Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.016 Junk Code Insertion |
Malwareyty | yty contains junk code in its binary, likely to confuse malware analysts. |
| T1027.016 Junk Code Insertion |
MalwarePony | Pony obfuscates memory flow by adding junk instructions when executing to make analysis more difficult. |
| T1027.016 Junk Code Insertion |
MalwareWastedLocker | WastedLocker contains junk code to increase its entropy and hide the actual code. |
| T1027.016 Junk Code Insertion |
MalwareZeroT | ZeroT has obfuscated DLLs and functions using dummy API calls inserted between real instructions. |
| T1027.016 Junk Code Insertion |
MalwareSamSam | SamSam has used garbage code to pad some of its malware components. |
| T1027.016 Junk Code Insertion |
MalwareFatDuke | FatDuke has been packed with junk code and strings. |
| T1027.016 Junk Code Insertion |
MalwareCORESHELL | CORESHELL contains unused machine instructions in a likely attempt to hinder analysis. |
| T1027.016 Junk Code Insertion |
MalwareNOOPLDR | NOOPLDR can insert junk code to obfuscate malicious payloads. |
| T1027.016 Junk Code Insertion |
MalwarePureCrypter | PureCrypter can insert junk code to avoid detection. |
| T1027.016 Junk Code Insertion |
MalwareXTunnel | A version of XTunnel introduced in July 2015 inserted junk code into the binary in a likely attempt to obfuscate it and bypass security products. |
| T1027.016 Junk Code Insertion |
MalwareLODEINFO | LODEINFO has inserted junk code to obstruct code analysis. |
| T1027.016 Junk Code Insertion |
MalwareStrelaStealer | StrelaStealer variants have included excessive mathematical functions padding the binary and slowing execution for anti-analysis and sandbox evasion purposes. |
| T1027.016 Junk Code Insertion |
MalwareFinFisher | FinFisher contains junk code in its functions in an effort to confuse disassembly programs. |
| T1027.016 Junk Code Insertion |
MalwareANELLDR | ANELLDR can use junk code for payload obfuscation. |
| T1027.016 Junk Code Insertion |
MalwareMaze | Maze has inserted large blocks of junk code, including some components to decrypt strings and other important information for later in the encryption process. |
| T1027.016 Junk Code Insertion |
MalwarePOWERSTATS | POWERSTATS has used useless code blocks to counter analysis. |
| T1027.016 Junk Code Insertion |
MalwareGoopy | Goopy's decrypter have been inflated with junk code in between legitimate API functions, and also included infinite loops to avoid analysis. |
| T1027.016 Junk Code Insertion |
MalwareGelsemium | Gelsemium can use junk code to hide functions and evade detection. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.