ATT&CKReferencesSecurity Intelligence More Eggs Aug 2019

Security Intelligence More Eggs Aug 2019

Villadsen, O.. (2019, August 29). More_eggs, Anyone? Threat Actor ITG08 Strikes Again. Retrieved September 16, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1016.001
Internet Connection Discovery
MalwareMore_eggs

More_eggs has used HTTP GET requests to check internet connectivity.

T1033
System Owner/User Discovery
MalwareMore_eggs

More_eggs has the capability to gather the username from the victim's machine.

T1047
Windows Management Instrumentation
GroupFIN6

FIN6 has used WMI to automate the remote execution of PowerShell scripts.

T1059.003
Windows Command Shell
MalwareMore_eggs

More_eggs has used cmd.exe for execution.

T1070.004
File Deletion
MalwareMore_eggs

More_eggs can remove itself from a system.

T1071.001
Web Protocols
MalwareMore_eggs

More_eggs uses HTTPS for C2.

T1082
System Information Discovery
MalwareMore_eggs

More_eggs has the capability to gather the OS version and computer name.

T1105
Ingress Tool Transfer
MalwareMore_eggs

More_eggs can download and launch additional payloads.

T1132.001
Standard Encoding
MalwareMore_eggs

More_eggs has used basE91 encoding, along with encryption, for C2 communication.

T1140
Deobfuscate/Decode Files or Information
MalwareMore_eggs

More_eggs will decode malware components that are then dropped to the system.

T1218.010
Regsvr32
MalwareMore_eggs

More_eggs has used regsvr32.exe to execute the malicious DLL.

T1553.002
Code Signing
GroupFIN6

FIN6 has used Comodo code-signing certificates.

T1553.002
Code Signing
MalwareMore_eggs

More_eggs has used a signed binary shellcode loader and a signed Dynamic Link Library (DLL) to create a reverse shell.

T1566.003
Spearphishing via Service
GroupFIN6

FIN6 has used fake job advertisements sent via LinkedIn to spearphish targets.

T1573.001
Symmetric Cryptography
MalwareMore_eggs

More_eggs has used an RC4-based encryption method for its C2 communications.

T1588.002
Tool
GroupFIN6

FIN6 has obtained and used tools such as Mimikatz, Cobalt Strike, and AdFind.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.