Obfuscated Files or Information

T1027

Technique with 18 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Payloads may be compressed, archived, or encrypted in order to avoid detection. These payloads may be used during Initial Access or later to mitigate detection. Sometimes a user's action may be required to open and Deobfuscate/Decode Files or Information for User Execution. The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary. Adversaries may also use compressed or archived scripts, such as JavaScript.

Portions of files can also be encoded to hide the plain-text strings that would otherwise help defenders with discovery. Payloads may also be split into separate, seemingly benign files that only reveal malicious functionality when reassembled.

Adversaries may also abuse Command Obfuscation to obscure commands executed from payloads or directly via Command and Scripting Interpreter. Environment variables, aliases, characters, and other platform/language specific semantics can be used to evade signature based detections and application control mechanisms.

Detection rules136

Rules on DetectionCode tagged with T1027 or one of its sub-techniques.

Sigma115

RuleLevelLog sourceTechnique
Base64 Encoded PowerShell Command Detectedhighwindows / process_creationT1027
Binary Padding - Linuxhighlinux / NULLT1027.001
Binary Padding - MacOShighmacos / process_creationT1027.001
Csc.EXE Execution Form Potentially Suspicious Parenthighwindows / process_creationT1027.004
File Decoded From Base64/Hex Via Certutil.EXEhighwindows / process_creationT1027
File In Suspicious Location Encoded To Base64 Via Certutil.EXEhighwindows / process_creationT1027
HackTool - CrackMapExec PowerShell Obfuscationhighwindows / process_creationT1027.005
Invoke-Obfuscation CLIP+ Launcherhighwindows / process_creationT1027
Invoke-Obfuscation CLIP+ Launcher - PowerShellhighwindows / ps_scriptT1027
Invoke-Obfuscation CLIP+ Launcher - PowerShell Modulehighwindows / ps_moduleT1027
Invoke-Obfuscation CLIP+ Launcher - Securityhighwindows / NULLT1027
Invoke-Obfuscation CLIP+ Launcher - Systemhighwindows / NULLT1027
Invoke-Obfuscation Obfuscated IEX Invocationhighwindows / process_creationT1027
Invoke-Obfuscation Obfuscated IEX Invocation - PowerShellhighwindows / ps_scriptT1027
Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell Modulehighwindows / ps_moduleT1027

Splunk21

RuleTypeRiskData sourceTechnique
Cisco Secure Firewall - Lumma Stealer ActivityTTPNULLCisco Secure Firewall Threat Defense Intrusion EventT1027
Cisco Secure Firewall - Repeated Malware DownloadsAnomalyNULLCisco Secure Firewall Threat Defense File EventT1027
Cisco Secure Firewall - Snort Rule Triggered Across Multiple HostsAnomalyNULLCisco Secure Firewall Threat Defense Intrusion EventT1027
CSC Net On The Fly CompilationHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1027.004
Curl Execution with Percent Encoded URLAnomalyNULLCrowdStrike ProcessRollup2, Sysmon EventID 1, Sysmon for Linux EventID 1, Windows Event Log Security 4688T1027
Linux Decode Base64 to ShellTTPNULLSysmon for Linux EventID 1, Cisco Isovalent Process ExecT1027
Linux Obfuscated Files or Information Base64 DecodeAnomalyNULLSysmon for Linux EventID 1T1027
Linux Suspicious GCC Invocation Building Init Shared ObjectTTPNULLSysmon for Linux EventID 1T1027.004
Malicious PowerShell Process - Encoded CommandHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1027
Powershell Creating Thread MutexTTPNULLPowershell Script Block Logging 4104T1027.005
Powershell Enable SMB1Protocol FeatureTTPNULLPowershell Script Block Logging 4104T1027.005
Powershell Fileless Script Contains Base64 Encoded ContentTTPNULLPowershell Script Block Logging 4104T1027
PowerShell WebRequest Using Memory StreamTTPNULLPowershell Script Block Logging 4104T1027.011
Wermgr Process Create Executable FileTTPNULLSysmon EventID 11T1027
Windows Command Obfuscation with Environment Variable SubstringsAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1027.010

