Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.007 Dynamic API Resolution |
MalwareAvosLocker | AvosLocker has used obfuscated API calls that are retrieved by their checksums. |
| T1027.007 Dynamic API Resolution |
MalwareTONESHELL | TONESHELL has utilized a modified DJB2 algorithm to resolve APIs. |
| T1027.007 Dynamic API Resolution |
MalwareCANONSTAGER | CANONSTAGER has utilized custom API hashing to obfuscate the Windows APIs being used. |
| T1027.007 Dynamic API Resolution |
MalwareCLAIMLOADER | CLAIMLOADER has utilized XOR-encrypted API names and native APIs of `LdrLoadDll()` and `LderGetProcedureAddress()` to resolve imports dynamically. |
| T1027.007 Dynamic API Resolution |
MalwareHTTPTroy | HTTPTroy has utilized dynamic API resolution by reconstructing API calls during runtime using combinations of arithmetic and logical operations to complicate static analysis. |
| T1027.007 Dynamic API Resolution |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use `LoadLibrary` and `GetProcAddress` to resolve Windows API function strings at run time. |
| T1027.007 Dynamic API Resolution |
MalwarePteranodon | Pteranodon can use a dynamic Windows hashing algorithm to map API components. |
| T1027.007 Dynamic API Resolution |
MalwareSplatDropper | SplatDropper has leveraged hashed Windows API calls using a seed value of "131313". |
| T1027.007 Dynamic API Resolution |
MalwarePlugX | PlugX has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API. |
| T1027.007 Dynamic API Resolution |
MalwareLatrodectus | Latrodectus can resolve Windows APIs dynamically by hash. |
| T1027.007 Dynamic API Resolution |
MalwareLODEINFO | LODEINFO can use a hashing algorithm to dynamically resolve API function addresses. |
| T1027.007 Dynamic API Resolution |
MalwareLP-Notes | LP-Notes has dynamically resolved API functions during the C runtime startup. |
| T1027.007 Dynamic API Resolution |
MalwareBazar | Bazar can hash then resolve API calls at runtime. |
| T1027.007 Dynamic API Resolution |
MalwareHiddenFace | HiddenFace can dynamically resolve Windows APIs. |
| T1027.007 Dynamic API Resolution |
MalwareSamurai | Samurai can encrypt API name strings with an XOR-based algorithm. |
| T1027.007 Dynamic API Resolution |
MalwareRaccoon Stealer | Raccoon Stealer dynamically links key WinApi functions during execution. |
| T1027.007 Dynamic API Resolution |
ToolBrute Ratel C4 | Brute Ratel C4 can call and dynamically resolve hashed APIs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.