Malware.View on attack.mitre.org
More_eggs is a JScript backdoor used by Cobalt Group and FIN6. Its name was given based on the variable "More_eggs" being present in its code. There are at least two different versions of the backdoor being used, version 2.0 and version 4.4.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
More_eggs has the capability to gather the IP address from the victim's machine. |
| T1016.001 Internet Connection Discovery |
More_eggs has used HTTP GET requests to check internet connectivity. |
| T1027.013 Encrypted/Encoded File |
More_eggs's payload has been encrypted with a key that has the hostname and processor family information appended to the end. |
| T1033 System Owner/User Discovery |
More_eggs has the capability to gather the username from the victim's machine. |
| T1059.003 Windows Command Shell |
More_eggs has used cmd.exe for execution. |
| T1070.004 File Deletion |
More_eggs can remove itself from a system. |
| T1071.001 Web Protocols |
More_eggs uses HTTPS for C2. |
| T1082 System Information Discovery |
More_eggs has the capability to gather the OS version and computer name. |
| T1105 Ingress Tool Transfer |
More_eggs can download and launch additional payloads. |
| T1132.001 Standard Encoding |
More_eggs has used basE91 encoding, along with encryption, for C2 communication. |
| T1140 Deobfuscate/Decode Files or Information |
More_eggs will decode malware components that are then dropped to the system. |
| T1218.010 Regsvr32 |
More_eggs has used regsvr32.exe to execute the malicious DLL. |
| T1518.001 Security Software Discovery |
More_eggs can obtain information on installed anti-malware programs. |
| T1553.002 Code Signing |
More_eggs has used a signed binary shellcode loader and a signed Dynamic Link Library (DLL) to create a reverse shell. |
| T1573.001 Symmetric Cryptography |
More_eggs has used an RC4-based encryption method for its C2 communications. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.