Real-world descriptions of how a group, tool or campaign used a technique.
35 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
MalwareIronWind | IronWind has used Base64 encoding and XOR encryption with the key “53” to obfuscate command strings. |
| T1027.010 Command Obfuscation |
MalwareSardonic | Sardonic PowerShell scripts can be encrypted with RC4 and compressed using Gzip. |
| T1027.010 Command Obfuscation |
MalwareUrsnif | Ursnif droppers execute base64 encoded PowerShell commands. |
| T1027.010 Command Obfuscation |
MalwareTsundere Botnet | Tsundere Botnet’s MSI installer has Base64-encoded command execution. |
| T1027.010 Command Obfuscation |
MalwareZeus Panda | Zeus Panda obfuscates the macro commands in its initial payload. |
| T1027.010 Command Obfuscation |
MalwareHavoc | Havoc has utilized XOR encryption with the key “01-01-1900” to obfuscate command strings. |
| T1027.010 Command Obfuscation |
MalwareCARROTBAT | CARROTBAT has the ability to execute obfuscated commands on the infected host. |
| T1027.010 Command Obfuscation |
MalwareEmotet | Emotet has obfuscated macros within malicious documents to hide the URLs hosting the malware, CMD.exe arguments, and PowerShell scripts. |
| T1027.010 Command Obfuscation |
MalwareBADHATCH | BADHATCH malicious PowerShell commands can be encoded with base64. |
| T1027.010 Command Obfuscation |
MalwareMachete | Machete has used pyobfuscate, zlib compression, and base64 encoding for obfuscation. Machete has also used some visual obfuscation techniques by naming variables as combinations of letters to hinder analysis. |
| T1027.010 Command Obfuscation |
MalwareFruitFly | FruitFly executes and stores obfuscated Perl scripts. |
| T1027.010 Command Obfuscation |
MalwareDarkWatchman | DarkWatchman has used Base64 to encode PowerShell commands. |
| T1027.010 Command Obfuscation |
MalwareSHARPSTATS | SHARPSTATS has used base64 encoding and XOR to obfuscate PowerShell scripts. |
| T1027.010 Command Obfuscation |
MalwareNetwalker | Netwalker's PowerShell script has been obfuscated with multiple layers including base64 and hexadecimal encoding and XOR-encryption, as well as obfuscated PowerShell functions and variables. |
| T1027.010 Command Obfuscation |
MalwareQUADAGENT | QUADAGENT was likely obfuscated using `Invoke-Obfuscation`. |
| T1027.010 Command Obfuscation |
MalwareRedLine Stealer | RedLine Stealer has obfuscated scripts within text files used in execution. |
| T1027.010 Command Obfuscation |
MalwareRogueRobin | The PowerShell script with the RogueRobin payload was obfuscated using the COMPRESS technique in `Invoke-Obfuscation`. |
| T1027.010 Command Obfuscation |
MalwareSQLRat | SQLRat has used a character insertion obfuscation technique, making the script appear to contain Chinese characters. |
| T1027.010 Command Obfuscation |
MalwareSibot | Sibot has obfuscated scripts used in execution. |
| T1027.010 Command Obfuscation |
MalwareBackConfig | BackConfig has used compressed and decimal encoded VBS scripts. |
| T1027.010 Command Obfuscation |
MalwarePHASEJAM | PHASEJAM has encoded commands with Base64. |
| T1027.010 Command Obfuscation |
MalwarePoetRAT | PoetRAT has `pyminifier` to obfuscate scripts. |
| T1027.010 Command Obfuscation |
MalwarePowerPunch | PowerPunch can use Base64-encoded scripts. |
| T1027.010 Command Obfuscation |
MalwareComRAT | ComRAT has used encryption and base64 to obfuscate its orchestrator code in the Registry. ComRAT has also used encoded PowerShell scripts. |
| T1027.010 Command Obfuscation |
MalwareIceApple | IceApple can use Base64 and "junk" JavaScript code to obfuscate information. |
| T1027.010 Command Obfuscation |
MalwareKOCTOPUS | KOCTOPUS has obfuscated scripts with the BatchEncryption tool. |
| T1027.010 Command Obfuscation |
MalwarePOWERSTATS | POWERSTATS uses character replacement, PowerShell environment variables, and XOR encoding to obfuscate code. POWERSTATS's backdoor code is a multi-layer obfuscated, encoded, and compressed blob. POWERSTATS has used PowerShell code with custom string obfuscation |
| T1027.010 Command Obfuscation |
MalwareAstaroth | Astaroth has obfuscated and randomized parts of the JScript code it is initiating. |
| T1027.010 Command Obfuscation |
MalwareQakBot | QakBot can use obfuscated and encoded scripts. |
| T1027.010 Command Obfuscation |
MalwareCookieMiner | CookieMiner has used base64 encoding to obfuscate scripts on the system. |
| T1027.010 Command Obfuscation |
MalwareDenis | Denis has encoded its PowerShell commands in Base64. |
| T1027.010 Command Obfuscation |
MalwareLoudMiner | LoudMiner has obfuscated various scripts. |
| T1027.010 Command Obfuscation |
MalwareXORIndex Loader | XORIndex Loader has obfuscated strings using ASCII buffers and TextDecoder. |
| T1027.010 Command Obfuscation |
ToolPowerSploit | PowerSploit contains a collection of ScriptModification modules that compress and encode scripts and payloads. |
| T1027.010 Command Obfuscation |
ToolEmpire | Empire has the ability to obfuscate commands using |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.