Malware.View on attack.mitre.org
PowGoop is a loader that consists of a DLL loader and a PowerShell-based downloader; it has been used by MuddyWater as their main loader.
| Technique | Procedure example |
|---|---|
| T1036 Masquerading |
PowGoop has disguised a PowerShell script as a .dat file (goopdate.dat). |
| T1036.005 Match Legitimate Resource Name or Location |
PowGoop has used a DLL named Goopdate.dll to impersonate a legitimate Google update file. |
| T1059.001 PowerShell |
PowGoop has the ability to use PowerShell scripts to execute commands. |
| T1071.001 Web Protocols |
PowGoop can send HTTP GET requests to malicious servers. |
| T1132.002 Non-Standard Encoding |
PowGoop can use a modified Base64 encoding mechanism to send data to and from the C2 server. |
| T1140 Deobfuscate/Decode Files or Information |
PowGoop can decrypt PowerShell scripts for execution. |
| T1573 Encrypted Channel |
PowGoop can receive encrypted commands from C2. |
| T1574.001 DLL |
PowGoop can side-load `Goopdate.dll` into `GoogleUpdate.exe`. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.