Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
Epic uses the |
| T1012 Query Registry |
Epic uses the |
| T1016 System Network Configuration Discovery |
Epic uses the |
| T1018 Remote System Discovery |
Epic uses the |
| T1027 Obfuscated Files or Information |
Epic heavily obfuscates its code to make analysis more difficult. |
| T1033 System Owner/User Discovery |
Epic collects the user name from the victim’s machine. |
| T1049 System Network Connections Discovery |
Epic uses the |
| T1055.011 Extra Window Memory Injection |
Epic has overwritten the function pointer in the extra window memory of Explorer's Shell_TrayWnd in order to execute malicious code in the context of the explorer.exe process. |
| T1057 Process Discovery |
Epic uses the |
| T1069.001 Local Groups |
Epic gathers information on local group names. |
| T1070.004 File Deletion |
Epic has a command to delete a file from the machine. |
| T1071.001 Web Protocols |
Epic uses HTTP and HTTPS for C2 communications. |
| T1082 System Information Discovery |
Epic collects the OS version, hardware information, computer name, available system memory status, and system and user language settings. |
| T1083 File and Directory Discovery |
Epic recursively searches for all .doc files on the system and collects a directory listing of the Desktop, %TEMP%, and %WINDOWS%\Temp directories. |
| T1087.001 Local Account |
Epic gathers a list of all user accounts, privilege classes, and time of last logon. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.