If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1027/010 - Obfuscated Files or Informatio.

site address: attack.mitre.org/techniques/T1027/010 redirected to: attack.mitre.org/techniques/T1027/010

site title: Obfuscated Files or Information: Command Obfuscation, Sub-technique T1027.010 - Enterprise MITRE ATT&CK®

Our opinion (on Tuesday 18 August 2026 11:24:40 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

obfuscated, files, or, information, command, obfuscation, procedure, examples, mitigations, detection, strategy, references, other, sub, techniques, of, 18,

Text of the page (most frequently used words):
retrieved (111), and (81), the (59), has (53), used (38), 2018 (35), powershell (34), base64 (34), 2020 (33), 2019 (33), #obfuscated (31), 2025 (30), scripts (29), obfuscation (29), commands (29), march (27), encoded (27), may (26), threat (26), october (25), 2021 (23), june (22), command (21), t1027 (21), 2023 (19), with (19), group (19), obfuscate (18), november (17), july (17), september (17), 2022 (17), january (16), april (16), february (15), malware (15), encoding (15), 2017 (14), new (14), 2024 (14), code (14), december (13), detection (12), techniques (12), august (12), using (12), for (12), targets (11), campaign (11), analysis (11), att (10), all (10), operation (10), invoke (10), muddywater (9), actors (9), enterprise (8), execution (8), files (8), exploitation (8), ransomware (8), during (8), can (8), xor (8), also (8), malicious (7), from (7), actor (7), sharepoint (7), via (7), strings (7), 2026 (6), use (6), software (6), microsoft (6), attack (6), into (6), its (6), apt (6), research (6), attacks (6), fin8 (6), middle (6), cobalt (6), tools (6), powersploit (6), targeting (6), team (6), information (6), emotet (6), encryption (6), payloads (6), executed (6), variables (6), ics (5), mobile (5), none (5), backdoor (5), security (5), 2016 (5), east (5), powerstats (5), phishing (5), medusa (5), machete (5), panda (5), bohannon (5), variable (5), line (5), script (5), environment (5), mitre (4), data (4), sub (4), well (4), fin7 (4), sidewinder (4), global (4), toolshell (4), cve (4), falcone (4), government (4), qakbot (4), post (4), framework (4), targeted (4), netwalker (4), iranian (4), their (4), through (4), empire (4), north (4), korean (4), gamaredon (4), comrat (4), javascript (4), string (4), that (4), such (4), characters (4), windows (4), encrypted (4), including (4), technique (4), compressed (4), within (4), version (4), adversaries (4), reference (3), campaigns (3), groups (3), cti (3), mitigations (3), defenses (3), tactics (3), block (3), contagious (3), interview (3), loader (3), report (3), tricks (3), ursnif (3), dive (3), turla (3), tsundere (3), botnet (3), payload (3), ta505 (3), sqlrat (3), silence (3), sibot (3), analyzing (3), vulnerabilities (3), trend (3), micro (3), exploit (3), sardonic (3), redline (3), stealer (3), quadagent (3), uses (3), operations (3), compromised (3), poetrat (3), public (3), play (3), patchwork (3), wocao (3), cuckoobees (3), deep (3), fileless (3), organizations (3), expands (3), your (3), activity (3), magic (3), hound (3), loudminer (3), leafminer (3), lazyscripter (3), peck (3), iceapple (3), wirte (3), based (3), frankenstein (3), spider (3), carr (3), fin6 (3), havoc (3), after (3), darkwatchman (3), chimera (3), key (3), carrotbat (3), badhatch (3), backconfig (3), astaroth (3), aquatic (3), apt32 (3), patterns (3), description (3), name (3), analyze (3), execute (3), file (3), character (3), compression (3), zlib (3), encode (3), various (3), input (3), c0021 (3), c0018 (3), 010 (3), smuggling (3), corporation (2), are (2), domains (2), resources (2), components (2), analytics (2), strategies (2), assets (2), matrices (2), core (2), objects (2), surface (2), reduction (2), asr (2), rules (2), potentially (2), brumaghin (2), banking (2), trojan (2), search (2), faou (2), evolution (2), macro (2), salem (2), inside (2), forensic (2), active (2), updated (2), zero (2), day (2), wild (2), under (2), intelligence (2), rise (2), disruptive (2), novel (2), lee (2), service (2), agency (2), black (2), lunghi (2), multi (2), stage (2), clearsky (2), cyber (2), ventura (2), sector (2), daniel (2), vpn (2), cyberespionage (2), continues (2), exploits (2), arsenal (2), adamitis (2), associated (2), updates (2), spear (2), mstic (2), symantec (2), response (2), espionage (2), iuzvyk (2), tim (2), drive (2), platforms (2), way (2), ukraine (2), carbon (2), military (2), game (2), mac (2), alive (2), open (2), cisa (2), ahl (2), you (2), activities (2), developers (2), likely (2), multiple (2), asia (2), attackers (2), antivirus (2), obfuscator (2), vbscript (2), references (2), shell (2), unusual (2), tokens (2), substitution (2), excessive (2), escape (2), strategy (2), analytic (2), antimalware (2), being (2), obfuscates (2), zeus (2), xorindex (2), wizard (2), names (2), ta551 (2), insertion (2), making (2), sharpstats (2), rc4 (2), sandworm (2), was (2), compress (2), roguerobin (2), replacement (2), powerpunch (2), hosts (2), phasejam (2), which (2), were (2), been (2), other (2), randomized (2), leveraged (2), embedded (2), machine (2), interpreter (2), victim (2), batchencryption (2), tool (2), koctopus (2), kimsuky (2), ironwind (2), junk (2), hexane (2), gold (2), southfield (2), fruitfly (2), fox (2), kitten (2), standard (2), stdin (2), arguments (2), macros (2), delivered (2), ability (2), exe (2), denis (2), cookieminer (2), apt19 (2), binary (2), difficult (2), more (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, poisoning, google, results, kirill, boychenko, escalates, npm, packages, dfir, ryuk, return, goody, nasty, trick, credential, theft, business, disruption, holland, comfoolery, how, evades, dumont, usage, ubiedo, blockchain, node, abused, emerging, duncan, valak, beginnings, mass, distribution, vilkomir, preisman, servhelper, variant, employs, excel, drop, signed, financial, enterprises, lolbins, platt, reeves, revisited, astra, panel, skulkin, dissecting, chm, performing, rewterz, hegel, perspective, nafisi, lelli, goldmax, goldfinder, nobelium, layered, persistence, unit, brief, kenin, exploited, servers, proactive, insights, 53770, 53771, eye, siege, 49706, 49704, disrupting, premises, budaca, goes, agile, cherepanov, telebots, killdisk, darkhydrus, mohansundaram, neil, tyagi, approach, oilrig, technology, provider, kenefick, basta, gang, infiltrates, networks, brute, ratel, strike, cyberint, horejsi, resurfaces, lebanon, oman, israeli, domain, two, powershellmafia, 2012, mercer, rascagneres, private, azerbaijan, evolves, spotlight, john, wolfram, josh, murchie, matt, lin, ainsworth, robert, wallace, dimiter, andonov, dhanesh, kizhakkinan, jacob, thompson, ivanti, connect, secure, untangling, dantzig, schamper, shining, light, one, china, hidden, hacking, cybereason, nocturnus, stealthy, winnti, szappanos, brandt, give, insight, victor, injected, reflective, loading, malhortra, turkish, users, pdfs, executables, peretz, theck, earth, vetala, target, adds, recent, blackwater, shows, signs, anti, kaspersky, lab, singh, procedures, lancaster, muddying, water, anthony, galiette, doel, santos, turning, stone, cybersecurity, infrastructure, aa25, 071a, stopransomware, evolving, trends, presentation, cyberwarcon, saudi, eset, just, got, sharper, venezuelan, institutions, cylance, cut, latam, malik, cross, platform, mining, cracked, vst, eastern, regions, jazi, double, rat, den, observed, exploiting, trusted, crowdstrike, internet, services, iis, kayal, lyceum, reborn, counterintelligence, check, point, hamas, affiliated, moves, tetra, defense, cause, effect, sodinokibi, rusnák, toolset, spy, hunter, shuckworm, foreign, mission, center, actinium, ukrainian, boutin, grows, patrick, wardle, cobble, together, source, pieces, monstrous, iran, martin, zugec, investigation, elovitz, know, enemy, financially, motivated, loui, reynolds, embraces, big, hunting, part, hunt, pursuing, enigmatic, evasive, criminal, visa, cybercrime, ecommerce, merchants, schroeder, warner, nelson, github, powershellempire, perez, latest, propagation, özarslan, christmas, card, never, wanted, wave, back, wreak, exploring, emerges, holidays, smith, stafford, chen, steals, cryptocurrency, exchanges, cookies, seongsu, park, pyongyang, payroll, remote, workers, west, securonix, kolesnikov, dev, popper, ryan, sherstobitoff, devops, employees, matej, havranek, deceptivedevelopment, freelance, ar20, 303a, agent, btz, ten, year, journey, gorelik, svajcer, personality, disorder, cycraft, skeleton, taiwan, semiconductor, vendors, grunzweig, wilhoit, fractured, deliver, southeast, defender, cyberattack, think, tanks, non, profits, unidentified, dunwoody, not, cozy, uncomfortable, examination, suspected, apt29, costa, raas, avoslocker, incident, venere, neal, avos, vrabie, returns, improved, toolkit, hinchliffe, south, legitimate, processes, steal, passwords, personal, wiley, overwatch, exposes, possession, log4shell, hands, intrusion, attempt, dahan, kitty, corporations, privileges, credentials, phished, request, counsel, dosfuscation, ackroyd, twitter, lead, evasion, lefevre, bashfuscator, obfuscators, about_powershell_exe, encodedcommand, red, canary, bromiley, monday, vbe, katz, catch, osascript, applescript, interpreters, runtime, reconstruction, an1396, leverage, chaining, piping, token, indicative, an1395, exhibiting, syntactic, concatenation, outlier, length, entropy, an1394, det0505, enable, 