T1027 Obfuscated Files or Information — ATT&CK Technique
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses. Payloads may be compressed, archived, or encrypted in order to avoid detection. These payloads may be used during Initial Access or later to mitigate detection. Sometimes a user's action may be required to open and Deobfuscate/Decode Files or Information for User Execution. The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary. Adversaries may also use compressed or archived scripts, such as JavaScript. Portions of files can also be encoded to hide the plain-text strings that would otherwise help defenders with discovery. Payloads may also be split into separate, seemingly benign files that only reveal malicious functionality when reassembled. Adversaries may also abuse Command Obfuscation to obscure commands executed from payloads or directly via Command and Scripting Interpreter. Environment variables, aliases, characters, and other platform/language specific semantics can be used to evade signature based detections and application control mechanisms.
Detection coverage (50)
- Turla Group Commands May 2020 critical
- Potential Emotet Activity high
- Operation Wocao Activity high
- Operation Wocao Activity - Security high
- Potentially Suspicious Long Filename Pattern - Linux low
- Potential Suspicious Execution From GUID Like Folder Names low
- Potential CommandLine Obfuscation Using Unicode Characters medium
- Suspicious XOR Encoded PowerShell Command medium
- Suspicious Filename with Embedded Base64 Commands high
- Decode Base64 Encoded Text low
- Decode Base64 Encoded Text -MacOs low
- PUA - Potential PE Metadata Tamper Using Rcedit medium
- Invoke-Obfuscation STDIN+ Launcher - Security high
- Invoke-Obfuscation Via Use Clip - Security high
- Invoke-Obfuscation VAR+ Launcher - Security high
- Invoke-Obfuscation Via Use MSHTA - Security high
- Invoke-Obfuscation Obfuscated IEX Invocation - Security high
- Invoke-Obfuscation Via Stdin - Security high
- Invoke-Obfuscation CLIP+ Launcher - Security high
- Invoke-Obfuscation RUNDLL LAUNCHER - Security medium
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - Security high
- Invoke-Obfuscation COMPRESS OBFUSCATION - Security medium
- Invoke-Obfuscation Via Use Rundll32 - Security high
- Password Protected ZIP File Opened medium
- Password Protected ZIP File Opened (Email Attachment) high
- Password Protected ZIP File Opened (Suspicious Filenames) high
- Invoke-Obfuscation VAR+ Launcher - System high
- Invoke-Obfuscation Via Use MSHTA - System high
- Invoke-Obfuscation STDIN+ Launcher - System high
- Invoke-Obfuscation Via Use Clip - System high
- Invoke-Obfuscation Obfuscated IEX Invocation - System high
- Invoke-Obfuscation Via Stdin - System high
- Invoke-Obfuscation COMPRESS OBFUSCATION - System medium
- Invoke-Obfuscation Via Use Rundll32 - System high
- Invoke-Obfuscation CLIP+ Launcher - System high
- Invoke-Obfuscation RUNDLL LAUNCHER - System medium
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - System high
- Potential Winnti Dropper Activity high
- Suspicious Get-Variable.exe Creation high
- Invoke-Obfuscation STDIN+ Launcher - PowerShell Module high
- Invoke-Obfuscation Via Use Clip - PowerShell Module high
- Invoke-Obfuscation CLIP+ Launcher - PowerShell Module high
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell Module medium
- Invoke-Obfuscation Via Use Rundll32 - PowerShell Module high
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell Module high
- Invoke-Obfuscation Via Stdin - PowerShell Module high
- Invoke-Obfuscation VAR+ Launcher - PowerShell Module high
- Invoke-Obfuscation Via Use MSHTA - PowerShell Module high
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell Module medium
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell Module high
Malware using this technique
- Shai-Hulud
- Sliver
- Ryuk
- DarkTortilla
- POSHSPY
- SUNBURST
- Remcos
- Lokibot
- SVCReady
- PowerStallion
- BRICKSTORM
- SynAck
- FatDuke
- Amadey
- PolyglotDuke
- CHIMNEYSWEEP
- Fooder
- PUNCHTRACK
- ECCENTRICBANDWAGON
- Drovorub
- Valak
- StrelaStealer
- PoisonIvy
- Out1
- HTTPBrowser
- Trojan.Karagany
- Saint Bot
- NanoCore
- SHOTPUT
- SodaMaster
- CoinTicker
- Conti
- Turian
- Snip3
- ComRAT
- Final1stspy
- DustySky
- SUNSPOT
- Pillowmint
- Lizar
- H1N1
- Kazuar
- NETWIRE
- SombRAT
- Agent Tesla
- TrickBot
- InnaputRAT
- MiniDuke
- TEARDROP
- Matryoshka