Sub-technique of T1027 Obfuscated Files or Information.View on attack.mitre.org
Adversaries may obfuscate content during command execution to impede detection. Command-line obfuscation is a method of making strings and patterns within commands and scripts more difficult to signature and analyze. This type of obfuscation can be included within commands executed by delivered payloads (e.g., Phishing and Drive-by Compromise) or interactively via Command and Scripting Interpreter.
For example, adversaries may abuse syntax that utilizes various symbols and escape characters (such as spacing, `^`, `+`. `$`, and `%`) to make commands difficult to analyze while maintaining the same intended functionality. Many languages support built-in obfuscation in the form of base64 or URL encoding. Adversaries may also manually implement command obfuscation via string splitting (`“Wor”+“d.Application”`), order and casing of characters (`rev <<<'dwssap/cte/ tac'`), globing (`mkdir -p '/tmp/:&$NiA'`), as well as various tricks involving passing strings through tokens/environment variables/input streams.
Adversaries may also use tricks such as directory traversals to obfuscate references to the binary being invoked by a command (`C:\voi\pcw\..\..\Windows\tei\qs\k\..\..\..\system32\erool\..\wbem\wg\je\..\..\wmic.exe shadowcopy delete`).
Tools such as Invoke-Obfuscation and Invoke-DOSfucation have also been used to obfuscate commands.
Rules on DetectionCode tagged with T1027.010.
| Rule | Level | Log source |
|---|---|---|
| Obfuscated PowerShell MSI Install via WindowsInstaller COM | high | windows / process_creation |
| Python One-Liners with Base64 Decoding | high | windows / process_creation |
| Python One-Liners with Base64 Decoding - Linux | high | linux / process_creation |
| Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix | high | windows / process_creation |
| Suspicious Space Characters in RunMRU Registry Path - ClickFix | high | windows / registry_set |
| Suspicious Space Characters in TypedPaths Registry Path - FileFix | high | windows / registry_set |
| Potential Obfuscated Ordinal Call Via Rundll32 | medium | windows / process_creation |
| Suspicious Usage of For Loop with Recursive Directory Search in CMD | medium | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows Command Obfuscation with Environment Variable Substrings | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows PowerShell Process Implementing Manual Base64 Decoder | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAPT19 | APT19 used Base64 to obfuscate executed commands. |
| GroupAPT32 | APT32 has used the `Invoke-Obfuscation` framework to obfuscate their PowerShell. |
| GroupAquatic Panda | Aquatic Panda has encoded PowerShell commands in Base64. |
| GroupChimera | Chimera has encoded PowerShell commands. |
| GroupCobalt Group | Cobalt Group obfuscated several scriptlets and code used on the victim’s machine, including through use of XOR and RC4. |
| GroupContagious Interview | Contagious Interview has obfuscated JavaScript code using Base64 and variable substitutions. |
| GroupFIN6 | FIN6 has used encoded PowerShell commands. |
| GroupFIN7 | FIN7 has used fragmented strings, environment variables, standard input (stdin), and native character-replacement functionalities to obfuscate commands. |
| Used by | Procedure example |
|---|---|
| MalwareAstaroth | Astaroth has obfuscated and randomized parts of the JScript code it is initiating. |
| MalwareBackConfig | BackConfig has used compressed and decimal encoded VBS scripts. |
| MalwareBADHATCH | BADHATCH malicious PowerShell commands can be encoded with base64. |
| MalwareCARROTBAT | CARROTBAT has the ability to execute obfuscated commands on the infected host. |
| MalwareComRAT | ComRAT has used encryption and base64 to obfuscate its orchestrator code in the Registry. ComRAT has also used encoded PowerShell scripts. |
| MalwareCookieMiner | CookieMiner has used base64 encoding to obfuscate scripts on the system. |
| MalwareDarkWatchman | DarkWatchman has used Base64 to encode PowerShell commands. |
| MalwareDenis | Denis has encoded its PowerShell commands in Base64. |
| Used by | Procedure example |
|---|---|
| CampaignC0018 | During C0018, the threat actors used Base64 to encode their PowerShell scripts. |
| CampaignC0021 | During C0021, the threat actors used encoded PowerShell commands. |
| CampaignFrankenstein | During Frankenstein, the threat actors ran encoded commands from the command line. |
| CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors executed an encoded VBScript file. |
| CampaignOperation Wocao | During Operation Wocao, threat actors executed PowerShell commands which were encoded or compressed using Base64, zlib, and XOR. |
| CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors executed Base64-encoded PowerShell commands. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.