111, behavior, prevention, endpoint, m1040, consider, utilizing, scan, interface, amsi, processed, interpreted, m1049, mitigation, initial, 110, s0330, ascii, buffers, textdecoder, 109, s1248, 108, 107, g0102, conceal, chains, g0090, droppers, 106, s0386, salted, 3des, random, 105, out, encryptedscript, ps1, g0010, msi, installer, 104, s9034, configuration, 103, g0127, 102, 101, g0092, appear, contain, chinese, 100, s0390, g0091, g0121, s0589, s0450, c0058, gzip, s1085, rot13, aes, library, python, g0034, s0270, text, s1240, s0269, s0650, layer, blob, custom, s0223, contains, collection, scriptmodification, modules, s0194, s0685, pyminifier, s0428, g1040, s9014, crypto, g0040, c0014, c0012, layers, hexadecimal, functions, s0457, methods, vbscripts, g0069, dropped, kernel, drivers, known, safengine, shielden, mutations, then, virtual, g1051, g0059, pyobfuscate, some, visual, naming, combinations, letters, hinder, s0409, s0451, machines, g0077, perform, advanced, batch, g0140, s0669, g0094, s9029, s1022, g1001, utilized, 1900, s1229, g0115, g0047, executes, stores, perl, s0277, ran, c0001, avoid, g0117, g0061, fragmented, native, functionalities, g0046, g0037, s0363, documents, hide, urls, hosting, cmd, s0367, s0354, s0673, system, s0492, substitutions, g1052, orchestrator, registry, s0126, several, scriptlets, g0080, g0114, infected, host, s0462, s1081, decimal, vbs, s0475, parts, jscript, initiating, s0373, g0143, g0050, g0073, procedure, examples, live, permalink, last, modified, created, george, thomas, trukno, contributors, linux, macos, stealth, tactic, have, dosfucation, directory, traversals, invoked, voi, pcw, tei, system32, erool, wbem, wmic, shadowcopy, delete, example, abuse, syntax, utilizes, symbols, spacing, make, while, maintaining, same, intended, functionality, many, languages, support, built, form, url, manually, implement, splitting, order, casing, globing, involving, passing, streams, mkdir, tmp, nia, rev, dwssap, cte, tac, wor, application, content, impede, method, signature, this, type, included, interactively, scripting, compromise, invisible, unicode, 018, svg, 017, 016, 015, polymorphic, 014, 013, lnk, icon, 012, storage, 011, 009, stripped, 008, dynamic, api, resolution, 007, html, 006, indicator, removal, 005, compile, delivery, 004, steganography, 003, packing, 002, padding, 001, home, join, mclean, hotel, location, details, found, register, here, blog, contribute, benefactors, legal, branding, history, engage, advisory, council, learn, about, get, started, detections,


Text of the page (random words):
hound magic hound has used base64 encoded commands 61 62 g1051 medusa group medusa group has obfuscated powershell scripts with base64 encoding 63 medusa group has also obfuscated the code of dropped kernel drivers using a software known as safengine shielden which randomized the code through code mutations and then leveraged an embedded virtual machine interpreter to execute the code 64 g0069 muddywater muddywater has used daniel bohannon s invoke obfuscation framework and obfuscated powershell scripts 65 12 the group has also used other obfuscation methods including base64 obfuscation of vbscripts and powershell commands 65 66 67 68 69 70 71 s0457 netwalker netwalker s powershell script has been obfuscated with multiple layers including base64 and hexadecimal encoding and xor encryption as well as obfuscated powershell functions and variables 72 73 c0012 operation cuckoobees during operation cuckoobees the threat actors executed an encoded vbscript file 74 c0014 operation wocao during operation wocao threat actors executed powershell commands which were encoded or compressed using base64 zlib and xor 75 g0040 patchwork patchwork has obfuscated a script with crypto obfuscator 76 s9014 phasejam phasejam has encoded commands with base64 77 g1040 play play has used base64 encoded powershell scripts for post exploit activities on compromised hosts 78 s0428 poetrat poetrat has pyminifier to obfuscate scripts 79 s0685 