Porolli, M. (2020, July 9). More evil: A deep look at Evilnum and its toolset. Retrieved January 22, 2021.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareMore_eggs | More_eggs's payload has been encrypted with a key that has the hostname and processor family information appended to the end. |
| T1059.003 Windows Command Shell |
MalwareMore_eggs | More_eggs has used cmd.exe for execution. |
| T1059.007 JavaScript |
GroupEvilnum | Evilnum has used malicious JavaScript files on the victim's machine. |
| T1070.004 File Deletion |
GroupEvilnum | Evilnum has deleted files used during infection. |
| T1105 Ingress Tool Transfer |
GroupEvilnum | Evilnum can deploy additional components or tools as needed. |
| T1105 Ingress Tool Transfer |
MalwareEVILNUM | EVILNUM can download and upload files to the victim's computer. |
| T1204.001 Malicious Link |
GroupEvilnum | Evilnum has sent spearphishing emails designed to trick the recipient into opening malicious shortcut links which downloads a .LNK file. |
| T1218.010 Regsvr32 |
MalwareEVILNUM | EVILNUM can run a remote scriptlet that drops a file and executes it via regsvr32.exe. |
| T1219.002 Remote Desktop Software |
GroupEvilnum | EVILNUM has used the malware variant, TerraTV, to run a legitimate TeamViewer application to connect to compromised machines. |
| T1497.001 System Checks |
GroupEvilnum | Evilnum has used a component called TerraLoader to check certain hardware and file information to detect sandboxed environments. |
| T1539 Steal Web Session Cookie |
GroupEvilnum | Evilnum can steal cookies and session information from browsers. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareEVILNUM | EVILNUM can achieve persistence through the Registry Run key. |
| T1548.002 Bypass User Account Control |
GroupEvilnum | Evilnum has used PowerShell to bypass UAC. |
| T1555 Credentials from Password Stores |
GroupEvilnum | Evilnum can collect email credentials from victims. |
| T1566.002 Spearphishing Link |
GroupEvilnum | Evilnum has sent spearphishing emails containing a link to a zip file hosted on Google Drive. |
| T1574.001 DLL |
GroupEvilnum | Evilnum has used the malware variant, TerraTV, to load a malicious DLL placed in the TeamViewer directory, instead of the original Windows DLL located in a system folder. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.