ATT&CKReferencesMicrosoft SIR Vol 21

Microsoft SIR Vol 21

Anthe, C. et al. (2016, December 14). Microsoft Security Intelligence Report Volume 21. Retrieved November 27, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups2

Software3

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1055
Process Injection
MalwareWingbird

Wingbird performs multiple process injections to hijack system processes and execute malicious code.

T1068
Exploitation for Privilege Escalation
MalwareWingbird

Wingbird exploits CVE-2016-4117 to allow an executable to gain escalated privileges.

T1070.004
File Deletion
MalwareWingbird

Wingbird deletes its payload along with the payload's parent process after it finishes copying files.

T1082
System Information Discovery
MalwareWingbird

Wingbird checks the victim OS version after executing to determine where to drop files based on whether the victim is 32-bit or 64-bit.

T1518.001
Security Software Discovery
MalwareWingbird

Wingbird checks for the presence of Bitdefender security software.

T1543.003
Windows Service
MalwareWingbird

Wingbird uses services.exe to register a new autostart service named "Audit Service" using a copy of the local lsass.exe file.

T1547.008
LSASS Driver
MalwareWingbird

Wingbird drops a malicious file (sspisrv.dll) alongside a copy of lsass.exe, which is used to register a service that loads sspisrv.dll as a driver. The payload of the malicious driver (located in its entry-point function) is executed when loaded by lsass.exe before the spoofed service becomes unstable and crashes.

T1569.002
Service Execution
MalwareWingbird

Wingbird uses services.exe to register a new autostart service named "Audit Service" using a copy of the local lsass.exe file.

T1574.001
DLL
MalwareWingbird

Wingbird side loads a malicious file, sspisrv.dll, in part of a spoofed lssas.exe service.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.