Obfuscated Files or Information: Software Packing

Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or encrypting an executable. Packing an executable changes the file signature in an attempt to avoid signature-based detection. Most decompression techniques decompress the executable code in memory. Virtual machine software protection translates an executable's original code into a special format that only a special virtual machine can run. A virtual machine is then called to run this code.[1]

Utilities used to perform software packing are called packers. Example packers are MPRESS and UPX. A more comprehensive list of known packers is available, [2] but adversaries may create their own packing techniques that do not leave the same artifacts as well-known packers to evade defenses.

ID: T1027.002
Sub-technique of:  T1027
Tactic: Defense Evasion
Platforms: Windows, macOS
Data Sources: File: File Content, File: File Metadata
Defense Bypassed: Anti-virus, Heuristic detection, Signature-based detection
CAPEC ID: CAPEC-570
Contributors: Filip Kafka, ESET
Version: 1.0
Created: 05 February 2020
Last Modified: 05 February 2020

Procedure Examples

ID Name Description
S0504 Anchor

Anchor has come with a packed payload.[3]

G0016 APT29

APT29 used UPX to pack files.[4]

G0022 APT3

APT3 has been known to pack their tools.[5]

G0082 APT38

APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium, to pack their implants.[6]

G0087 APT39

APT39 has packed tools with UPX, and has repacked a modified version of Mimikatz to thwart anti-virus detection.[7][8]

S0373 Astaroth

Astaroth uses a software packer called Pe123\RPolyCryptor.[9]

S0534 Bazar

Bazar has a variant with a packed payload.[10][11]

S0520 BLINDINGCAN

BLINDINGCAN has been packed with the UPX packer.[12]

S0020 China Chopper

China Chopper's client component is packed with UPX.[13]

S0527 CSPY Downloader

CSPY Downloader has been packed with UPX.[14]

G0070 Dark Caracal

Dark Caracal has used UPX to pack Bandook.[15]

S0334 DarkComet

DarkComet has the option to compress its payload using UPX or MPRESS.[16]

S0187 Daserf

A version of Daserf uses the MPRESS packer.[17]

S0024 Dyre

Dyre has been delivered with encrypted resources and must be unpacked for execution.[18]

S0554 Egregor

Egregor's payloads are custom-packed, archived and encrypted to prevent analysis.[19][20]

G0066 Elderwood

Elderwood has packed malware payloads before delivery to victims.[21]

S0367 Emotet

Emotet has used custom packers to protect its payloads.[22]

S0512 FatDuke

FatDuke has been regularly repacked by its operators to create large binaries and evade detection.[23]

S0182 FinFisher

A FinFisher variant uses a custom packer.[24][25]

G0093 GALLIUM

GALLIUM packed some payloads using different types of packers, both known and custom.[26]

S0588 GoldMax

GoldMax has been packed for obfuscation.[27]

S0342 GreyEnergy

GreyEnergy is packed for obfuscation.[28]

S0132 H1N1

H1N1 uses a custom packing algorithm.[29]

S0601 Hildegard

Hildegard has packed ELF files into other binaries.[30]

S0431 HotCroissant

HotCroissant has used the open source UPX executable packer.[31]

S0483 IcedID

IcedID has packed and encrypted its loader module.[32]

S0283 jRAT

jRAT payloads have been packed.[33]

G0032 Lazarus Group

Lazarus Group has used Themida to pack at least two separate backdoor implants.[34]

S0447 Lokibot

Lokibot has used several packing methods for obfuscation.[35]

S0532 Lucifer

Lucifer has used UPX packed binaries.[36]

S0409 Machete

Machete has been packed with NSIS.[37]

S0530 Melcoz

Melcoz has been packed with VMProtect and Themida.[38]

S0455 Metamorfo

Metamorfo has used VMProtect to pack and protect files.[39]

S0198 NETWIRE

NETWIRE has used .NET packer tools to evade detection.[40]

G0014 Night Dragon

Night Dragon is known to use software packing in its tools.[41]

S0264 OopsIE

OopsIE uses the SmartAssembly obfuscator to pack an embedded .Net Framework assembly used for C2.[42]

S0352 OSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has a variant that is packed with UPX.[43]

G0040 Patchwork

A Patchwork payload was packed with UPX.[44]

S0565 Raindrop

Raindrop used a custom packer for its Cobalt Strike payload, which was compressed using the LZMA algorithm.[45][46]

G0106 Rocke

Rocke's miner has created UPX-packed files in the Windows Start Menu Folder.[47][48][49]

S0461 SDBbot

SDBbot has used a packed installer file.[50]

S0053 SeaDuke

SeaDuke has been packed with the UPX packer.[51]

