GREAT. (2021, March 30). APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign. Retrieved June 17, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.001 Junk Data |
MalwareP8RAT | P8RAT can send randomly-generated data as part of its C2 communication. |
| T1012 Query Registry |
MalwareSodaMaster | SodaMaster has the ability to query the Registry to detect a key specific to VMware. |
| T1027 Obfuscated Files or Information |
MalwareEcipekac | Ecipekac can use XOR, AES, and DES to encrypt loader shellcode. |
| T1027 Obfuscated Files or Information |
MalwareSodaMaster | SodaMaster can use "stackstrings" for obfuscation. |
| T1027.002 Software Packing |
MalwareFYAnti | FYAnti has used ConfuserEx to pack its .NET module. |
| T1033 System Owner/User Discovery |
MalwareSodaMaster | SodaMaster can identify the username on a compromised host. |
| T1057 Process Discovery |
MalwareSodaMaster | SodaMaster can search a list of running processes. |
| T1057 Process Discovery |
MalwareP8RAT | P8RAT can check for specific processes associated with virtual environments. |
| T1070.003 Clear Command History |
GroupmenuPass | menuPass has used Wevtutil to remove PowerShell execution logs. |
| T1071.001 Web Protocols |
MalwareCobalt Strike | Cobalt Strike can use a custom command and control protocol that can be encapsulated in HTTP or HTTPS. All protocols use their standard assigned ports. |
| T1078 Valid Accounts |
GroupmenuPass | menuPass has used valid accounts including shared between Managed Service Providers and clients to move between the two environments. |
| T1082 System Information Discovery |
MalwareSodaMaster | SodaMaster can enumerate the host name and OS version on a target system. |
| T1083 File and Directory Discovery |
MalwareFYAnti | FYAnti can search the |
| T1105 Ingress Tool Transfer |
MalwareP8RAT | P8RAT can download additional payloads to a target system. |
| T1105 Ingress Tool Transfer |
MalwareEcipekac | Ecipekac can download additional payloads to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareFYAnti | FYAnti can download additional payloads to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareSodaMaster | SodaMaster has the ability to download additional payloads from C2 to the targeted system. |
| T1106 Native API |
MalwareSodaMaster | SodaMaster can use |
| T1140 Deobfuscate/Decode Files or Information |
MalwareFYAnti | FYAnti has the ability to decrypt an embedded .NET module. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareEcipekac | Ecipekac has the ability to decrypt fileless loader modules. |
| T1190 Exploit Public-Facing Application |
GroupmenuPass | menuPass has leveraged vulnerabilities in Pulse Secure VPNs to hijack sessions. |
| T1497.001 System Checks |
MalwareSodaMaster | SodaMaster can check for the presence of the Registry key |
| T1497.001 System Checks |
MalwareP8RAT | P8RAT can check the compromised host for processes associated with VMware or VirtualBox environments. |
| T1497.003 Time Based Checks |
MalwareP8RAT | P8RAT has the ability to "sleep" for a specified time to evade detection. |
| T1497.003 Time Based Checks |
MalwareSodaMaster | SodaMaster has the ability to put itself to "sleep" for a specified time. |
| T1553.002 Code Signing |
GroupmenuPass | menuPass has resized and added data to the certificate table to enable the signing of modified files with legitimate signatures. |
| T1553.002 Code Signing |
MalwareEcipekac | Ecipekac has used a valid, legitimate digital signature to evade detection. |
| T1573.001 Symmetric Cryptography |
MalwareSodaMaster | SodaMaster can use RC4 to encrypt C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareSodaMaster | SodaMaster can use a hardcoded RSA key to encrypt some of its C2 traffic. |
| T1574.001 DLL |
MalwareEcipekac | Ecipekac can abuse the legitimate application policytool.exe to load a malicious DLL. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.