powerpunch powerpunch can use base64 encoded scripts 48 s0194 powersploit powersploit contains a collection of scriptmodification modules that compress and encode scripts and payloads 80 81 s0223 powerstats powerstats uses character replacement powershell environment variables and xor encoding to obfuscate code powerstats s backdoor code is a multi layer obfuscated encoded and compressed blob 66 82 powerstats has used powershell code with custom string obfuscation 83 s0650 qakbot qakbot can use obfuscated and encoded scripts 84 85 s0269 quadagent quadagent was likely obfuscated using invoke obfuscation 86 12 s1240 redline stealer redline stealer has obfuscated scripts within text files used in execution 87 s0270 roguerobin the powershell script with the roguerobin payload was obfuscated using the compress technique in invoke obfuscation 88 12 g0034 sandworm team sandworm team has used rot13 encoding aes encryption and compression with the zlib library for their python based backdoor 89 s1085 sardonic sardonic powershell scripts can be encrypted with rc4 and compressed using gzip 90 c0058 sharepoint toolshell exploitation during sharepoint toolshell exploitation threat actors executed base64 encoded powershell commands 91 92 93 94 95 s0450 sharpstats sharpstats has used base64 encoding and xor to obfuscate powershell scripts 83 s0589 sibot sibot has obfuscated scripts used in execution 96 g0121 sidewinder sidewinder has used base64 encoding for scripts 97 98 g0091 silence silence has used environment variable string substitution for obfuscation 99 s0390 sqlrat sqlrat has used a character insertion obfuscation technique making the script appear to contain chinese characters 100 g0092 ta505 ta505 has used base64 encoded powershell commands 101 102 g0127 ta551 ta551 has used obfuscated variable names in a javascript configuration file 103 s9034 tsundere botnet tsundere botnet s msi installer has base64 encoded command execution 104 g0010 turla turla has used encryption including salted 3des via powersploit s out encryptedscript ps1 random variable names and base64 encoding to obfuscate powershell commands and payloads 105 s0386 ursnif ursnif droppers execute base64 encoded powershell commands 106 g0090 wirte wirte has xor encrypted command line strings to conceal malware execution chains 52 g0102 wizard spider wizard spider used base64 encoding to obfuscate an empire service and powershell commands 107 108 s1248 xorindex loader xorindex loader has obfuscated strings using ascii buffers and textdecoder 109 s0330 zeus panda zeus panda obfuscates the macro commands in its initial payload 110 mitigations id mitigation description m1049 antivirus antimalware consider utilizing the antimalware scan interface amsi on windows 10 to analyze commands after being processed interpreted m1040 behavior prevention on endpoint on windows 10 enable attack surface reduction asr rules to block execution of potentially obfuscated scripts 111 detection strategy id name analytic id analytic description det0505 detection strategy for command obfuscation an1394 detection of command line activity exhibiting syntactic obfuscation patterns such as excessive escape characters base64 encoding command concatenation or outlier command length and entropy an1395 detection of shell commands that leverage encoded execution command chaining excessive piping or unusual token patterns indicative of obfuscation an1396 detection of obfuscated commands via shell osascript or applescript interpreters using unusual tokens encoding variable substitution or runtime string reconstruction references katz o 2020 october 26 catch me if you can javascript obfuscation retrieved march 17 2023 bromiley m 2016 december 27 malware monday vbscript and vbe files retrieved march 17 2023 red canary n d 2022 threat detection report powershell retrieved march 17 2023 microsoft 2023 february 8 about_powershell_exe encodedcommand retrieved march 17 2023 lefevre a n d bashfuscator command obfuscators retrieved march 17 2023 bohannon d carr n 2017 june 30 obfuscation in the wild targeted attackers lead the way in evasion techniques retrieved february 12 2018 ackroyd r 2023 march 24 twitter retrieved september 12 2024 bohannon d 2018 march 19 invoke dosfuscation retrieved march 17 2023 bohannon d 2016 september 24 invoke obfuscation retrieved march 17 2023 ahl i 2017 june 06 privileges and credentials phished at the request of counsel retrieved may 17 2018 carr n 2017 may 14 cyber espionage is alive and well