Real-world descriptions of how a group, tool or campaign used a technique.
301 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1140 Deobfuscate/Decode Files or Information |
MalwareTrickBot | TrickBot decodes the configuration data and modules. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBLINDINGCAN | BLINDINGCAN has used AES and XOR to decrypt its DLLs. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareNinja | The Ninja loader component can decrypt and decompress the payload. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePikabot | Pikabot decrypts command and control URIs using ADVobfuscator, and decrypts IP addresses and port numbers with a custom algorithm. Other versions of Pikabot decode chunks of stored stage 2 payload content in the initial payload |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSpark | Spark has used a custom XOR algorithm to decrypt the payload. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBumblebee | Bumblebee can deobfuscate C2 server responses and unpack its code on targeted hosts. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBRICKSTORM | BRICKSTORM has decoded its encrypted C2 traffic prior to execution. BRICKSTORM also has the ability to decode its obfuscated payload before execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAmadey | Amadey has decoded antivirus name strings. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTorisma | Torisma has used XOR and Base64 to decode C2 data. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareNOKKI | NOKKI uses a unique, custom de-obfuscation technique. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareStuxnet | Stuxnet decrypts resources that are loaded into memory and executed. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareIronWind | IronWind can deobfuscate the next stage payload using Base64 and XOR operations with the key "53". |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRotaJakiro | RotaJakiro uses the AES algorithm, bit shifts in a function called `rotate`, and an XOR cipher to decrypt resources required for persistence, process guarding, and file locking. It also performs this same function on encrypted stack strings and the `head` and `key` sections in the network packet structure used for C2 communications. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAvosLocker | AvosLocker has deobfuscated XOR-encoded strings. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareChinoxy | The Chinoxy dropping function can initiate decryption of its config file. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSharpStage | SharpStage has decompressed data received from the C2 server. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCOATHANGER | COATHANGER decodes configuration items from a bundled file for command and control activity. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSardonic | Sardonic can first decrypt with the RC4 algorithm using a hardcoded decryption key before decompressing. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSmoke Loader | Smoke Loader deobfuscates its code. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareWindTail | WindTail has the ability to decrypt strings using hard-coded AES keys. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareExaramel for Linux | Exaramel for Linux can decrypt its configuration file. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePS1 | PS1 can use an XOR key to decrypt a PowerShell loader and payload binary. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHeartCrypt | HeartCrypt can decrypt payloads prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareUrsnif | Ursnif has used crypto key information stored in the Registry to decrypt Tor clients dropped to disk. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCASTLETAP | CASTLETAP can filter and deobfuscate an XOR encrypted activation string in the payload of an ICMP echo request. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareThreatNeedle | ThreatNeedle can decrypt its payload using RC4, AES, or one-byte XORing. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRansomHub | RansomHub can use a provided passphrase to decrypt its configuration file. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTsundere Botnet | Tsundere Botnet’s loader has decrypted obfuscated JavaScript files using the AES-256 CBC algorithm, a build-specific key, and initialization vector. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareZeus Panda | Zeus Panda decrypts strings in the code during the execution process. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareInvisibleFerret | InvisibleFerret has decoded XOR-encrypted and Base-64-encoded payloads prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBankshot | Bankshot decodes embedded XOR strings. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarexCaon | xCaon has decoded strings from the C2 server before executing commands. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAuditCred | AuditCred uses XOR and RC4 to perform decryption on the code functions. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareROAMINGHOUSE | ROAMINGHOUSE can decode and drop a malicious ZIP file prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTONESHELL | TONESHELL has decoded its payload prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareUPSTYLE | UPSTYLE encodes its main content prior to loading via Python as base64-encoded blobs. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMedusa Ransomware | Medusa Ransomware has decoded XOR encrypted strings prior to execution in memory. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRainyDay | RainyDay can decrypt its payload via a XOR key. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareEcipekac | Ecipekac has the ability to decrypt fileless loader modules. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAppleSeed | AppleSeed can decode its payload prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBUSHWALK | BUSHWALK can Base64 decode and RC4 decrypt malicious payloads sent through a web request’s command parameter. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePyDCrypt | PyDCrypt has decrypted and dropped the DCSrv payload to disk. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePowerExchange | PowerExchange can decode and decrypt C2 commands received via email. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBOOKWORM | BOOKWORM has decoded its Base64 encoded payload prior to execution. BOOKWORM has also encrypted files with RC4 and has decrypted its payload prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareEnvyScout | EnvyScout can deobfuscate and write malicious ISO files to disk. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAria-body | Aria-body has the ability to decrypt the loader configuration and payload DLL. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareEmotet | Emotet has used a self-extracting RAR file to deliver modules to victims. Emotet has also extracted embedded executables from files using hard-coded buffer offsets. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCrimson | Crimson can decode its encoded PE file prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTEARDROP | TEARDROP was decoded using a custom rolling XOR algorithm to execute a customized Cobalt Strike payload. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDUSTTRAP | DUSTTRAP deobfuscates embedded payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.