Technique.View on attack.mitre.org
Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.
One such example is the use of certutil to decode a remote access tool portable executable file that has been hidden inside a certificate file. Another example is using the Windows copy /b or type command to reassemble binary fragments into a malicious payload.
Sometimes a user's action may be required to open it for deobfuscation or decryption as part of User Execution. The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary.
Rules on DetectionCode tagged with T1140.
| Rule | Level | Log source |
|---|---|---|
| Base64 Encoded PowerShell Command Detected | high | windows / process_creation |
| MSHTA Execution with Suspicious File Extensions | high | windows / process_creation |
| Ping Hex IP | high | windows / process_creation |
| Potential Base64 Decoded From Images | high | macos / process_creation |
| PowerShell Base64 Encoded FromBase64String Cmdlet | high | windows / process_creation |
| Suspicious Inbox Manipulation Rules | high | azure / NULL |
| DNS-over-HTTPS Enabled by Registry | medium | windows / registry_set |
| Linux Base64 Encoded Pipe to Shell | medium | linux / process_creation |
| Linux Base64 Encoded Shebang In CLI | medium | linux / process_creation |
| Linux Shell Pipe to Shell | medium | linux / process_creation |
| Payload Decoded and Decrypted via Built-in Utilities | medium | macos / process_creation |
| Potential Commandline Obfuscation Using Escape Characters | medium | windows / process_creation |
| Suspicious XOR Encoded PowerShell Command | medium | windows / process_creation |
| PowerShell Decompress Commands | informational | windows / ps_module |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| CertUtil With Decode Argument | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Linux Auditd Base64 Decode Files | Anomaly | NULL | Linux Auditd Execve |
| Used by | Procedure example |
|---|---|
| GroupAgrius | Agrius has deployed base64-encoded variants of ASPXSpy to evade detection. |
| GroupAPT19 | An APT19 HTTP malware variant decrypts strings using single-byte XOR keys. |
| GroupAPT28 | An APT28 macro uses the command |
| GroupAPT38 | APT38 has used the RC4 algorithm to decrypt configuration data. |
| GroupAPT39 | APT39 has used malware to decrypt encrypted CAB files. |
| GroupBlackByte | BlackByte has encoded commands in base64-encoded sections concatenated together in PowerShell. BlackByte uses PowerShell commands to disable Windows Defender. |
| GroupBRONZE BUTLER | BRONZE BUTLER downloads encoded payloads and decodes them on the victim. |
| GroupCinnamon Tempest | Cinnamon Tempest has used weaponized DLLs to load and decrypt payloads. |
| Used by | Procedure example |
|---|---|
| MalwareABK | ABK has the ability to decrypt AES encrypted payloads. |
| MalwareAction RAT | Action RAT can use Base64 to decode actor-controlled C2 server communications. |
| MalwareAgent Tesla | Agent Tesla has the ability to decrypt strings encrypted with the Rijndael symmetric encryption algorithm. |
| MalwareAmadey | Amadey has decoded antivirus name strings. |
| MalwareANELLDR | ANELLDR can decrypt encrypted payload data using AES-256-CBC and subsequently execute the payload in memory. |
| MalwareApostle | Apostle compiled code is obfuscated in an unspecified fashion prior to delivery to victims. |
| MalwareAppleJeus | AppleJeus has decoded files received from a C2. |
| MalwareAppleSeed | AppleSeed can decode its payload prior to execution. |
View all 301 software examples
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries decoded a Base64-encoded ZIP archive using the built-in certutil. |
| CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 unarchived data using the GUI version of WinRAR. |
| CampaignArcaneDoor | ArcaneDoor involved the use of Base64 obfuscated scripts and commands. |
| CampaignC0017 | During C0017, APT41 used the DUSTPAN loader to decrypt embedded payloads. |
| CampaignC0021 | During C0021, the threat actors deobfuscated encoded PowerShell commands including use of the specific string `'FromBase'+0x40+'String'`, in place of `FromBase64String` which is normally used to decode base64. |
| CampaignFrankenstein | During Frankenstein, the threat actors deobfuscated Base64-encoded commands following the execution of a malicious script, which revealed a small script designed to obtain an additional payload. |
| CampaignJuicy Mix | During Juicy Mix, OilRig used a script to concatenate and deobfuscate encoded strings in Mango. |
| CampaignOperation Dust Storm | During Operation Dust Storm, attackers used VBS code to decode payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.