Command Obfuscation

T1027.010

Sub-technique of T1027 Obfuscated Files or Information.View on attack.mitre.org

About this technique

Adversaries may obfuscate content during command execution to impede detection. Command-line obfuscation is a method of making strings and patterns within commands and scripts more difficult to signature and analyze. This type of obfuscation can be included within commands executed by delivered payloads (e.g., Phishing and Drive-by Compromise) or interactively via Command and Scripting Interpreter.

For example, adversaries may abuse syntax that utilizes various symbols and escape characters (such as spacing, `^`, `+`. `$`, and `%`) to make commands difficult to analyze while maintaining the same intended functionality. Many languages support built-in obfuscation in the form of base64 or URL encoding. Adversaries may also manually implement command obfuscation via string splitting (`“Wor”+“d.Application”`), order and casing of characters (`rev <<<'dwssap/cte/ tac'`), globing (`mkdir -p '/tmp/:&$NiA'`), as well as various tricks involving passing strings through tokens/environment variables/input streams.

Adversaries may also use tricks such as directory traversals to obfuscate references to the binary being invoked by a command (`C:\voi\pcw\..\..\Windows\tei\qs\k\..\..\..\system32\erool\..\wbem\wg\je\..\..\wmic.exe shadowcopy delete`).

Tools such as Invoke-Obfuscation and Invoke-DOSfucation have also been used to obfuscate commands.

Detection rules10

Rules on DetectionCode tagged with T1027.010.

Sigma8

Splunk2

RuleTypeRiskData source
Windows Command Obfuscation with Environment Variable SubstringsAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows PowerShell Process Implementing Manual Base64 DecoderAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups29

Show 5 more

Software35

Show 11 more

Campaigns6

Procedure examples70

Groups29

Used byProcedure example
GroupAPT19

APT19 used Base64 to obfuscate executed commands.

GroupAPT32

APT32 has used the `Invoke-Obfuscation` framework to obfuscate their PowerShell.

GroupAquatic Panda

Aquatic Panda has encoded PowerShell commands in Base64.

GroupChimera

Chimera has encoded PowerShell commands.

GroupCobalt Group

Cobalt Group obfuscated several scriptlets and code used on the victim’s machine, including through use of XOR and RC4.

GroupContagious Interview

Contagious Interview has obfuscated JavaScript code using Base64 and variable substitutions.

GroupFIN6

FIN6 has used encoded PowerShell commands.

GroupFIN7

FIN7 has used fragmented strings, environment variables, standard input (stdin), and native character-replacement functionalities to obfuscate commands.

View all 29 groups examples

Software35

Used byProcedure example
MalwareAstaroth

Astaroth has obfuscated and randomized parts of the JScript code it is initiating.

MalwareBackConfig

BackConfig has used compressed and decimal encoded VBS scripts.

MalwareBADHATCH

BADHATCH malicious PowerShell commands can be encoded with base64.

MalwareCARROTBAT

CARROTBAT has the ability to execute obfuscated commands on the infected host.

MalwareComRAT

ComRAT has used encryption and base64 to obfuscate its orchestrator code in the Registry. ComRAT has also used encoded PowerShell scripts.

MalwareCookieMiner

CookieMiner has used base64 encoding to obfuscate scripts on the system.

MalwareDarkWatchman

DarkWatchman has used Base64 to encode PowerShell commands.

MalwareDenis

Denis has encoded its PowerShell commands in Base64.

View all 35 software examples

Campaigns6

Used byProcedure example
CampaignC0018

During C0018, the threat actors used Base64 to encode their PowerShell scripts.

CampaignC0021

During C0021, the threat actors used encoded PowerShell commands.

CampaignFrankenstein

During Frankenstein, the threat actors ran encoded commands from the command line.

CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors executed an encoded VBScript file.

CampaignOperation Wocao

During Operation Wocao, threat actors executed PowerShell commands which were encoded or compressed using Base64, zlib, and XOR.

CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors executed Base64-encoded PowerShell commands.

References9

  1. Akamai JS Open source
    Katz, O. (2020, October 26). Catch Me if You Can—JavaScript Obfuscation. Retrieved March 17, 2023.
  2. Bashfuscator Command Obfuscators Open source
    LeFevre, A. (n.d.). Bashfuscator Command Obfuscators. Retrieved March 17, 2023.
  3. FireEye Obfuscation June 2017 Open source
    Bohannon, D. & Carr N. (2017, June 30). Obfuscation in the Wild: Targeted Attackers Lead the Way in Evasion Techniques. Retrieved February 12, 2018.
  4. Invoke-DOSfuscation Open source
    Bohannon, D. (2018, March 19). Invoke-DOSfuscation. Retrieved March 17, 2023.
  5. Invoke-Obfuscation Open source
    Bohannon, D. (2016, September 24). Invoke-Obfuscation. Retrieved March 17, 2023.
  6. Malware Monday VBE Open source
    Bromiley, M. (2016, December 27). Malware Monday: VBScript and VBE Files. Retrieved March 17, 2023.
  7. Microsoft PowerShellB64 Open source
    Microsoft. (2023, February 8). about_PowerShell_exe: EncodedCommand. Retrieved March 17, 2023.
  8. RC PowerShell Open source
    Red Canary. (n.d.). 2022 Threat Detection Report: PowerShell. Retrieved March 17, 2023.
  9. Twitter Richard WMIC Open source
    Ackroyd, R. (2023, March 24). Twitter. Retrieved September 12, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.