T1140 Deobfuscate/Decode Files or Information — ATT&CK Technique
Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system. One such example is the use of certutil to decode a remote access tool portable executable file that has been hidden inside a certificate file. Another example is using the Windows copy /b or type command to reassemble binary fragments into a malicious payload. Sometimes a user's action may be required to open it for deobfuscation or decryption as part of User Execution. The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary.
Detection coverage (20)
- UNC4841 - SSL Certificate Exfiltration Via Openssl high
- UNC4841 - Download Compressed Files From Temp.sh Using Wget high
- UNC4841 - Download Tar File From Untrusted Direct IP Via Wget high
- Payload Decoded and Decrypted via Built-in Utilities medium
- Suspicious Inbox Manipulation Rules high
- Suspicious XOR Encoded PowerShell Command medium
- Linux Base64 Encoded Pipe to Shell medium
- Linux Base64 Encoded Shebang In CLI medium
- Linux Shell Pipe to Shell medium
- Potential Base64 Decoded From Images high
- PowerShell Decompress Commands informational
- MSHTA Execution with Suspicious File Extensions high
- Ping Hex IP high
- PowerShell Base64 Encoded FromBase64String Cmdlet high
- Base64 Encoded PowerShell Command Detected high
- Potential Commandline Obfuscation Using Escape Characters medium
- DNS-over-HTTPS Enabled by Registry medium
- CertUtil With Decode Argument
- Linux Auditd Base64 Decode Files
- Potential BlackByte Ransomware Activity high
Malware using this technique
- TrickBot
- BLINDINGCAN
- Ninja
- Pikabot
- Spark
- Bumblebee
- BRICKSTORM
- Amadey
- Torisma
- NOKKI
- Stuxnet
- IronWind
- RotaJakiro
- Bandook
- PipeMon
- MagicRAT
- KONNI
- AvosLocker
- Chinoxy
- SharpStage
- COATHANGER
- Sardonic
- Smoke Loader
- WindTail
- Exaramel for Linux
- PS1
- HeartCrypt
- Ursnif
- CASTLETAP
- ThreatNeedle
- RansomHub
- Tsundere Botnet
- Zeus Panda
- ShimRat
- Chrommme
- InvisibleFerret
- Bankshot
- xCaon
- AuditCred
- ROAMINGHOUSE
- TONESHELL
- UPSTYLE
- Medusa Ransomware
- RainyDay
- Ecipekac
- AppleSeed
- BUSHWALK
- SQLRat
- MegaCortex
- PyDCrypt
Threat actors using this technique
- Money Message
- InvisiMole
- RansomExx
- APT38
- WIRTE
- BlackByte
- Kimsuky
- Volt Typhoon
- Gorgon Group
- APT10
- MuddyWater
- Gamaredon Group
- Storm-1811
- TeamTNT
- FIN7
- Sandworm Team
- Mustang Panda
- ZIRCONIUM
- Rocke
- APT39
- OilRig
- Higaisa
- Tropic Trooper
- APT15
- APT40
- Winter Vivern
- Turla
- APT27
- TA505
- Cinnamon Tempest
- BRONZE BUTLER
- Darkhotel
- Agrius
- APT28
- Malteiro
- Lazarus Group
- Earth Lusca
- Molerats
- Moonstone Sleet
- FIN13
- APT19