Malware.View on attack.mitre.org
Ecipekac is a multi-layer loader that has been used by menuPass since at least 2019 including use as a loader for P8RAT, SodaMaster, and FYAnti.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
Ecipekac can use XOR, AES, and DES to encrypt loader shellcode. |
| T1105 Ingress Tool Transfer |
Ecipekac can download additional payloads to a compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
Ecipekac has the ability to decrypt fileless loader modules. |
| T1553.002 Code Signing |
Ecipekac has used a valid, legitimate digital signature to evade detection. |
| T1574.001 DLL |
Ecipekac can abuse the legitimate application policytool.exe to load a malicious DLL. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.