S0444 ShimRat

ShimRat's loader has been packed with the compressed ShimRat core DLL and the legitimate DLL for it to hijack.[52]

S0543 Spark

Spark has been packed with Enigma Protector to obfuscate its contents.[53]

G0092 TA505

TA505 has used UPX to obscure malicious code.[50]

G0089 The White Company

The White Company has obfuscated their payloads through packing.[54]

S0266 TrickBot

TrickBot leverages a custom packer to obfuscate its functionality.[55]

S0094 Trojan.Karagany

Trojan.Karagany samples sometimes use common binary packers such as UPX and Aspack on top of a custom Delphi binary packer.[56][57]

S0022 Uroburos

Uroburos uses a custom packer.[58]

S0476 Valak

Valak has used packed DLL payloads.[59]

S0257 VERMIN

VERMIN is initially packed.[60]

S0248 yty

yty packs a plugin with UPX.[61]

S0251 Zebrocy

Zebrocy's Delphi variant was packed with UPX.[62][63]

S0230 ZeroT

Some ZeroT DLL files have been packed with UPX.[64]

G0128 ZIRCONIUM

ZIRCONIUM has used multi-stage packers for exploit code.[65]

Mitigations

ID Mitigation Description
M1049 Antivirus/Antimalware

Employ heuristic-based malware detection. Ensure updated virus definitions and create custom signatures for observed malware.

Detection

Use file scanning to look for known software packers or artifacts of packing techniques. Packing is not a definitive indicator of malicious activity, because legitimate software may use packing techniques to reduce binary size or to protect proprietary code.