apt32 and the threat to global corporations retrieved june 18 2017 bohannon d 2017 march 13 invoke obfuscation powershell obfuscator retrieved june 18 2017 dahan a 2017 operation cobalt kitty retrieved december 27 2018 wiley b et al 2021 december 29 overwatch exposes aquatic panda in possession of log4shell exploit tools during hands on intrusion attempt retrieved january 18 2022 salem e 2019 february 13 astaroth malware uses legitimate os and antivirus processes to steal passwords and personal data retrieved april 17 2019 hinchliffe a and falcone r 2020 may 11 updated backconfig malware targeting government and military organizations in south asia retrieved june 17 2020 vrabie v et al 2021 march 10 fin8 returns with improved badhatch toolkit retrieved september 8 2021 venere g neal c 2022 june 21 avos ransomware group expands with new attack arsenal retrieved january 11 2023 costa f 2022 may 1 raas avoslocker incident response analysis retrieved january 11 2023 dunwoody m et al 2018 november 19 not so cozy an uncomfortable examination of a suspected apt29 phishing campaign retrieved november 27 2018 microsoft defender research team 2018 december 3 analysis of cyberattack on u s think tanks non profits public sector by unidentified attackers retrieved april 15 2019 grunzweig j and wilhoit k 2018 november 29 the fractured block campaign carrotbat used to deliver malware targeting southeast asia retrieved june 2 2020 cycraft 2020 april 15 apt group chimera apt operation skeleton key targets taiwan semiconductor vendors retrieved august 24 2020 svajcer v 2018 july 31 multiple cobalt personality disorder retrieved september 5 2018 gorelik m 2018 october 08 cobalt group 2 0 retrieved november 5 2018 faou m 2020 may from agent btz to comrat v4 a ten year journey retrieved june 15 2020 cisa 2020 october 29 malware analysis report ar20 303a retrieved december 9 2020 matej havranek 2025 february 20 deceptivedevelopment targets freelance developers retrieved october 17 2025 ryan sherstobitoff 2024 october 29 inside a north korean phishing operation targeting devops employees retrieved october 20 2025 securonix threat research d iuzvyk t peck o kolesnikov 2024 april 24 analysis of dev popper new attack campaign targeting software developers likely associated with north korean threat actors retrieved october 20 2025 seongsu park 2024 november 4 from pyongyang to your payroll the rise of north korean remote workers in the west retrieved october 17 2025 chen y et al 2019 january 31 mac malware steals cryptocurrency exchanges cookies retrieved july 22 2020 smith s stafford m 2021 december 14 darkwatchman a new evolution in fileless techniques retrieved january 10 2022 brumaghin e 2019 january 15 emotet re emerges after the holidays retrieved march 25 2019 trend micro 2019 january 16 exploring emotet s activities retrieved march 25 2019 özarslan s 2018 december 21 the christmas card you never wanted a new wave of emotet is back to wreak havoc retrieved march 25 2019 perez d 2018 december 28 analysis of the latest emotet propagation campaign retrieved april 16 2019 schroeder w warner j nelson m n d github powershellempire retrieved april 28 2016 visa public 2019 february fin6 cybercrime group expands threat to ecommerce merchants retrieved september 16 2019 carr n et al 2018 august 01 on the hunt for fin7 pursuing an enigmatic and evasive global criminal operation retrieved august 23 2018 loui e and reynolds j 2021 august 30 carbon spider embraces big game hunting part 1 retrieved september 20 2021 elovitz s ahl i 2016 august 18 know your enemy new financially motivated spear phishing group retrieved february 26 2018 martin zugec 2021 july 27 deep dive into a fin8 attack a forensic investigation retrieved september 1 2021 cisa 2020 september 15 iran based threat actor exploits vpn vulnerabilities retrieved december 21 2020 adamitis d et al 2019 june 4 it s alive threat actors cobble together open source pieces into monstrous frankenstein campaign retrieved may 11 2020 patrick wardle n d mac malware of 2017 retrieved september 21 2018 boutin j 2020 june 11 gamaredon group grows its game retrieved june 16 2020 microsoft threat intelligence center 2022 february 4 actinium targets ukrainian organizations retrieved february 18 2022 threat hunter team symantec and carbon black 2025 april 10 shuckworm targets foreign military mission based in ukraine retrieved july 23 2025 rusnák z 2024 september 26 cyberespionage the gamaredon way analysis of toolset used to