MITRE ATT4CK - T1132 - Data Encoding
| Base64 Code | Mnemonic | Decoded* | Description |
|---|---|---|---|
JAB |
Jabber π£ | $. |
Variable declaration (UTF-16) |
TVq |
Television πΊ | MZ |
MZ header |
UEs |
Upper East Side π¬ | PK |
ZIP, Office documents |
SUVY |
SUV π | IEX |
PowerShell Invoke Expression |
SQBFAF |
Squab π£ favorite | I.E. |
PowerShell Invoke Expression (UTF-16) |
PAA |
"Pah!" πͺ | <. |
Often used by Emotet (UTF-16) |
cwBhA |
Chewbaka π¦ | s.a. |
Often used in malicious droppers (UTF-16) 'sal' instead of 'var' |
aWV4 |
Awe version 4 | iex |
PowerShell Invoke Expression |
aQBlA |
Aqua Blah (aquaplaning) π¦ | i.e. |
PowerShell Invoke Expression (UTF-16) |
R2V0 |
R2D2 π€ but version 0 | Get |
Often used to obfuscate imports like GetCurrentThreadId |
dmFy |
defy / demonify πΉ | var |
Variable declaration |
dgBhA |
debugger + high availability | v.a. |
Variable declaration (UTF-16) |
dXNpbm |
Dixon problem | usin |
Often found in compile after delivery attacks |
* the . stands for 0x00
Tweet and Thread https://twitter.com/cyb3rops/status/1187341941794660354