Decompress Data

September 27, 2024 ยท View on GitHub

ID C0025
Objective(s) Data
Related ATT&CK Techniques None
Version 2.1
Created 13 October 2020
Last Modified 5 December 2023

Decompress Data

Malware may decompress data.

Methods

NameIDDescription
aPLibC0025.003Malware decompresses data using aPLib.
IEncodingFilterFactoryC0025.002Malware decompresses data using IEncodingFilterFactory.
QuickLZC0025.001Malware decompresses data using QuickLZ.

Use in Malware

NameDateMethodDescription
Bagle2004C0025.003Bagle decompresses data using aPLib. [1]

Detection

Tool: capaMappingAPIs
decompress data using aPLibDecompress Data::aPLib (C0025.003)--
decompress data via IEncodingFilterFactoryDecompress Data::IEncodingFilterFactory (C0025.002)ole32.CoCreateInstance
decompress data using LZODecompress Data (C0025)--
decompress data using QuickLZDecompress Data::QuickLZ (C0025.001)--
decompress data using UCLDecompress Data (C0025)--
Tool: CAPEClassMappingAPIs
compressionCAPE_CompressionDecompress Data (C0025)RtlDecompressBuffer

References

[1] capa v4.0, analyzed at MITRE on 10/12/2022