spy on ukraine in 2022 and 2023 retrieved october 30 2024 tetra defense 2020 march cause and effect sodinokibi ransomware analysis retrieved november 17 2024 check point 2024 november 12 hamas affiliated threat actor wirte continues its middle east operations and moves to disruptive activity retrieved april 20 2026 kayal a et al 2021 october lyceum reborn counterintelligence in the middle east retrieved june 14 2022 crowdstrike 2022 may iceapple a novel internet information services iis post exploitation framework retrieved june 27 2022 den iuzvyk tim peck 2025 february 13 analyzing deep drive north korean threat actors observed exploiting trusted platforms for targeted attacks retrieved august 19 2025 jazi h 2021 february lazyscripter from empire to double rat retrieved november 17 2024 symantec security response 2018 july 25 leafminer new espionage campaigns targeting middle eastern regions retrieved august 28 2018 malik m 2019 june 20 loudminer cross platform mining in cracked vst software retrieved may 18 2020 the cylance threat research team 2017 march 22 el machete s malware attacks cut through latam retrieved september 13 2019 eset 2019 july machete just got sharper venezuelan government institutions under attack retrieved september 13 2019 lee b and falcone r 2017 february 15 magic hound campaign attacks saudi targets retrieved december 27 2017 mstic 2021 november 16 evolving trends in iranian threat actor activity mstic presentation at cyberwarcon 2021 retrieved january 12 2023 cybersecurity and infrastructure security agency 2025 march 12 aa25 071a stopransomware medusa ransomware retrieved october 15 2025 anthony galiette doel santos 2024 january 11 medusa ransomware turning your files into stone retrieved october 15 2025 lancaster t 2017 november 14 muddying the water targeted attacks in the middle east retrieved march 15 2018 singh s et al 2018 march 13 iranian threat group updates tactics techniques and procedures in spear phishing campaign retrieved april 11 2018 kaspersky lab s global research analysis team 2018 october 10 muddywater expands operations retrieved november 2 2018 adamitis d et al 2019 may 20 recent muddywater associated blackwater campaign shows signs of new anti detection techniques retrieved june 5 2019 clearsky 2019 june iranian apt group muddywater adds exploits to their arsenal retrieved may 14 2020 peretz a and theck e 2021 march 5 earth vetala muddywater continues to target organizations in the middle east retrieved march 18 2021 malhortra a and ventura v 2022 january 31 iranian apt muddywater targets turkish users via malicious pdfs executables retrieved june 22 2022 victor k 2020 may 18 netwalker fileless ransomware injected via reflective loading retrieved may 26 2020 szappanos g brandt a 2020 may 27 netwalker ransomware tools give insight into threat actor retrieved may 27 2020 cybereason nocturnus 2022 may 4 operation cuckoobees deep dive into stealthy winnti techniques retrieved september 22 2022 dantzig m v schamper e 2019 december 19 operation wocao shining a light on one of china s hidden hacking groups retrieved october 8 2020 lunghi d et al 2017 december untangling the patchwork cyberespionage group retrieved july 10 2018 john wolfram josh murchie matt lin daniel ainsworth robert wallace dimiter andonov dhanesh kizhakkinan jacob thompson 2025 january 8 ivanti connect secure vpn targeted in new zero day exploitation retrieved april 14 2026 trend micro research 2023 july 21 ransomware spotlight play retrieved september 24 2024 mercer w rascagneres p ventura v 2020 october 6 poetrat malware targeting public and private sector in azerbaijan evolves retrieved april 9 2021 powershellmafia 2012 may 26 powersploit a powershell post exploitation framework retrieved february 6 2018 powersploit n d powersploit retrieved february 6 2018 clearsky cyber security 2018 november muddywater operations in lebanon and oman using an israeli compromised domain for a two stage campaign retrieved november 29 2018 lunghi d and horejsi j 2019 june 10 muddywater resurfaces uses multi stage backdoor powerstats v3 and new post exploitation tools retrieved may 14 2020 cyberint 2021 may 25 qakbot banking trojan retrieved september 27 2021 kenefick i et al 2022 october 12 black basta ransomware gang infiltrates networks via qakbot brute ratel and cobalt strike retrieved february 6 2023 lee b falcone r 2018 july 25 oilrig targets technology service provider and government agency with quadagent retrieved august 9 2018 m...
