Real-world descriptions of how a group, tool or campaign used a technique.
35 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareUrsnif | Ursnif has collected files from victim machines, including certificates and cookies. |
| T1007 System Service Discovery |
MalwareUrsnif | Ursnif has gathered information about running services. |
| T1012 Query Registry |
MalwareUrsnif | Ursnif has used Reg to query the Registry for installed programs. |
| T1027.010 Command Obfuscation |
MalwareUrsnif | Ursnif droppers execute base64 encoded PowerShell commands. |
| T1027.013 Encrypted/Encoded File |
MalwareUrsnif | Ursnif has used an XOR-based algorithm to encrypt Tor clients dropped to disk. Ursnif droppers have also been delivered as password-protected zip files that execute base64 encoded PowerShell commands. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareUrsnif | Ursnif has used strings from legitimate system files and existing folders for its file, folder, and Registry entry names. |
| T1041 Exfiltration Over C2 Channel |
MalwareUrsnif | Ursnif has used HTTP POSTs to exfil gathered information. |
| T1047 Windows Management Instrumentation |
MalwareUrsnif | Ursnif droppers have used WMI classes to execute PowerShell commands. |
| T1055.005 Thread Local Storage |
MalwareUrsnif | Ursnif has injected code into target processes via thread local storage callbacks. |
| T1055.012 Process Hollowing |
MalwareUrsnif | Ursnif has used process hollowing to inject into child processes. |
| T1056.004 Credential API Hooking |
MalwareUrsnif | Ursnif has hooked APIs to perform a wide variety of information theft, such as monitoring traffic from browsers. |
| T1057 Process Discovery |
MalwareUrsnif | Ursnif has gathered information about running processes. |
| T1059.001 PowerShell |
MalwareUrsnif | Ursnif droppers have used PowerShell in download cradles to download and execute the malware's full executable payload. |
| T1059.005 Visual Basic |
MalwareUrsnif | Ursnif droppers have used VBA macros to download and execute the malware's full executable payload. |
| T1070.004 File Deletion |
MalwareUrsnif | Ursnif has deleted data staged in tmp files after exfiltration. |
| T1071.001 Web Protocols |
MalwareUrsnif | Ursnif has used HTTPS for C2. |
| T1074.001 Local Data Staging |
MalwareUrsnif | Ursnif has used tmp files to stage gathered information. |
| T1080 Taint Shared Content |
MalwareUrsnif | Ursnif has copied itself to and infected files in network drives for propagation. |
| T1082 System Information Discovery |
MalwareUrsnif | Ursnif has used Systeminfo to gather system information. |
| T1090 Proxy |
MalwareUrsnif | Ursnif has used a peer-to-peer (P2P) network for C2. |
| T1090.003 Multi-hop Proxy |
MalwareUrsnif | |
| T1091 Replication Through Removable Media |
MalwareUrsnif | Ursnif has copied itself to and infected removable drives for propagation. |
| T1105 Ingress Tool Transfer |
MalwareUrsnif | Ursnif has dropped payload and configuration files to disk. Ursnif has also been used to download and execute additional payloads. |
| T1106 Native API |
MalwareUrsnif | Ursnif has used |
| T1112 Modify Registry |
MalwareUrsnif | Ursnif has used Registry modifications as part of its installation routine. |
| T1113 Screen Capture |
MalwareUrsnif | Ursnif has used hooked APIs to take screenshots. |
| T1132 Data Encoding |
MalwareUrsnif | Ursnif has used encoded data in HTTP URLs for C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareUrsnif | Ursnif has used crypto key information stored in the Registry to decrypt Tor clients dropped to disk. |
| T1185 Browser Session Hijacking |
MalwareUrsnif | Ursnif has injected HTML codes into banking sites to steal sensitive online banking information (ex: usernames and passwords). |
| T1497.003 Time Based Checks |
MalwareUrsnif | Ursnif has used a 30 minute delay after execution to evade sandbox monitoring tools. |
| T1543.003 Windows Service |
MalwareUrsnif | Ursnif has registered itself as a system service in the Registry for automatic execution at system startup. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareUrsnif | Ursnif has used Registry Run keys to establish automatic execution at system startup. |
| T1559.001 Component Object Model |
MalwareUrsnif | Ursnif droppers have used COM objects to execute the malware's full executable payload. |
| T1564.003 Hidden Window |
MalwareUrsnif | Ursnif droppers have used COM properties to execute malware in hidden windows. |
| T1568.002 Domain Generation Algorithms |
MalwareUrsnif | Ursnif has used a DGA to generate domain names for C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.