Sub-techniques18

IDNameExamples
T1027.001Binary Padding30
T1027.002Software Packing103
T1027.003Steganography31
T1027.004Compile After Delivery10
T1027.005Indicator Removal from Tools18
T1027.006HTML Smuggling3
T1027.007Dynamic API Resolution20
T1027.008Stripped Payloads2
T1027.009Embedded Payloads24
T1027.010Command Obfuscation70
T1027.011Fileless Storage31
T1027.012LNK Icon Smuggling4
T1027.013Encrypted/Encoded File248
T1027.014Polymorphic Code1
T1027.015Compression35
T1027.016Junk Code Insertion24
T1027.017SVG Smuggling0
T1027.018Invisible Unicode1

Groups18

Software138

Show 114 more

Campaigns4

Procedure examples160

Groups18

Used byProcedure example
GroupAPT-C-36

APT-C-36 has used ConfuserEx to obfuscate its variant of Imminent Monitor, compressed payloads and RAT packages, and password protected encrypted email attachments to avoid detection. APT-C-36 has also compressed initial droppers into ZIP, LHA and UUE formats.

GroupAPT3

APT3 obfuscates files or information to help evade defensive measures.

GroupAPT37

APT37 obfuscates strings and payloads.

GroupAPT41

APT41 used VMProtected binaries in multiple intrusions.

GroupBackdoorDiplomacy

BackdoorDiplomacy has obfuscated tools and malware it uses with VMProtect.

GroupBlackOasis

BlackOasis's first stage shellcode contains a NOP sled with alternative instructions that was likely designed to bypass antivirus tools.

GroupEarth Lusca

Earth Lusca used Base64 to encode strings.

GroupGALLIUM

GALLIUM used a modified version of HTRAN in which they obfuscated strings such as debug messages in an apparent attempt to evade detection.

View all 18 groups examples

Software138

Used byProcedure example
MalwareAction RAT

Action RAT's commands, strings, and domains can be Base64 encoded within the payload.

MalwareADVSTORESHELL

Most of the strings in ADVSTORESHELL are encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed. API function names are also reversed, presumably to avoid detection in memory.

MalwareAgent Tesla

Agent Tesla has had its code obfuscated in an apparent attempt to make analysis difficult. Agent Tesla has used the Rijndael symmetric encryption algorithm to encrypt strings.

MalwareAmadey

Amadey has obfuscated strings such as antivirus vendor names, domains, files, and others.

MalwareAnchor

Anchor has obfuscated code with stack strings and string encryption.

MalwareANELLDR

ANELLDR code implements anti-analysis techniques including control flow flattening and Mixed Boolean Arithmetic (MBA).

MalwareAppleJeus

AppleJeus has XOR-encrypted collected system information prior to sending to a C2. AppleJeus has also used the open source ADVObfuscation library for its components.

MalwareAppleSeed

AppleSeed has the ability to Base64 encode its payload and custom encrypt API calls.

View all 138 software examples

Campaigns4

Used byProcedure example
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used heavily obfuscated code with Industroyer in its Windows Notepad backdoor.

Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus payloads use AES-256 GCM cipher to encrypt data to include ICONICSTEALER and VEILEDSIGNAL.

CampaignC0015

During C0015, the threat actors used Base64-encoded strings.

CampaignC0017

During C0017, APT41 broke malicious binaries, including DEADEYE and KEYPLUG, into multiple sections on disk to evade detection.

References6

  1. Carbon Black Obfuscation Sept 2016 Open source
    Tedesco, B. (2016, September 23). Security Alert Summary. Retrieved February 12, 2018.
  2. FireEye Obfuscation June 2017 Open source
    Bohannon, D. & Carr N. (2017, June 30). Obfuscation in the Wild: Targeted Attackers Lead the Way in Evasion Techniques. Retrieved February 12, 2018.
  3. FireEye Revoke-Obfuscation July 2017 Open source
    Bohannon, D. & Holmes, L. (2017, July 27). Revoke-Obfuscation: PowerShell Obfuscation Detection Using Science. Retrieved November 17, 2024.
  4. Linux/Cdorked.A We Live Security Analysis Open source
    Pierre-Marc Bureau. (2013, April 26). Linux/Cdorked.A: New Apache backdoor being used in the wild to serve Blackhole. Retrieved September 10, 2017.
  5. PaloAlto EncodedCommand March 2017 Open source
    White, J. (2017, March 10). Pulling Back the Curtains on EncodedCommand PowerShell Attacks. Retrieved February 12, 2018.
  6. Volexity PowerDuke November 2016 Open source
    Adair, S.. (2016, November 9). PowerDuke: Widespread Post-Election Spear Phishing Campaigns Targeting Think Tanks and NGOs. Retrieved January 11, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.