ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1027.010×

35 examples

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
MalwareIronWind

IronWind has used Base64 encoding and XOR encryption with the key “53” to obfuscate command strings.

T1027.010
Command Obfuscation
MalwareSardonic

Sardonic PowerShell scripts can be encrypted with RC4 and compressed using Gzip.

T1027.010
Command Obfuscation
MalwareUrsnif

Ursnif droppers execute base64 encoded PowerShell commands.

T1027.010
Command Obfuscation
MalwareTsundere Botnet

Tsundere Botnet’s MSI installer has Base64-encoded command execution.

T1027.010
Command Obfuscation
MalwareZeus Panda

Zeus Panda obfuscates the macro commands in its initial payload.

T1027.010
Command Obfuscation
MalwareHavoc

Havoc has utilized XOR encryption with the key “01-01-1900” to obfuscate command strings.

T1027.010
Command Obfuscation
MalwareCARROTBAT

CARROTBAT has the ability to execute obfuscated commands on the infected host.

T1027.010
Command Obfuscation
MalwareEmotet

Emotet has obfuscated macros within malicious documents to hide the URLs hosting the malware, CMD.exe arguments, and PowerShell scripts.

T1027.010
Command Obfuscation
MalwareBADHATCH

BADHATCH malicious PowerShell commands can be encoded with base64.

T1027.010
Command Obfuscation
MalwareMachete

Machete has used pyobfuscate, zlib compression, and base64 encoding for obfuscation. Machete has also used some visual obfuscation techniques by naming variables as combinations of letters to hinder analysis.

T1027.010
Command Obfuscation
MalwareFruitFly

FruitFly executes and stores obfuscated Perl scripts.

T1027.010
Command Obfuscation
MalwareDarkWatchman

DarkWatchman has used Base64 to encode PowerShell commands.

T1027.010
Command Obfuscation
MalwareSHARPSTATS

SHARPSTATS has used base64 encoding and XOR to obfuscate PowerShell scripts.

T1027.010
Command Obfuscation
MalwareNetwalker

Netwalker's PowerShell script has been obfuscated with multiple layers including base64 and hexadecimal encoding and XOR-encryption, as well as obfuscated PowerShell functions and variables.

T1027.010
Command Obfuscation
MalwareQUADAGENT

QUADAGENT was likely obfuscated using `Invoke-Obfuscation`.

T1027.010
Command Obfuscation
MalwareRedLine Stealer

RedLine Stealer has obfuscated scripts within text files used in execution.

T1027.010
Command Obfuscation
MalwareRogueRobin

The PowerShell script with the RogueRobin payload was obfuscated using the COMPRESS technique in `Invoke-Obfuscation`.

T1027.010
Command Obfuscation
MalwareSQLRat

SQLRat has used a character insertion obfuscation technique, making the script appear to contain Chinese characters.

T1027.010
Command Obfuscation
MalwareSibot

Sibot has obfuscated scripts used in execution.

T1027.010
Command Obfuscation
MalwareBackConfig

BackConfig has used compressed and decimal encoded VBS scripts.

T1027.010
Command Obfuscation
MalwarePHASEJAM

PHASEJAM has encoded commands with Base64.

T1027.010
Command Obfuscation
MalwarePoetRAT

PoetRAT has `pyminifier` to obfuscate scripts.

T1027.010
Command Obfuscation
MalwarePowerPunch

PowerPunch can use Base64-encoded scripts.

T1027.010
Command Obfuscation
MalwareComRAT

ComRAT has used encryption and base64 to obfuscate its orchestrator code in the Registry. ComRAT has also used encoded PowerShell scripts.

T1027.010
Command Obfuscation
MalwareIceApple

IceApple can use Base64 and "junk" JavaScript code to obfuscate information.

T1027.010
Command Obfuscation
MalwareKOCTOPUS

KOCTOPUS has obfuscated scripts with the BatchEncryption tool.

T1027.010
Command Obfuscation
MalwarePOWERSTATS

POWERSTATS uses character replacement, PowerShell environment variables, and XOR encoding to obfuscate code. POWERSTATS's backdoor code is a multi-layer obfuscated, encoded, and compressed blob. POWERSTATS has used PowerShell code with custom string obfuscation

T1027.010
Command Obfuscation
MalwareAstaroth

Astaroth has obfuscated and randomized parts of the JScript code it is initiating.

T1027.010
Command Obfuscation
MalwareQakBot

QakBot can use obfuscated and encoded scripts.

T1027.010
Command Obfuscation
MalwareCookieMiner

CookieMiner has used base64 encoding to obfuscate scripts on the system.

T1027.010
Command Obfuscation
MalwareDenis

Denis has encoded its PowerShell commands in Base64.

T1027.010
Command Obfuscation
MalwareLoudMiner

LoudMiner has obfuscated various scripts.

T1027.010
Command Obfuscation
MalwareXORIndex Loader

XORIndex Loader has obfuscated strings using ASCII buffers and TextDecoder.

T1027.010
Command Obfuscation
ToolPowerSploit

PowerSploit contains a collection of ScriptModification modules that compress and encode scripts and payloads.

T1027.010
Command Obfuscation
ToolEmpire

Empire has the ability to obfuscate commands using Invoke-Obfuscation.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.