FORENSIA

ATT&CK · T1132.002 · sub-technique

Non-Standard Encoding

Tactics: command-and-control

About

Adversaries may encode data with a non-standard data encoding system to make the content of command and control traffic more difficult to detect. Command and control (C2) information can be encoded using a non-standard data encoding system that diverges from existing protocol specifications. Non-standard data encoding schemes may be based on or related to standard data encoding schemes, such as a modified Base64 encoding for the message body of an HTTP request.

Platforms: ESXi, Linux, macOS, WindowsParent: T1132 Data EncodingMITRE ATT&CK ↗

Used by actors

1 known groups

Software

17 malware/tools implement this

UroburosBACKSPACEBankshotInvisiMoleOceanSaltRDATShadowPadLizarCyclops BlinkSmall SievePowGoopNightClubNinjaCHIMNEYSWEEPNeo-reGeorgTONESHELLHTTPTroy

Corpus indicators tagged with this technique

7 indicators in the corpus carry T1132.002.

IndicatorTypeFamilySevSrc
http://140.206.161.227:443url755
http://43.160.202.246:8053url755
124.156.129.151ip704
140.206.161.227ip704
43.160.202.246ip704
hcgos.comdomain655
ashx.lhlsjcb.comdomain655