ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1027.013×

195 examples

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareTrickBot

TrickBot uses an AES CBC (256 bits) encryption algorithm for its loader and configuration files.

T1027.013
Encrypted/Encoded File
MalwareBLINDINGCAN

BLINDINGCAN has obfuscated code using Base64 encoding.

T1027.013
Encrypted/Encoded File
MalwareNinja

The Ninja payload is XOR encrypted and compressed. Ninja has also XORed its configuration data with a constant value of `0xAA`.

T1027.013
Encrypted/Encoded File
MalwareBRICKSTORM

BRICKSTORM has utilized XOR cipher encryption to hide key strings within their code, to include IPv4 addresses of public DNS-over-HTTPS (DOH) servers.

T1027.013
Encrypted/Encoded File
MalwareTorisma

Torisma has been Base64 encoded and AES encrypted.

T1027.013
Encrypted/Encoded File
MalwareDOGCALL

DOGCALL is encrypted using single-byte XOR.

T1027.013
Encrypted/Encoded File
MalwareStuxnet

Stuxnet uses encrypted configuration blocks and writes encrypted files to disk.

T1027.013
Encrypted/Encoded File
MalwareMEDUSA

MEDUSA can XOR encrypt configuration strings.

T1027.013
Encrypted/Encoded File
MalwareVersaMem

VersaMem encrypted captured credentials with AES then Base64 encoded them before writing to local storage.

T1027.013
Encrypted/Encoded File
MalwareChinoxy

Chinoxy has encrypted its configuration file.

T1027.013
Encrypted/Encoded File
MalwarePAKLOG

PAKLOG has utilized a simple encoding mechanism to encode characters in the buffer.

T1027.013
Encrypted/Encoded File
MalwareSmoke Loader

Smoke Loader uses a simple one-byte XOR method to obfuscate values in the malware.

T1027.013
Encrypted/Encoded File
MalwareWindTail

WindTail can be delivered as a compressed, encrypted, and encoded payload.

T1027.013
Encrypted/Encoded File
MalwareEmissary

Variants of Emissary encrypt payloads using various XOR ciphers, as well as a custom algorithm that uses the "srand" and "rand" functions.

T1027.013
Encrypted/Encoded File
MalwareExaramel for Linux

Exaramel for Linux uses RC4 for encrypting the configuration.

T1027.013
Encrypted/Encoded File
MalwareHAWKBALL

HAWKBALL has encrypted the payload with an XOR-based algorithm.

T1027.013
Encrypted/Encoded File
MalwarePS1

PS1 is distributed as a set of encrypted files and scripts.

T1027.013
Encrypted/Encoded File
MalwareHeartCrypt

HeartCrypt strings are encrypted via a single-byte XOR operation rotating over a hard-coded key, possibly provided by the PaaS customers.

T1027.013
Encrypted/Encoded File
MalwareUrsnif

Ursnif has used an XOR-based algorithm to encrypt Tor clients dropped to disk. Ursnif droppers have also been delivered as password-protected zip files that execute base64 encoded PowerShell commands.

T1027.013
Encrypted/Encoded File
MalwareThreatNeedle

ThreatNeedle has been compressed and obfuscated using RC4, AES, or XOR.

T1027.013
Encrypted/Encoded File
MalwareRansomHub

RansomHub has an encrypted configuration file.

T1027.013
Encrypted/Encoded File
MalwareRedLeaves

A RedLeaves configuration file is encrypted with a simple XOR key, 0x53.

T1027.013
Encrypted/Encoded File
MalwareTsundere Botnet

Tsundere Botnet’s loader contained AES-CBC/PKCS7 encrypted blobs, which were descrypted and written to disk.

T1027.013
Encrypted/Encoded File
MalwareZeus Panda

Zeus Panda encrypts strings with XOR. Zeus Panda also encrypts all configuration and settings in AES and RC4.