References

  1. Kafka, F. (2018, January). ESET's Guide to Deobfuscating and Devirtualizing FinFisher. Retrieved August 12, 2019.
  2. Executable compression. (n.d.). Retrieved December 4, 2014.
  3. Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.
  4. Dunwoody, M. and Carr, N.. (2016, September 27). No Easy Breach DerbyCon 2016. Retrieved October 4, 2016.
  5. Korban, C, et al. (2017, September). APT3 Adversary Emulation Plan. Retrieved January 16, 2018.
  6. FireEye. (2018, October 03). APT38: Un-usual Suspects. Retrieved November 6, 2018.
  7. Hawley et al. (2019, January 29). APT39: An Iranian Cyber Espionage Group Focused on Personal Information. Retrieved February 19, 2019.
  8. Rusu, B. (2020, May 21). Iranian Chafer APT Targeted Air Transportation and Government in Kuwait and Saudi Arabia. Retrieved May 22, 2020.
  9. Salem, E. (2019, February 13). ASTAROTH MALWARE USES LEGITIMATE OS AND ANTIVIRUS PROCESSES TO STEAL PASSWORDS AND PERSONAL DATA. Retrieved April 17, 2019.
  10. Cybereason Nocturnus. (2020, July 16). A BAZAR OF TRICKS: FOLLOWING TEAM9’S DEVELOPMENT CYCLES. Retrieved November 18, 2020.
  11. Sadique, M. and Singh, A. (2020, September 29). Spear Phishing Campaign Delivers Buer and Bazar Malware. Retrieved November 19, 2020.
  12. US-CERT. (2020, August 19). MAR-10295134-1.v1 – North Korean Remote Access Trojan: BLINDINGCAN. Retrieved August 19, 2020.
  13. Lee, T., Hanzlik, D., Ahl, I. (2013, August 7). Breaking Down the China Chopper Web Shell - Part I. Retrieved March 27, 2015.
  14. Dahan, A. et al. (2020, November 2). Back to the Future: Inside the Kimsuky KGH Spyware Suite. Retrieved November 6, 2020.
  15. Blaich, A., et al. (2018, January 18). Dark Caracal: Cyber-espionage at a Global Scale. Retrieved April 11, 2018.
  16. Kujawa, A. (2018, March 27). You dirty RAT! Part 1: DarkComet. Retrieved November 6, 2018.
  17. Chen, J. and Hsieh, M. (2017, November 7). REDBALDKNIGHT/BRONZE BUTLER’s Daserf Backdoor Now Using Steganography. Retrieved December 27, 2017.
  18. hasherezade. (2015, November 4). A Technical Look At Dyreza. Retrieved June 15, 2020.
  19. NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.
  20. Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.
  21. O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved February 15, 2018.
  22. Trend Micro. (2019, January 16). Exploring Emotet's Activities . Retrieved March 25, 2019.
  23. Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.
  24. FinFisher. (n.d.). Retrieved December 20, 2017.
  25. Kaspersky Lab's Global Research & Analysis Team. (2017, October 16). BlackOasis APT and new targeted attacks leveraging zero-day exploit. Retrieved February 15, 2018.
  26. Cybereason Nocturnus. (2019, June 25). Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers. Retrieved July 18, 2019.
  27. Smith, L., Leathery, J., Read, B. (2021, March 4). New SUNSHUTTLE Second-Stage Backdoor Uncovered Targeting U.S.-Based Entity; Possible Connection to UNC2452. Retrieved March 12, 2021.
  28. Cherepanov, A. (2018, October). GREYENERGY A successor to BlackEnergy. Retrieved November 15, 2018.
  29. Reynolds, J.. (2016, September 13). H1N1: Technical analysis reveals new capabilities. Retrieved September 26, 2016.
  30. Chen, J. et al. (2021, February 3). Hildegard: New TeamTNT Cryptojacking Malware Targeting Kubernetes. Retrieved April 5, 2021.
  31. Knight, S.. (2020, April 16). VMware Carbon Black TAU Threat Analysis: The Evolution of Lazarus. Retrieved May 1, 2020.
  32. Kimayong, P. (2020, June 18). COVID-19 and FMLA Campaigns used to install new IcedID banking malware. Retrieved July 14, 2020.
  33. Kamluk, V. & Gostev, A. (2016, February). Adwind - A Cross-Platform RAT. Retrieved April 23, 2019.
  1. F-Secure Labs. (2020, August 18). Lazarus Group Campaign Targeting the Cryptocurrency Vertical. Retrieved September 1, 2020.
  2. Hoang, M. (2019, January 31). Malicious Activity Report: Elements of Lokibot Infostealer. Retrieved May 15, 2020.
  3. Hsu, K. et al. (2020, June 24). Lucifer: New Cryptojacking and DDoS Hybrid Malware Exploiting High and Critical Vulnerabilities to Infect Windows Devices. Retrieved November 16, 2020.
  4. ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.
  5. GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.
  6. Zhang, X.. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.
  7. Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.
  8. McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.
  9. Lee, B., Falcone, R. (2018, February 23). OopsIE! OilRig Uses ThreeDollars to Deliver New Trojan. Retrieved July 16, 2018.
  10. Dumont, R.. (2019, April 9). OceanLotus: macOS malware update. Retrieved April 15, 2019.
  11. Kaspersky Lab's Global Research & Analysis Team. (2016, July 8). The Dropping Elephant – aggressive cyber-espionage in the Asian region. Retrieved August 3, 2016.
  12. Symantec Threat Hunter Team. (2021, January 18). Raindrop: New Malware Discovered in SolarWinds Investigation. Retrieved January 19, 2021.
  13. MSTIC, CDOC, 365 Defender Research Team. (2021, January 20). Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop . Retrieved January 22, 2021.
  14. Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.
  15. Xingyu, J.. (2019, January 17). Malware Used by Rocke Group Evolves to Evade Detection by Cloud Security Products. Retrieved May 26, 2020.
  16. Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.
  17. Frydrych, M. (2020, April 14). TA505 Continues to Infect Networks With SDBbot RAT. Retrieved May 29, 2020.
  18. Grunzweig, J.. (2015, July 14). Unit 42 Technical Analysis: Seaduke. Retrieved August 3, 2016.
  19. Yonathan Klijnsma. (2016, May 17). Mofang: A politically motivated information stealing adversary. Retrieved May 12, 2020.
  20. Falcone, R., et al. (2020, March 3). Molerats Delivers Spark Backdoor to Government and Telecommunications Organizations. Retrieved December 14, 2020.
  21. Livelli, K, et al. (2018, November 12). Operation Shaheen. Retrieved May 1, 2019.
  22. Salinas, M., Holguin, J. (2017, June). Evolution of Trickbot. Retrieved July 31, 2018.
  23. Symantec Security Response. (2014, July 7). Dragonfly: Cyberespionage Attacks Against Energy Suppliers. Retrieved April 8, 2016.
  24. Secureworks. (2019, July 24). Updated Karagany Malware Targets Energy Sector. Retrieved August 12, 2020.
  25. Symantec. (2015, January 26). The Waterbug attack group. Retrieved April 10, 2015.
  26. Reaves, J. and Platt, J. (2020, June). Valak Malware and the Connection to Gozi Loader ConfCrew. Retrieved August 31, 2020.
  27. Lancaster, T., Cortes, J. (2018, January 29). VERMIN: Quasar RAT and Custom Malware Used In Ukraine. Retrieved July 5, 2018.
  28. Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.
  29. Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.
  30. Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.
  31. Huss, D., et al. (2017, February 2). Oops, they did it again: APT Targets Russia and Belarus with ZeroT and PlugX. Retrieved April 5, 2018.
  32. Itkin, E. and Cohen, I. (2021, February 22). The Story of Jian – How APT31 Stole and Used an Unknown Equation Group 0-Day. Retrieved March 24, 2021.