Malware.View on attack.mitre.org
NOOPLDR is a shellcode loader with XML/C# and DLL versions that has been used by MirrorFace to load HiddenFace.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
NOOPLDR can use control flow flattening to help hide malicious code. |
| T1027.013 Encrypted/Encoded File |
The NOOPLDR payload is encrypted with AES256-CBC. |
| T1027.016 Junk Code Insertion |
NOOPLDR can insert junk code to obfuscate malicious payloads. |
| T1055 Process Injection |
NOOPLDR can inject decrypted payloads into processes including wuauclt.exe., rdrleakdiag.exe, and tabcal.exe. |
| T1070.004 File Deletion |
NOOPLDR can delete a file containing configuration instructions after use. |
| T1082 System Information Discovery |
NOOPLDR can discover the device ID and hostname from the targeted machine to use for encryption keys. |
| T1106 Native API |
NOOPLDR can use native APIs `NtProtectVirtualMemory`, `NtWriteVirtualMemory`, and `NtCreateThreadEx` to aid process injection. |
| T1112 Modify Registry |
NOOPLDR can store its payload in the Registry using a random hex string in `HKCU\SOFTWARE\Microsoft\COM3`. |
| T1127.001 MSBuild |
NOOPLDR can be executed via MSBuild. |
| T1140 Deobfuscate/Decode Files or Information |
NOOPLDR can decrypt its payload prior to execution. |
| T1564 Hide Artifacts |
NOOPLDR can hide services used to aid execution. |
| T1574.001 DLL |
NOOPLDR can be executed via sideloading. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.