T1027.013
Encrypted/Encoded File
MalwareCARROTBAT

CARROTBAT has the ability to download a base64 encoded payload.

T1027.013
Encrypted/Encoded File
MalwareGravityRAT

GravityRAT supports file encryption (AES with the key "lolomycin2017").

T1027.013
Encrypted/Encoded File
MalwareInvisibleFerret

InvisibleFerret has utilized the XOR and Base64 encoding for each of its modules. InvisibleFerret has also obfuscated files with a combination of zlib, Base64 and reverse string order. InvisibleFerret has also utilized the XOR and Base64 encoding some of its Python scripts.

T1027.013
Encrypted/Encoded File
MalwareStrongPity

StrongPity has used encrypted strings in its dropper component.

T1027.013
Encrypted/Encoded File
MalwareAuditCred

AuditCred encrypts the configuration.

T1027.013
Encrypted/Encoded File
MalwareROAMINGHOUSE

ROAMINGHOUSE can embed a ZIP file containing UPPERCUT components into three base64 encoded parts.

T1027.013
Encrypted/Encoded File
MalwareUPSTYLE

UPSTYLE stores primary content as base64-encoded objects.

T1027.013
Encrypted/Encoded File
MalwareMedusa Ransomware

Medusa Ransomware has utilized XOR encrypted strings.

T1027.013
Encrypted/Encoded File
MalwareRainyDay

RainyDay has downloaded as a XOR-encrypted payload.

T1027.013
Encrypted/Encoded File
MalwarePyDCrypt

PyDCrypt has been compiled and encrypted with PyInstaller, specifically using the --key flag during the build phase.

T1027.013
Encrypted/Encoded File
MalwareBOOKWORM

BOOKWORM has utilized Base64 encoding to obfuscate its payload.

T1027.013
Encrypted/Encoded File
MalwareEnvyScout

EnvyScout can Base64 encode payloads.

T1027.013
Encrypted/Encoded File
MalwareGreyEnergy

GreyEnergy encrypts its configuration files with AES-256 and also encrypts its strings.

T1027.013
Encrypted/Encoded File
MalwareAria-body

Aria-body has used an encrypted configuration file for its loader.

T1027.013
Encrypted/Encoded File
MalwareEmotet

Emotet uses obfuscated URLs to download a ZIP file.

T1027.013
Encrypted/Encoded File
MalwareDUSTTRAP

DUSTTRAP begins with an initial launcher that decrypts an AES-128-CFB encrypted file on disk and executes it in memory.

T1027.013
Encrypted/Encoded File
MalwareAvenger

Avenger has the ability to XOR encrypt files to be sent to C2.

T1027.013
Encrypted/Encoded File
MalwareDUSTPAN

DUSTPAN decrypts an embedded payload.

T1027.013
Encrypted/Encoded File
MalwarePrikormka

Some resources in Prikormka are encrypted with a simple XOR operation or encoded with Base64.

T1027.013
Encrypted/Encoded File
MalwareDacls

Dacls can encrypt its configuration file with AES CBC.

T1027.013
Encrypted/Encoded File
MalwareWoody RAT

Woody RAT has used Base64 encoded strings and scripts.

T1027.013
Encrypted/Encoded File
MalwareMafalda

Mafalda has been obfuscated and contains encrypted functions.

T1027.013
Encrypted/Encoded File
MalwareSquirrelwaffle

Squirrelwaffle has been obfuscated with a XOR-based algorithm.

T1027.013
Encrypted/Encoded File
MalwareHexEval Loader

HexEval Loader has encoded module names and C2 URLs as hexadecimal strings in attempts to evade analysis.

T1027.013
Encrypted/Encoded File
MalwareHildegard

Hildegard has encrypted an ELF file.

T1027.013
Encrypted/Encoded File
MalwareFlawedGrace

FlawedGrace encrypts its C2 configuration files with AES in CBC mode.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.