Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1033 System Owner/User Discovery |
EVILNUM can obtain the username from the victim's machine. |
| T1041 Exfiltration Over C2 Channel |
EVILNUM can upload files over the C2 channel from the infected host. |
| T1047 Windows Management Instrumentation |
EVILNUM has used the Windows Management Instrumentation (WMI) tool to enumerate infected machines. |
| T1070 Indicator Removal |
EVILNUM has a function called "DeleteLeftovers" to remove certain artifacts of the attack. |
| T1070.006 Timestomp |
EVILNUM has changed the creation date of files. |
| T1082 System Information Discovery |
EVILNUM can obtain the computer name from the victim's system. |
| T1102.003 One-Way Communication |
EVILNUM has used a one-way communication method via GitLab and Digital Point to perform C2. |
| T1105 Ingress Tool Transfer |
EVILNUM can download and upload files to the victim's computer. |
| T1112 Modify Registry |
EVILNUM can make modifications to the Regsitry for persistence. |
| T1218.010 Regsvr32 |
EVILNUM can run a remote scriptlet that drops a file and executes it via regsvr32.exe. |
| T1218.011 Rundll32 |
EVILNUM can execute commands and scripts through rundll32. |
| T1518.001 Security Software Discovery |
EVILNUM can search for anti-virus products on the system. |
| T1539 Steal Web Session Cookie |
EVILNUM can harvest cookies and upload them to the C2 server. |
| T1547.001 Registry Run Keys / Startup Folder |
EVILNUM can achieve persistence through the Registry Run key. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.