ATT&CKReferencesESET Recon Snake Nest

ESET Recon Snake Nest

Boutin, J. and Faou, M. (2018). Visiting the snake nest. Retrieved May 7, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples1

TechniqueUsed byProcedure example
T1055.011
Extra Window Memory Injection
MalwareEpic

Epic has overwritten the function pointer in the extra window memory of Explorer's Shell_TrayWnd in order to execute malicious code in the context of the explorer.exe process.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.