Binary Padding

T1027.001

Sub-technique of T1027 Obfuscated Files or Information.View on attack.mitre.org

About this technique

Adversaries may use binary padding to add junk data and change the on-disk representation of malware. This can be done without affecting the functionality or behavior of a binary, but can increase the size of the binary beyond what some security tools are capable of handling due to file size limitations.

Binary padding effectively changes the checksum of the file and can also be used to avoid hash-based blocklists and static anti-virus signatures. The padding used is commonly generated by a function to create junk data and then appended to the end or applied to sections of malware. Increasing the file size may decrease the effectiveness of certain tools and detection capabilities that are not designed or configured to scan large files. This may also reduce the likelihood of being collected for analysis. Public file scanning services, such as VirusTotal, limits the maximum size of an uploaded file to be analyzed.

Detection rules3

Rules on DetectionCode tagged with T1027.001.

Sigma3

RuleLevelLog source
Binary Padding - Linuxhighlinux / NULL
Binary Padding - MacOShighmacos / process_creation
Failed Code Integrity Checksinformationalwindows / NULL

Splunk0

No Splunk rules are mapped to this technique yet.

Groups8

Software22

Campaigns0

None recorded.

Procedure examples30

Groups8

Used byProcedure example
GroupAkira

Akira has used binary padding to obfuscate payloads.

GroupAPT29

APT29 used large size files to avoid detection by security solutions with hardcoded size limits.

GroupBRONZE BUTLER

BRONZE BUTLER downloader code has included "0" characters at the end of the file to inflate the file size in a likely attempt to evade anti-virus detection.

GroupHigaisa

Higaisa performed padding with null bytes before calculating its hash.

GroupKimsuky

Kimsuky has performed padding of PowerShell command line code with over 100 spaces.

GroupLeviathan

Leviathan has inserted garbage characters into code, presumably to avoid anti-virus detection.

GroupMoafee

Moafee has been known to employ binary padding.

GroupPatchwork

Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes.

Software22

Used byProcedure example
MalwareBisonal

Bisonal has appended random binary data to the end of itself to generate a large binary.

MalwareBlack Basta

Black Basta had added data prior to the Portable Executable (PE) header to prevent automatic scanners from identifying the payload.

MalwareCaminho

Caminho can use junk code for obfuscation.

MalwareCHIMNEYSWEEP

The CHIMNEYSWEEP installer has been padded with null bytes to inflate its size.

MalwareComnie

Comnie appends a total of 64MB of garbage data to a file to deter any security products in place that may be scanning files on disk.

MalwareCostaBricks

CostaBricks has added the entire unobfuscated code of the legitimate open source application Blink to its code.

MalwareEmissary

A variant of Emissary appends junk data to the end of its DLL file to create a large file that may exceed the maximum size that anti-virus programs can scan.

MalwareEmotet

Emotet inflates malicious files and malware as an evasion technique.

View all 22 software examples

References3

  1. ESET OceanLotus Open source
    Foltýn, T. (2018, March 13). OceanLotus ships new backdoor using old tricks. Retrieved May 22, 2018.
  2. Securelist Malware Tricks April 2017 Open source
    Ishimaru, S.. (2017, April 13). Old Malware Tricks To Bypass Detection in the Age of Big Data. Retrieved May 30, 2019.
  3. VirusTotal FAQ Open source
    VirusTotal. (n.d.). VirusTotal FAQ. Retrieved May 23, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.