Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Software
  3. PowGoop

PowGoop

PowGoop is a loader that consists of a DLL loader and a PowerShell-based downloader; it has been used byMuddyWater as their main loader.[1][2]

ID: S1046
Type: MALWARE
Platforms: Windows
Contributors: Ozer Sarilar, @ozersarilar, STM
Version: 1.0
Created: 29 September 2022
Last Modified: 16 April 2025
Enterprise Layer
downloadview

Techniques Used

DomainIDNameUse
EnterpriseT1071.001Application Layer Protocol:Web Protocols

PowGoop can send HTTP GET requests to malicious servers.[2]

EnterpriseT1059.001Command and Scripting Interpreter:PowerShell

PowGoop has the ability to use PowerShell scripts to execute commands.[1]

EnterpriseT1132.002Data Encoding:Non-Standard Encoding

PowGoop can use a modified Base64 encoding mechanism to send data to and from the C2 server.[2]

EnterpriseT1140Deobfuscate/Decode Files or Information

PowGoop can decrypt PowerShell scripts for execution.[1][2]

EnterpriseT1573Encrypted Channel

PowGoop can receive encrypted commands from C2.[1]

EnterpriseT1574.001Hijack Execution Flow:DLL

PowGoop can side-loadGoopdate.dll intoGoogleUpdate.exe.[1][2]

EnterpriseT1036Masquerading

PowGoop has disguised a PowerShell script as a .dat file (goopdate.dat).[1]

.005Match Legitimate Resource Name or Location

PowGoop has used a DLL named Goopdate.dll to impersonate a legitimate Google update file.[1]

Groups That Use This Software

IDNameReferences
G0069MuddyWater

[1]

References

×

[8]ページ先頭

©2009-2026 Movatter.jp