ATT&CKReferencesPrevailion EvilNum May 2020

Prevailion EvilNum May 2020

Adamitis, D. (2020, May 6). Phantom in the Command Shell. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareEVILNUM

EVILNUM can obtain the username from the victim's machine.

T1041
Exfiltration Over C2 Channel
MalwareEVILNUM

EVILNUM can upload files over the C2 channel from the infected host.

T1047
Windows Management Instrumentation
MalwareEVILNUM

EVILNUM has used the Windows Management Instrumentation (WMI) tool to enumerate infected machines.

T1070
Indicator Removal
MalwareEVILNUM

EVILNUM has a function called "DeleteLeftovers" to remove certain artifacts of the attack.

T1070.006
Timestomp
MalwareEVILNUM

EVILNUM has changed the creation date of files.

T1082
System Information Discovery
MalwareEVILNUM

EVILNUM can obtain the computer name from the victim's system.

T1102.003
One-Way Communication
MalwareEVILNUM

EVILNUM has used a one-way communication method via GitLab and Digital Point to perform C2.

T1105
Ingress Tool Transfer
MalwareEVILNUM

EVILNUM can download and upload files to the victim's computer.

T1112
Modify Registry
MalwareEVILNUM

EVILNUM can make modifications to the Regsitry for persistence.

T1218.011
Rundll32
MalwareEVILNUM

EVILNUM can execute commands and scripts through rundll32.

T1518.001
Security Software Discovery
MalwareEVILNUM

EVILNUM can search for anti-virus products on the system.

T1539
Steal Web Session Cookie
MalwareEVILNUM

EVILNUM can harvest cookies and upload them to the C2 server.

T1547.001
Registry Run Keys / Startup Folder
MalwareEVILNUM

EVILNUM can achieve persistence through the Registry Run key.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.