Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Goopy has the ability to exfiltrate documents from infected systems. |
| T1027.001 Binary Padding |
Goopy has had null characters padded in its malicious DLL payload. |
| T1027.016 Junk Code Insertion |
Goopy's decrypter have been inflated with junk code in between legitimate API functions, and also included infinite loops to avoid analysis. |
| T1033 System Owner/User Discovery |
Goopy has the ability to enumerate the infected system's user name. |
| T1036.005 Match Legitimate Resource Name or Location |
Goopy has impersonated the legitimate goopdate.dll, which was dropped on the target system with a legitimate GoogleUpdate.exe. |
| T1041 Exfiltration Over C2 Channel |
Goopy has the ability to exfiltrate data over the Microsoft Outlook C2 channel. |
| T1053.005 Scheduled Task |
Goopy has the ability to maintain persistence by creating scheduled tasks set to run every hour. |
| T1057 Process Discovery |
Goopy has checked for the Google Updater process to ensure Goopy was loaded properly. |
| T1059.003 Windows Command Shell |
Goopy has the ability to use cmd.exe to execute commands passed from an Outlook C2 channel. |
| T1059.005 Visual Basic |
Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2. |
| T1070.008 Clear Mailbox Data |
Goopy has the ability to delete emails used for C2 once the content has been copied. |
| T1071.001 Web Protocols |
Goopy has the ability to communicate with its C2 over HTTP. |
| T1071.003 Mail Protocols |
Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2. |
| T1071.004 DNS |
Goopy has the ability to communicate with its C2 over DNS. |
| T1106 Native API |
Goopy has the ability to enumerate the infected system's user name via |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.