NOOPLDR — Malware Profile
NOOPLDR is a shellcode loader with XML/C# and DLL versions that has been used by MirrorFace to load HiddenFace.
MITRE ATT&CK techniques (12)
- T1027 Obfuscated Files or Information
- T1027.013 Encrypted/Encoded File
- T1027.016 Junk Code Insertion
- T1055 Process Injection
- T1070.004 File Deletion
- T1082 System Information Discovery
- T1106 Native API
- T1112 Modify Registry
- T1127.001 MSBuild
- T1140 Deobfuscate/Decode Files or Information
- T1564 Hide Artifacts
- T1574.001 DLL