissary appends junk data to the end of its DLL file to create a large file that may exceed the maximum size that anti-virus programs can scan. |
| T1027.001 Binary Padding |
MalwareHeartCrypt | HeartCrypt can add several hundred thousand kilobytes of null padding to payloads before saving onto the file system. |
| T1027.001 Binary Padding |
MalwareTONESHELL | TONESHELL has used randomized padding to obfuscate payloads. |
| T1027.001 Binary Padding |
MalwareEmotet | Emotet inflates malicious files and malware as an evasion technique. |
| T1027.001 Binary Padding |
MalwareSnip3 | Snip3 can obfuscate strings using junk Chinese characters. |
| T1027.001 Binary Padding |
MalwareRifdoor | Rifdoor has added four additional bytes of data upon launching, then saved the changed version as |
| T1027.001 Binary Padding |
MalwareCHIMNEYSWEEP | The CHIMNEYSWEEP installer has been padded with null bytes to inflate its size. |
| T1027.001 Binary Padding |
MalwareLightSpy | LightSpy's configuration file is appended to the end of the binary. For example, the last `0x1d0` bytes of one sample is an AES encrypted configuration file with a static key of `3e2717e8b3873b29`. |
| T1027.001 Binary Padding |
MalwareCostaBricks | CostaBricks has added the entire unobfuscated code of the legitimate open source application Blink to its code. |
| T1027.001 Binary Padding |
MalwareJavali | Javali can use large obfuscated libraries to hinder detection and analysis. |
| T1027.001 Binary Padding |
MalwarePlugX | PlugX has utilized junk code and opaque predicates in payloads to hinder analysis. |
| T1027.001 Binary Padding |
MalwareBisonal | Bisonal has appended random binary data to the end of itself to generate a large binary. |
| T1027.001 Binary Padding |
MalwareLatrodectus | Latrodectus has been obfuscated with a 129 byte sequence of junk data prepended to the file. |
| T1027.001 Binary Padding |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can execute |
| T1027.001 Binary Padding |
MalwareBlack Basta | Black Basta had added data prior to the Portable Executable (PE) header to prevent automatic scanners from identifying the payload. |
| T1027.001 Binary Padding |
MalwareGrandoreiro | Grandoreiro has added BMP images to the resources section of its Portable Executable (PE) file increasing each binary to at least 300MB in size. |
| T1027.001 Binary Padding |
MalwareCaminho | Caminho can use junk code for obfuscation. |
| T1027.001 Binary Padding |
MalwareKwampirs | Before writing to disk, Kwampirs inserts a randomly generated string into the middle of the decrypted payload in an attempt to evade hash-based detections. |
| T1027.001 Binary Padding |
MalwareGrimAgent | GrimAgent has the ability to add bytes to change the file hash. |
| T1027.001 Binary Padding |
MalwareGoopy | Goopy has had null characters padded in its malicious DLL payload. |
| T1027.001 Binary Padding |
MalwareQakBot | QakBot can use large file sizes to evade detection. |
| T1027.001 Binary Padding |
MalwareComnie | Comnie appends a total of 64MB of garbage data to a file to deter any security products in place that may be scanning files on disk. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.