Deobfuscate/Decode Files or Information

T1140

Technique.View on attack.mitre.org

About this technique

Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.

One such example is the use of certutil to decode a remote access tool portable executable file that has been hidden inside a certificate file. Another example is using the Windows copy /b or type command to reassemble binary fragments into a malicious payload.

Sometimes a user's action may be required to open it for deobfuscation or decryption as part of User Execution. The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary.

Detection rules16

Rules on DetectionCode tagged with T1140.

Sigma14

RuleLevelLog source
Base64 Encoded PowerShell Command Detectedhighwindows / process_creation
MSHTA Execution with Suspicious File Extensionshighwindows / process_creation
Ping Hex IPhighwindows / process_creation
Potential Base64 Decoded From Imageshighmacos / process_creation
PowerShell Base64 Encoded FromBase64String Cmdlethighwindows / process_creation
Suspicious Inbox Manipulation Ruleshighazure / NULL
DNS-over-HTTPS Enabled by Registrymediumwindows / registry_set
Linux Base64 Encoded Pipe to Shellmediumlinux / process_creation
Linux Base64 Encoded Shebang In CLImediumlinux / process_creation
Linux Shell Pipe to Shellmediumlinux / process_creation
Payload Decoded and Decrypted via Built-in Utilitiesmediummacos / process_creation
Potential Commandline Obfuscation Using Escape Charactersmediumwindows / process_creation
Suspicious XOR Encoded PowerShell Commandmediumwindows / process_creation
PowerShell Decompress Commandsinformationalwindows / ps_module

Splunk2

RuleTypeRiskData source
CertUtil With Decode ArgumentTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Linux Auditd Base64 Decode FilesAnomalyNULLLinux Auditd Execve

Groups38

Show 14 more

Software301

Show 277 more
BBSRATBendyBearBisonalBlackByte RansomwareBLINDINGCANBOOKWORMBoomBoxBOOSTWRITEBRICKSTORMBRUSHFIREBrute Ratel C4BumblebeeBundloreBUSHWALKCaminhoCanisterWormCarbonCardinal RATCASTLETAPcertutilChaesCharmPowerCHIMNEYSWEEPChinoxyChrommmeCLAIMLOADERClamblingClopCOATHANGERCobalt StrikeCoinTickerComRATContiCookieMinerCorKLOGCostaBricksCrimsonCuckoo StealerCyclops BlinkDanBotDarkGateDarkTortillaDarkWatchmanDDKONGDEADEYEDEADWOODDenisDOWNIISSADropBookDrovorubDtrackDUSTPANDUSTTRAPDyreEburyEcipekacEgregorEmbargoEmotetEnvyScoutExaramel for LinuxExbyteExpandFatDukeFinal1stspyFinFisherFIVEHANDSFoggyWebFooderFRAMESTINGFYAntiGelsemiumgh0st RATGLASSTOKENGlassWormGoldMaxGoopyGootloaderGrandoreiroGreen LambertGrimAgentHancitorHeartCryptHermeticWiperHexEval LoaderHeyoka BackdoorHiddenFaceHiddenWaspHildegardHTTPTroyHUI LoaderHyperBroIceAppleImminent MonitorINC RansomwareIndustroyerInvisibleFerretInvisiMoleIronNetInjectorIronWindISMInjectorKapekaKerrdownKesselKEYPLUGKGH_SPYKobalosKOCTOPUSKONNIKwampirsLAMEHUGLatrodectusLightNeuronLIGHTWIRELine DancerLiteDukeLizarLockBit 2.0LockBit 3.0LokibotLookBackLP-NotesLuciferLumma StealerLunarLoaderLunarMailLunarWebMacheteMacMaMafaldaMagicRATMedusa RansomwareMegaCortexMESSAGETAPmetaMainMetamorfoMini Shai-HuludMirageFoxMispaduMongallMOPSLEDMore_eggsMoriMuddyViperNativeZoneNetwalkerNightdoorNinjaNOKKINOOPLDRODAgentOilBoosterOkrumOnionDukeOopsIEOSX_OCEANLOTUS.DOSX/ShlayerP.A.S. WebshellPcSharePHASEJAMPHPsertPikabotPillowmintPingPullPipeMonPITSTOPPlugXPoetRATPolyglotDukePowerExchangePowerLessPOWERSTATSPowGoopProtonPS1PteranodonPUBLOADPUNCHBUGGYPureCrypterPyDCryptQakBotQUADAGENTQUIETCANARYRaccoon StealerRaindropRainyDayRamsayRansomHubRAPIDPULSERaspberry RobinRDATRedLine StealerRegDukeRemexiREPTILEREvilRGDoorRIFLESPINERising SunROADSWEEPROAMINGHOUSERogueRobinROKRATRotaJakiroRustyWaterSagerunexSaint BotSampleCheck5000SardonicSDBbotShadowPadShamoonSharkSharpStageShimRatSibotSideTwistSiloscapeSkidmapSLIGHTPULSESmoke LoaderSnip3SombRATSoreFangSparkSPAWNCHIMERASpicaSplatDropperSQLRatSquirrelwaffleStarloaderStarProxySTEADYPULSEStealBitStrelaStealerStuxnetSUNSPOTSystemBCSysUpdateTaidoorTeamPCP Cloud StealerTEARDROPTHINCRUSTThreatNeedleTONESHELLTorismaTrickBotTSCookieTsundere BotnetTurianTYPEFRAMEUPSTYLEUroburosUrsnifValakVaporRageVERMINVolgmerWarzoneRATWastedLockerWaterbearWellMailWellMessWhisperGateWindTailWinnti for LinuxWinnti for WindowsWIREFIREWoody RATxCaonXLoaderXORIndex LoaderYAHOYAHZebrocyZeroTZeus PandaZxxZ

