FORENSIA

ATT&CK · T1027.002 · sub-technique

Software Packing

Tactics: stealth

About

Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or encrypting an executable. Packing an executable changes the file signature in an attempt to avoid signature-based detection. Most decompression techniques decompress the executable code in memory. Virtual machine software protection translates an executable's original code into a special format that only a special virtual machine can run. A virtual machine is then called to run this code. Utilities used to perform software packing are called packers. Example packers are MPRESS and UPX. A more comprehensive list of known packers is available, but adversaries may create their own packing techniques that do not leave the same artifacts as well-known packers to evade defenses.

Platforms: Linux, macOS, WindowsParent: T1027 Obfuscated Files or InformationMITRE ATT&CK ↗

Used by actors

23 known groups

Software

73 malware/tools implement this

China ChopperUroburosDyreSeaDukeMisdatS-TypeTrojan.KaraganyH1N1FinFisherDaserfNETWIREZeroTytyZebrocyVERMINOopsIETrickBotBisonalDokjRATDarkCometGreyEnergyOSX_OCEANLOTUS.DKONNIEmotetAstarothHyperBroMacheteHotCroissantShimRatLokibotMetamorfoSDBbotValakIcedIDAnchorFatDukeLiteDukeBLINDINGCANCSPY DownloaderMelcozLuciferBazarSparkEgregorRaindropGoldMaxHildegardClopCostaBricksAppleSeedCubaFYAntiBabukQakBotSysUpdateTomirisTorismaDRATzarusDonutSaint BotMongallSquirrelwaffleCOATHANGERRaspberry RobinLatrodectusStrelaStealerTroll StealerLockBit 3.0XLoaderSagerunexRedLine StealerHeartCrypt

Corpus indicators tagged with this technique

5,100 indicators in the corpus carry T1027.002.

IndicatorTypeFamilySevSrc
cve-2016-0638cvephishing851
cve-2021-27076cve851
4c357a29b202b77e7db190d359ead2dfd3f8869c6808b96bfa8bee82525bb2a2hashransomware801
c8075bbff748096e1c6a1ea0aa67bb6762fdd7551427a12425b35b94c1f1ecf2sha256supply_chain801
b90988400cced319d260c4937f334ecc364785ed5c593cd2139965e62ca58173sha256phishing801
46b2155c1e71b840d4b7a2e94410b89a61e2446523e6f497206d402eb02e0e93hashransomware801
17832aa629524ef6e8d8d6e9b6b902a8d324b559e3c36dbd0e221ab1690be871sha256supply_chain801
2654c08491a0f7c4a3dfc6282de5638bhash803
282b9bc318ad1234cbd1b86424b784299b8be31545802a7c6b751166b814b990sha256supply_chain801
50ffce607867d8fa8eaf6ef5cd25a3c0e7e4415e881b9e55c04a67bcddb74fdfsha256supply_chain801
07cd03e2082bcb0b890cc59ce4c770d1a095ac6f1ae9cf999f5542555c56f841sha256phishing801
3d510977d60a44322f88100b515f06cb5ed83babc64247068d1a489595faa6c5sha256phishing801
08060143ea9b55b480746b415af22e3ahashransomware801
15d1002d9935fbfc9dfc65eb70fe4ecc0943c784hashransomware801
9c44bc9373377831c45dd0ac2661a28ehash803
4c9f271242f61f1a31b8146305e9a7ed512c521445d4f7a7a901e301307add3dsha256801
625b6535321d58bb5c613e85332bf731hash803
164e322d6fbc62e254d73583acd7f39444c884d3f5e6a5d27db143fc25bc88b3sha256supply_chain801
873f1277a42de5c82f869459e7fb7c94554a642bhash803
c099f965144bccd0b590f946659fc3c0747c54aef505b6caaca9078712f455fbsha256801
64c7dd0a3a3ae49977ac05913d3878000cce14e5d8c1ee05b782bdfd648bde91sha256801
ad10ff9043d6f327045943635fcbd0c5918acb79dc998db92ee4c7dee5224710sha256801
681075027553546c119ec447eb8df84633dcffcehash803
5864a697bd7b339f56b05405f29a097cd027cafdcc4e63c2aaeccccbf930605fsha256801
f4d77958a12a0778283d3e679b24b18f82e332c4hash803
123e80a34508c4dede7cc70e76931fcchash803
b8eed63ab9cbdca494f26a6f66bfd4a0a693b3f0hash803
e20b35a8c30e076cdd0e1df05ba1ff2e418dbd39a674f084787cc0af2fda9e95sha256phishing801
b148626849c11dd5b3230632a38a6302hashransomware802
f6669bd504ce6b0e303be7ee47f2ebbc062989c88c41f0a3f436044a24869798sha256supply_chain801

Showing the top 30 by severity of 5,100.