1200KM / simulation
T1140 Deobfuscate/Decode Files or Information — Attack Simulation
Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system. One such example is the use of certutil to decode a remote access tool portable executable file that has been hidden…
Technique description
Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system. One such example is the use of certutil to decode a remote access tool portable executable file that has been hidden…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Hex decoding with shell utilities
Procedure 005943f9-8dd5-4349-8b46-0313c0a9f973; elevation not declared required; cleanup not declared. Not executed or individually validated.
- FreeBSD b64encode Shebang in CLI
Procedure 18ee2002-66e8-4518-87c5-c0ec9c8299ac; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Base64 decoding with Python
Procedure 356dc0e8-684f-4428-bb94-9313998ad608; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Linux Base64 Encoded Shebang in CLI
Procedure 3a15c372-67c1-4430-ac8e-ec06d641ce4d; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Base64 decoding with Perl
Procedure 6604d964-b9f6-4d4b-8ce8-499829a14d0a; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Certutil Rename and Decode
Procedure 71abc534-3c05-4d0c-80f7-cbe93cb2aa94; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Expand CAB with expand.exe
Procedure 9f8b1c54-cb76-4d5e-bb1f-2f5c0e8f5a11; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Base64 decoding with shell utilities
Procedure b4f6a567-a27a-41e5-b8ef-ac4b4008bb7e; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Base64 decoding with shell utilities (freebsd)
Procedure b6097712-c42e-4174-b8f2-4b1e1a5bbb3d; elevation not declared required; cleanup not declared. Not executed or individually validated.
- XOR decoding and command execution using Python
Procedure c3b65cd5-ee51-4e98-b6a3-6cbdec138efc; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Deobfuscate/Decode Files Or Information
Procedure dc6fe391-69e6-4506-bd06-ea5eeb4082f8; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT28 · G0007
- Turla · G0010
- Darkhotel · G0012
- Molerats · G0021
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Sandworm Team · G0034
- menuPass · G0045
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- BRONZE BUTLER · G0060
- Leviathan · G0065
- MuddyWater · G0069
- APT19 · G0073
- Gorgon Group · G0078
- Tropic Trooper · G0081
- APT38 · G0082
- APT39 · G0087
- WIRTE · G0090
- TA505 · G0092
- Kimsuky · G0094
- Rocke · G0106
- Higaisa · G0126
- ZIRCONIUM · G0128
- Mustang Panda · G0129
- TeamTNT · G0139
- Earth Lusca · G1006
- FIN13 · G1016
- Volt Typhoon · G1017
- Cinnamon Tempest · G1021
- Malteiro · G1026
- Agrius · G1030
- Winter Vivern · G1035
- Moonstone Sleet · G1036
- BlackByte · G1043
- Storm-1811 · G1046
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.