Encode Data

May 1, 2024 ยท View on GitHub

ID C0026
Objective(s) Data
Related ATT&CK Techniques None
Version 2.0
Created 13 October 2020
Last Modified 5 December 2023

Encode Data

Malware may encode data.

Methods

NameIDDescription
Base64C0026.001Malware may encode data using Base64.
XORC0026.002Malware may use XOR to encode data.

Use in Malware

NameDateMethodDescription
CryptoLocker2013C0026.002CryptoLocker encodes data using XOR. [1]
Dark Comet2008C0026.002Dark Comet encodes data using XOR. [1]
DNSChanger2011C0026.002DNSChanger encodes data using XOR. [1]
Gamut2014C0026.002Gamut encodes data using XOR. [1]
Hupigon2013C0026.002Hupigon encodes data using XOR. [1]
Kraken2008C0026.002Kraken encodes data using XOR. [1]
Locky Bart2017C0026.002Locky Bart encodes data using XOR. [1]
Mebromi2011C0026.002Mebromi encodes data using XOR. [1]
Redhip2011C0026.002Redhip encodes data using XOR. [1]
Rombertik2015C0026.002Rombertik encodes data using XOR. [1]
Shamoon2012C0026.002Shamoon encodes data using XOR. [1]
Stuxnet2010C0026.002Stuxnet encodes data using XOR. [1]
TrickBot2016C0026.002TrickBot encodes data using XOR. [1]
UP0072016C0026.002The malware encodes data using XOR. [1]

Detection

Tool: capaMappingAPIs
encode data using XOREncode Data::XOR (C0026.002)--
encode data using Base64Encode Data::Base64 (C0026.001)System.Convert::ToBase64String, System.Convert::ToBase64CharArray, System.Convert::TryToBase64Chars
decode data using Base64 via dword translation tableEncode Data::Base64 (C0026.001)--
reference Base64 stringEncode Data::Base64 (C0026.001)--

References

[1] capa v4.0, analyzed at MITRE on 10/12/2022