ATT&CK · T1132.002 · sub-technique
Non-Standard Encoding
Tactics: command-and-control
About
Adversaries may encode data with a non-standard data encoding system to make the content of command and control traffic more difficult to detect. Command and control (C2) information can be encoded using a non-standard data encoding system that diverges from existing protocol specifications. Non-standard data encoding schemes may be based on or related to standard data encoding schemes, such as a modified Base64 encoding for the message body of an HTTP request.
Used by actors
1 known groups
Software
17 malware/tools implement this
UroburosBACKSPACEBankshotInvisiMoleOceanSaltRDATShadowPadLizarCyclops BlinkSmall SievePowGoopNightClubNinjaCHIMNEYSWEEPNeo-reGeorgTONESHELLHTTPTroy
Corpus indicators tagged with this technique
7 indicators in the corpus carry T1132.002.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| http://140.206.161.227:443 | url | — | 75 | 5 |
| http://43.160.202.246:8053 | url | — | 75 | 5 |
| 124.156.129.151 | ip | — | 70 | 4 |
| 140.206.161.227 | ip | — | 70 | 4 |
| 43.160.202.246 | ip | — | 70 | 4 |
| hcgos.com | domain | — | 65 | 5 |
| ashx.lhlsjcb.com | domain | — | 65 | 5 |