Images from subpage: "attack.mitre.org/groups/G0094" Verify
Images from subpage: "attack.mitre.org/software/S0669" Verify
Images from subpage: "attack.mitre.org/groups/G0140" Verify
Images from subpage: "attack.mitre.org/groups/G0077" Verify
Images from subpage: "attack.mitre.org/software/S0451" Verify

Verified site has: 139 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-80 81-85 86-90 91-95 96-100
101-105 106-110 111-115 116-120 121-125 126-130 131-135 136-139


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


The site also has 57 references to external domain(s).

 medium.com  Verify  na.eventscloud.com  Verify  akamai.com  Verify
 bromiley.medium.com  Verify  redcanary.com  Verify  bashfuscator.readthedocs.io  Verify
 web.archive.org  Verify  x.com  Verify  github.com  Verify
 fireeye.com  Verify  cdn2.hubspot.net  Verify  crowdstrike.com  Verify
 cybereason.com  Verify  unit42.paloaltonetworks.com  Verify  bitdefender.com  Verify
 blog.talosintelligence.com  Verify  linkedin.com  Verify  microsoft.com  Verify
 blog.morphisec.com  Verify  welivesecurity.com  Verify  us-cert.cisa.gov  Verify
 securityscorecard.com  Verify  securonix.com  Verify  zscaler.com  Verify
 documents.trendmicro.com  Verify  picussecurity.com  Verify  usa.visa.com  Verify
 www2.fireeye.com  Verify  businessinsights.bitdefender.com  Verify  objective-see.com  Verify
 security.com  Verify  web-assets.esetstatic.com  Verify  research.checkpoint.com  Verify
 vblocalhost.com  Verify  symantec.com  Verify  threatvector.cylance.com  Verify
 researchcenter.paloaltonetworks.com  Verify  cisa.gov  Verify  securelist.com  Verify
 clearskysec.com  Verify  trendmicro.com  Verify  blog.trendmicro.com  Verify
 news.sophos.com  Verify  fox-it.com  Verify  cloud.google.com  Verify
 powersploit.readthedocs.io  Verify  blog.cyberint.com  Verify  mcafee.com  Verify
 research.eye.security  Verify  sentinelone.com  Verify  cdn-cybersecurity.att.com  Verify
 rewterz.com  Verify  flashpoint-intel.com  Verify  deepinstinct.com  Verify
 bromium.com  Verify  thedfirreport.com  Verify  socket.dev  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1027/010/
access-control-allow-origin *
expires Tue, 18 Aug 2026 11:34:40 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id 9AD6:32BDB5:26FE3D5:2742267:6A8440F8
x-github-edge-region fra
accept-ranges bytes
age 0
date Tue, 18 Aug 2026 11:24:40 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290033-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787052280.383463,VS0,VE106
vary Accept-Encoding
x-fastly-request-id 0f55f73da444cf708fe00b65bae3f37bd9d67f01
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:18 GMT
access-control-allow-origin *
etag W/ 6a75ea92-311f5
expires Tue, 18 Aug 2026 11:34:40 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id A24E:351820:26CA247:270DF58:6A8440F8
x-github-edge-region fra
accept-ranges bytes
age 0
date Tue, 18 Aug 2026 11:24:40 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290033-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787052280.499964,VS0,VE123
vary Accept-Encoding
x-fastly-request-id aa5b3d0967bb6e63a66e80a4d8d8a77371cc0cbf
content-length 36088

Meta Tags

title="Obfuscated Files or Information: Command Obfuscation, Sub-technique T1027.010 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size36088
load time (s)0.543135
redirect count1
speed download66460
server IP 185.199.108.153
* all occurrences of the string "http://" have been changed to "htt???/"