Campaigns14

Procedure examples353

Groups38

Used byProcedure example
GroupAgrius

Agrius has deployed base64-encoded variants of ASPXSpy to evade detection.

GroupAPT19

An APT19 HTTP malware variant decrypts strings using single-byte XOR keys.

GroupAPT28

An APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload.

GroupAPT38

APT38 has used the RC4 algorithm to decrypt configuration data.

GroupAPT39

APT39 has used malware to decrypt encrypted CAB files.

GroupBlackByte

BlackByte has encoded commands in base64-encoded sections concatenated together in PowerShell. BlackByte uses PowerShell commands to disable Windows Defender.

GroupBRONZE BUTLER

BRONZE BUTLER downloads encoded payloads and decodes them on the victim.

GroupCinnamon Tempest

Cinnamon Tempest has used weaponized DLLs to load and decrypt payloads.

View all 38 groups examples

Software301

Used byProcedure example
MalwareABK

ABK has the ability to decrypt AES encrypted payloads.

MalwareAction RAT

Action RAT can use Base64 to decode actor-controlled C2 server communications.

MalwareAgent Tesla

Agent Tesla has the ability to decrypt strings encrypted with the Rijndael symmetric encryption algorithm.

MalwareAmadey

Amadey has decoded antivirus name strings.

MalwareANELLDR

ANELLDR can decrypt encrypted payload data using AES-256-CBC and subsequently execute the payload in memory.

MalwareApostle

Apostle compiled code is obfuscated in an unspecified fashion prior to delivery to victims.

MalwareAppleJeus

AppleJeus has decoded files received from a C2.

MalwareAppleSeed

AppleSeed can decode its payload prior to execution.

View all 301 software examples

Campaigns14

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries decoded a Base64-encoded ZIP archive using the built-in certutil.

CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 unarchived data using the GUI version of WinRAR.

CampaignArcaneDoor

ArcaneDoor involved the use of Base64 obfuscated scripts and commands.

CampaignC0017

During C0017, APT41 used the DUSTPAN loader to decrypt embedded payloads.

CampaignC0021

During C0021, the threat actors deobfuscated encoded PowerShell commands including use of the specific string `'FromBase'+0x40+'String'`, in place of `FromBase64String` which is normally used to decode base64.

CampaignFrankenstein

During Frankenstein, the threat actors deobfuscated Base64-encoded commands following the execution of a malicious script, which revealed a small script designed to obtain an additional payload.

CampaignJuicy Mix

During Juicy Mix, OilRig used a script to concatenate and deobfuscate encoded strings in Mango.

CampaignOperation Dust Storm

During Operation Dust Storm, attackers used VBS code to decode payloads.

View all 14 campaigns examples

References4

  1. Carbon Black Obfuscation Sept 2016 Open source
    Tedesco, B. (2016, September 23). Security Alert Summary. Retrieved February 12, 2018.
  2. Malwarebytes Targeted Attack against Saudi Arabia Open source
    Malwarebytes Labs. (2017, March 27). New targeted attack against Saudi Arabia Government. Retrieved July 3, 2017.
  3. Sentinel One Tainted Love 2023 Open source
    Aleksandar Milenkoski, Juan Andres Guerrero-Saade, and Joey Chen. (2023, March 23). Operation Tainted Love | Chinese APTs Target Telcos in New Attacks. Retrieved March 18, 2025.
  4. Volexity PowerDuke November 2016 Open source
    Adair, S.. (2016, November 9). PowerDuke: Widespread Post-Election Spear Phishing Campaigns Targeting Think Tanks and NGOs. Retrieved January 11, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.