ATT&CKReferencesWeLiveSecurity Gapz and Redyms Mar 2013

WeLiveSecurity Gapz and Redyms Mar 2013

Matrosov, A. (2013, March 19). Gapz and Redyms droppers based on Power Loader code. Retrieved December 16, 2017.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples1

TechniqueUsed byProcedure example
T1055.011
Extra Window Memory Injection
MalwarePower Loader

Power Loader overwrites Explorer’s Shell_TrayWnd extra window memory to redirect execution to a NTDLL function that is abused to assemble and execute a return-oriented programming (ROP) chain and create a malicious thread within Explorer.exe.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.