| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1574 | .002 | 劫持执行流: DLL Side-Loading |
Ecipekac can abuse the legitimate application policytool.exe to load a malicious DLL.[1] |
| Enterprise | T1140 | 反混淆/解码文件或信息 |
Ecipekac has the ability to decrypt fileless loader modules.[1] |
|
| Enterprise | T1027 | 混淆文件或信息 |
Ecipekac can use XOR, AES, and DES to encrypt loader shellcode.[1] |
|
| Enterprise | T1105 | 输入工具传输 |
Ecipekac can download additional payloads to a compromised host.[1] |
|
| Enterprise | T1553 | .002 | 颠覆信任控制: Code Signing |
Ecipekac has used a valid, legitimate digital signature to evade detection.[1] |