T1140 Deobfuscate/Decode Files or Information — ATT&CK Technique
Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system. One such example is the use of certutil to decode a remote access tool portable executable file that has been hidden inside a certificate file. Another example is using the Windows copy /b or type command to reassemble binary fragments into a malicious payload. Sometimes a user's action may be required to open it for deobfuscation or decryption as part of User Execution. The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary.
Detection coverage (20)
- Potential BlackByte Ransomware Activity high
- UNC4841 - SSL Certificate Exfiltration Via Openssl high
- UNC4841 - Download Compressed Files From Temp.sh Using Wget high
- UNC4841 - Download Tar File From Untrusted Direct IP Via Wget high
- Payload Decoded and Decrypted via Built-in Utilities medium
- Suspicious Inbox Manipulation Rules high
- Suspicious XOR Encoded PowerShell Command medium
- Linux Base64 Encoded Pipe to Shell medium
- Linux Base64 Encoded Shebang In CLI medium
- Linux Shell Pipe to Shell medium
- Potential Base64 Decoded From Images high
- PowerShell Decompress Commands informational
- MSHTA Execution with Suspicious File Extensions high
- Ping Hex IP high
- PowerShell Base64 Encoded FromBase64String Cmdlet high
- Base64 Encoded PowerShell Command Detected high
- Potential Commandline Obfuscation Using Escape Characters medium
- DNS-over-HTTPS Enabled by Registry medium
- CertUtil With Decode Argument
- Linux Auditd Base64 Decode Files
Malware using this technique
- PHPsert
- SPAWNCHIMERA
- ZeroT
- AppleJeus
- Action RAT
- KOCTOPUS
- Snip3
- BendyBear
- LiteDuke
- P.A.S. Webshell
- KONNI
- Machete
- BOOSTWRITE
- LockBit 3.0
- RotaJakiro
- More_eggs
- DarkTortilla
- Gelsemium
- ROAMINGHOUSE
- Smoke Loader
- Mispadu
- Clop
- SDBbot
- Babuk
- BBSRAT
- SysUpdate
- Lokibot
- POWERSTATS
- QUADAGENT
- VaporRage
- UPSTYLE
- Lucifer
- Caminho
- Avaddon
- Line Dancer
- SombRAT
- XORIndex Loader
- Mongall
- WIREFIRE
- FoggyWeb
- Imminent Monitor
- PHASEJAM
- RAPIDPULSE
- Aria-body
- ShadowPad
- QUIETCANARY
- Starloader
- TSCookie
- Conti
- Kwampirs
Threat actors using this technique
- BRONZE BUTLER
- Turla
- APT39
- WIRTE
- Gorgon Group
- Kimsuky
- Moonstone Sleet
- Mustang Panda
- Agrius
- APT15
- APT38
- Volt Typhoon
- Molerats
- Darkhotel
- Earth Lusca
- Storm-1811
- ZIRCONIUM
- MuddyWater
- OilRig
- Gamaredon Group
- TA505
- APT27
- APT28
- FIN7
- TeamTNT
- Winter Vivern
- APT10
- Lazarus Group
- BlackByte
- APT40
- Cinnamon Tempest
- Rocke
- Tropic Trooper
- FIN13
- Sandworm Team
- Malteiro
- APT19
- Higaisa