ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1027.016×

18 examples

TechniqueUsed byProcedure example
T1027.016
Junk Code Insertion
Malwareyty

yty contains junk code in its binary, likely to confuse malware analysts.

T1027.016
Junk Code Insertion
MalwarePony

Pony obfuscates memory flow by adding junk instructions when executing to make analysis more difficult.

T1027.016
Junk Code Insertion
MalwareWastedLocker

WastedLocker contains junk code to increase its entropy and hide the actual code.

T1027.016
Junk Code Insertion
MalwareZeroT

ZeroT has obfuscated DLLs and functions using dummy API calls inserted between real instructions.

T1027.016
Junk Code Insertion
MalwareSamSam

SamSam has used garbage code to pad some of its malware components.

T1027.016
Junk Code Insertion
MalwareFatDuke

FatDuke has been packed with junk code and strings.

T1027.016
Junk Code Insertion
MalwareCORESHELL

CORESHELL contains unused machine instructions in a likely attempt to hinder analysis.

T1027.016
Junk Code Insertion
MalwareNOOPLDR

NOOPLDR can insert junk code to obfuscate malicious payloads.

T1027.016
Junk Code Insertion
MalwarePureCrypter

PureCrypter can insert junk code to avoid detection.

T1027.016
Junk Code Insertion
MalwareXTunnel

A version of XTunnel introduced in July 2015 inserted junk code into the binary in a likely attempt to obfuscate it and bypass security products.

T1027.016
Junk Code Insertion
MalwareLODEINFO

LODEINFO has inserted junk code to obstruct code analysis.

T1027.016
Junk Code Insertion
MalwareStrelaStealer

StrelaStealer variants have included excessive mathematical functions padding the binary and slowing execution for anti-analysis and sandbox evasion purposes.

T1027.016
Junk Code Insertion
MalwareFinFisher

FinFisher contains junk code in its functions in an effort to confuse disassembly programs.

T1027.016
Junk Code Insertion
MalwareANELLDR

ANELLDR can use junk code for payload obfuscation.

T1027.016
Junk Code Insertion
MalwareMaze

Maze has inserted large blocks of junk code, including some components to decrypt strings and other important information for later in the encryption process.

T1027.016
Junk Code Insertion
MalwarePOWERSTATS

POWERSTATS has used useless code blocks to counter analysis.

T1027.016
Junk Code Insertion
MalwareGoopy

Goopy's decrypter have been inflated with junk code in between legitimate API functions, and also included infinite loops to avoid analysis.

T1027.016
Junk Code Insertion
MalwareGelsemium

Gelsemium can use junk code to hide functions and evade detection.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.